Source: SIP_20252701095738583757327401213.bat.exe, 00000006.00000002.2453692223.00000000031AF000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://checkip.dyndns.com |
Source: SIP_20252701095738583757327401213.bat.exe, 00000006.00000002.2453692223.00000000031AF000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://checkip.dyndns.comd |
Source: SIP_20252701095738583757327401213.bat.exe, 00000006.00000002.2453692223.00000000031AF000.00000004.00000800.00020000.00000000.sdmp, SIP_20252701095738583757327401213.bat.exe, 00000006.00000002.2453692223.0000000003131000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://checkip.dyndns.org |
Source: SIP_20252701095738583757327401213.bat.exe, 00000006.00000002.2453692223.0000000003131000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://checkip.dyndns.org/ |
Source: SIP_20252701095738583757327401213.bat.exe, 00000006.00000002.2453692223.00000000031AF000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://checkip.dyndns.org/d |
Source: SIP_20252701095738583757327401213.bat.exe, 00000000.00000002.1270299842.0000000003429000.00000004.00000800.00020000.00000000.sdmp, SIP_20252701095738583757327401213.bat.exe, 00000006.00000002.2451051118.0000000000402000.00000040.00000400.00020000.00000000.sdmp | String found in binary or memory: http://checkip.dyndns.org/q |
Source: SIP_20252701095738583757327401213.bat.exe, 00000006.00000002.2453692223.00000000031AF000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://checkip.dyndns.orgd |
Source: SIP_20252701095738583757327401213.bat.exe | String found in binary or memory: http://crl.comodoca.com/COMODORSACertificationAuthority.crl0q |
Source: SIP_20252701095738583757327401213.bat.exe | String found in binary or memory: http://crl.comodoca.com/COMODORSACodeSigningCA.crl0t |
Source: SIP_20252701095738583757327401213.bat.exe | String found in binary or memory: http://ocsp.comodoca.com0 |
Source: SIP_20252701095738583757327401213.bat.exe, 00000006.00000002.2453692223.00000000031CB000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://reallyfreegeoip.org |
Source: SIP_20252701095738583757327401213.bat.exe, 00000006.00000002.2453692223.00000000031CB000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://reallyfreegeoip.orgd |
Source: SIP_20252701095738583757327401213.bat.exe, 00000000.00000002.1266324152.0000000002470000.00000004.00000800.00020000.00000000.sdmp, SIP_20252701095738583757327401213.bat.exe, 00000006.00000002.2453692223.0000000003131000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name |
Source: SIP_20252701095738583757327401213.bat.exe, 00000000.00000002.1270299842.0000000003429000.00000004.00000800.00020000.00000000.sdmp, SIP_20252701095738583757327401213.bat.exe, 00000006.00000002.2451051118.0000000000402000.00000040.00000400.00020000.00000000.sdmp | String found in binary or memory: https://api.telegram.org/bot-/sendDocument?chat_id= |
Source: SIP_20252701095738583757327401213.bat.exe, 00000006.00000002.2453692223.00000000031AF000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://reallyfreegeoip.org |
Source: SIP_20252701095738583757327401213.bat.exe, 00000000.00000002.1270299842.0000000003429000.00000004.00000800.00020000.00000000.sdmp, SIP_20252701095738583757327401213.bat.exe, 00000006.00000002.2451051118.0000000000402000.00000040.00000400.00020000.00000000.sdmp, SIP_20252701095738583757327401213.bat.exe, 00000006.00000002.2453692223.00000000031AF000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://reallyfreegeoip.org/xml/ |
Source: SIP_20252701095738583757327401213.bat.exe, 00000006.00000002.2453692223.00000000031AF000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://reallyfreegeoip.org/xml/8.46.123.189d |
Source: SIP_20252701095738583757327401213.bat.exe, 00000006.00000002.2453692223.00000000031AF000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://reallyfreegeoip.org/xml/8.46.123.189l |
Source: SIP_20252701095738583757327401213.bat.exe | String found in binary or memory: https://www.chiark.greenend.org.uk/~sgtatham/putty/0 |
Source: 6.2.SIP_20252701095738583757327401213.bat.exe.400000.0.unpack, type: UNPACKEDPE | Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: 6.2.SIP_20252701095738583757327401213.bat.exe.400000.0.unpack, type: UNPACKEDPE | Matched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/ |
Source: 0.2.SIP_20252701095738583757327401213.bat.exe.348cd08.3.unpack, type: UNPACKEDPE | Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: 0.2.SIP_20252701095738583757327401213.bat.exe.348cd08.3.unpack, type: UNPACKEDPE | Matched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/ |
Source: 0.2.SIP_20252701095738583757327401213.bat.exe.34a3b28.4.unpack, type: UNPACKEDPE | Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: 0.2.SIP_20252701095738583757327401213.bat.exe.34a3b28.4.unpack, type: UNPACKEDPE | Matched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/ |
Source: 0.2.SIP_20252701095738583757327401213.bat.exe.34a3b28.4.raw.unpack, type: UNPACKEDPE | Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: 0.2.SIP_20252701095738583757327401213.bat.exe.348cd08.3.raw.unpack, type: UNPACKEDPE | Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: 00000006.00000002.2451051118.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY | Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: 00000000.00000002.1270299842.0000000003429000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY | Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: Process Memory Space: SIP_20252701095738583757327401213.bat.exe PID: 1964, type: MEMORYSTR | Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: Process Memory Space: SIP_20252701095738583757327401213.bat.exe PID: 7332, type: MEMORYSTR | Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Section loaded: dwrite.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Section loaded: windowscodecs.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Section loaded: textshaping.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Section loaded: edputil.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Section loaded: windows.staterepositoryps.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Section loaded: appresolver.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Section loaded: bcp47langs.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Section loaded: slc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Section loaded: sppc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Section loaded: onecorecommonproxystub.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Section loaded: onecoreuapcommonproxystub.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: atl.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: msisip.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wshext.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: appxsip.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: opcservices.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: secur32.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: microsoft.management.infrastructure.native.unmanaged.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: mi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: miutils.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wmidcom.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: dpapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wbemcomn.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Section loaded: rasapi32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Section loaded: rasman.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Section loaded: rtutils.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Section loaded: dhcpcsvc6.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Section loaded: dhcpcsvc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Section loaded: dnsapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Section loaded: winnsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Section loaded: rasadhlp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Section loaded: fwpuclnt.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Section loaded: secur32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Section loaded: schannel.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Section loaded: mskeyprotect.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Section loaded: ntasn1.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Section loaded: ncrypt.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Section loaded: ncryptsslp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Section loaded: dpapi.dll | Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: fastprox.dll | Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: ncobjapi.dll | Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: wbemcomn.dll | Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: wbemcomn.dll | Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: mpclient.dll | Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: wmitomi.dll | Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: mi.dll | Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: miutils.dll | Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: miutils.dll | Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: 0.2.SIP_20252701095738583757327401213.bat.exe.35a7580.2.raw.unpack, gp9e8nuurPapEMh55ef.cs | High entropy of concatenated method names: 'CZub0lVavd', 'Lq8bz9JCtJ', 'DGtOv0UAl5', 'RDEOuPMJIS', 'bDOOh4GZWB', 'd4IOMNcKuE', 'lhhOA35Aus', 'ffvOU2WCmd', 'KJ9O7lBgfF', 'kNhOxVaJ3T' |
Source: 0.2.SIP_20252701095738583757327401213.bat.exe.35a7580.2.raw.unpack, SaoQMVga0dKmqCmBUR.cs | High entropy of concatenated method names: 'DKOcm7sdF5', 'nlycJhlLwT', 'LjVcDmSdta', 'aA5cgWQJP1', 'OnKcEE1U39', 'A7ycSxeUvj', 'wOCcIKWjWV', 'dLZceWZguS', 'YEQcHImwvA', 'ucgcbnpYkD' |
Source: 0.2.SIP_20252701095738583757327401213.bat.exe.35a7580.2.raw.unpack, YS9xHGajdZDpHY6vxG.cs | High entropy of concatenated method names: 'g4XEXHjeI8', 'alPE4iyNwm', 'XcUEaCEIJb', 'omEE2Dew9H', 'mtjEBtaxUS', 'EQYE66vQBV', 'DJmEpui7W5', 'BMuEyykcDv', 'vrIENyvX07', 'GjiEfThyD6' |
Source: 0.2.SIP_20252701095738583757327401213.bat.exe.35a7580.2.raw.unpack, cEjiH4AkU4FRKdjpu9.cs | High entropy of concatenated method names: 'MuiuC8I7Qa', 'gXkuY2PYsI', 'ma0usdKmqC', 'ABUuVRtBum', 'jOsuEYlubY', 'kxFuSSErdu', 'EXGA2L9FO63Rf1DElX', 'B6YGfSrgw8xHfYSoG3', 'FIpuu7gKVt', 'YbnuM2HvM2' |
Source: 0.2.SIP_20252701095738583757327401213.bat.exe.35a7580.2.raw.unpack, WnZmKV0mcDiJCxdulQ.cs | High entropy of concatenated method names: 'L85bc51HGp', 'OfybZmE5ex', 'yV4b9LU7fQ', 'LCPbCkBTtY', 'FW2bHrbi71', 'OydbYakoso', 'Next', 'Next', 'Next', 'NextBytes' |
Source: 0.2.SIP_20252701095738583757327401213.bat.exe.35a7580.2.raw.unpack, SqGbmHuAlvtiiBPP0Ki.cs | High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'FYHlHTZqfo', 'vEFlbPpWtq', 'fMJlO7YCfj', 'KQ9llFSglD', 'l5LlwwZuvP', 'gjZlqXXFWG', 'uAql8sTvVy' |
Source: 0.2.SIP_20252701095738583757327401213.bat.exe.35a7580.2.raw.unpack, NKvZieN2X0WbeJmkQa.cs | High entropy of concatenated method names: 'oae9jp5D1J', 'KQG9QXHv9Z', 'r8A9GUCDfV', 'ToString', 'jjx9KMhUHB', 'G5q9RtYH6H', 'obWvyICnpDwkN4OAjVy', 'psUMfYCaqo4DvMDcXX9', 'D6mlebCbfj07qy06LYh' |
Source: 0.2.SIP_20252701095738583757327401213.bat.exe.35a7580.2.raw.unpack, ojy3lVuhXRFfXlUQUAp.cs | High entropy of concatenated method names: 'ToString', 'zsoODcRQS4', 'ULuOgnMvki', 'GbdOLoSy9T', 't9HO3RDUam', 'vatOBsLbKG', 'GuGO6pve13', 'USwOp8G7Yy', 'OnE6A1sQolr8yvTvSmJ', 'fwFwo9sW6j5dEP0he6Z' |
Source: 0.2.SIP_20252701095738583757327401213.bat.exe.35a7580.2.raw.unpack, hphorVBVdgDdMyUfcY.cs | High entropy of concatenated method names: 'LcO3rwCvoULIt6LVBsw', 'XmDMs4CD5KXeRhoC0Ji', 'Ybr9eYAOPJ', 'v7Z9HWbkY2', 'oDH9bqH1YE', 'tkEY7uCXfwpkwKWdmuV', 'aOToiACjyDWxOjcZ4dv' |
Source: 0.2.SIP_20252701095738583757327401213.bat.exe.35a7580.2.raw.unpack, pluHpQhoVyGOkcwkDA.cs | High entropy of concatenated method names: 'JXfF7QF1Y', 'HJ2mTIThI', 'd9hJ7bBdG', 'ITodUxTL4', 'O4Ag78upU', 'EfLL8iJqH', 'M4lVNleP8fBKvME5QG', 'GlcELnxEo50ruZAmUd', 'kWVeRBox0', 'UOPbbkGkx' |
Source: 0.2.SIP_20252701095738583757327401213.bat.exe.35a7580.2.raw.unpack, JqM2EtcTMZICegRNmI.cs | High entropy of concatenated method names: 'EditValue', 'GetEditStyle', 'PrOh5njGPK', 'yUYh0TDZUb', 'tdOhzRj9xT', 'e2NMv28yFd', 'GDAMuZ3aKI', 'x0aMhTSfbj', 'wwcMM7qX8O', 'KRYBvxWSd6csPKNHfHi' |
Source: 0.2.SIP_20252701095738583757327401213.bat.exe.35a7580.2.raw.unpack, P1sRiJjtmA026wQ8o5.cs | High entropy of concatenated method names: 'ToString', 'nPxS1n2xWT', 'VONSBkoTgK', 'GlcS6pibnk', 'jiySpSNmcE', 'FSXSyM2Rbv', 'UxySNxYaZU', 'OQTSfdR2pG', 'YlaSo29IoA', 'HLlSth9K5k' |
Source: 0.2.SIP_20252701095738583757327401213.bat.exe.35a7580.2.raw.unpack, Obv90fQXEGtsvP0qgn.cs | High entropy of concatenated method names: 'UYuIsKA9go', 'HRgIV8ybXm', 'ToString', 'zmBI7RUaeT', 'AmfIxweHV1', 'RNsIcm7H2g', 'k2bIZwMpgW', 'ssfI9urFnh', 'SxwIChNlZZ', 'VniIYS9mtO' |
Source: 0.2.SIP_20252701095738583757327401213.bat.exe.35a7580.2.raw.unpack, YkMb9uWWdZ2Z9Y2Fnm.cs | High entropy of concatenated method names: 'ptknDLQ2go', 'VCPngRJaAJ', 'p0En3nmYJi', 'r0dnB0JWh4', 'LGOnpGI8mL', 'eLtnyNAr0t', 'stynfMFiol', 'qplnoFdTmo', 'XgXnXc9RZi', 'GuXn1wkPGU' |
Source: 0.2.SIP_20252701095738583757327401213.bat.exe.35a7580.2.raw.unpack, MBum3wL6jpxgSCOsYl.cs | High entropy of concatenated method names: 'nAnZkt7HkI', 'J1UZdtRg4f', 'T6oc6oREXF', 'MsEcpZXPso', 'FCHcyQau2G', 'pIycNLC65e', 'bKYcfSUTNa', 'eWJcor1Aae', 'CVgctnjres', 'kLycXuhPWn' |
Source: 0.2.SIP_20252701095738583757327401213.bat.exe.35a7580.2.raw.unpack, ouDawY57Lhq0xKkI5d.cs | High entropy of concatenated method names: 'HhfH3A0Q0P', 'PtIHB3BlyE', 'JERH6yJIuk', 'UAFHp9mtsB', 'HTQHyK8HSe', 'JVWHNmSbu8', 'fiVHfMugHu', 'Q4xHoqowKv', 'ihUHtIfgLh', 'Cb0HXZ9e8i' |
Source: 0.2.SIP_20252701095738583757327401213.bat.exe.35a7580.2.raw.unpack, Qs9jKmtgiShvwmS1ly.cs | High entropy of concatenated method names: 'J7uCP75lII', 'axWCTa9fqp', 'MYkCFMhYth', 'Fa9Cm8AyjX', 'rs4CkaGg3C', 'JCHCJJFDIM', 'xF0CdNkfZE', 'iZgCDaADHX', 'nDxCg2hhTD', 'VifCL1PA4H' |
Source: 0.2.SIP_20252701095738583757327401213.bat.exe.35a7580.2.raw.unpack, fdMQ04uv5bAvd0x9Z7U.cs | High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'hqAb1HlWjT', 'Jt9b4Ob8e5', 'jyDbWuNCWG', 'k3Dbaqcb4X', 'vaob2mgMI5', 'PTjbjJkNYl', 'DmSbQf7GXd' |
Source: 0.2.SIP_20252701095738583757327401213.bat.exe.35a7580.2.raw.unpack, TnLgrixmaqLqLuwAmt.cs | High entropy of concatenated method names: 'Dispose', 'DqLu5RToJZ', 'lpXhBvQDH1', 'cIQA4l1AVY', 'QRju0GPOkZ', 'G2VuzNbTP1', 'ProcessDialogKey', 'jpEhvuDawY', 'fLhhuq0xKk', 'q5dhhrnZmK' |
Source: 0.2.SIP_20252701095738583757327401213.bat.exe.35a7580.2.raw.unpack, C0v2gSYfebBXrSIvND.cs | High entropy of concatenated method names: 'fbkMUbs8WG', 'QFfM78cwtD', 'ILgMx16RkJ', 'f7sMcChM3B', 'li7MZP9VR6', 'H5IM9Iri5j', 'wiMMCQivNx', 'TJTMYIxt3K', 'cqlMiOsFMa', 'CAUMsWEwdw' |
Source: 0.2.SIP_20252701095738583757327401213.bat.exe.35a7580.2.raw.unpack, VSPvCwRdFDqLRToJZW.cs | High entropy of concatenated method names: 'V1cHEiu6in', 'WCCHI0XQPQ', 'gR9HHCx9ST', 'yJHHOblOaT', 'igcHw4yi8p', 'PfqH8IUNuB', 'Dispose', 'Vjqe70hyDh', 'S9Jex2L7kS', 'LrYecskHmP' |
Source: 0.2.SIP_20252701095738583757327401213.bat.exe.35a7580.2.raw.unpack, l8I7QaDcXk2PYsIoYp.cs | High entropy of concatenated method names: 'gOkxavZCZa', 'xbDx28akws', 'dxfxjMKtse', 'XWfxQqq4q9', 'MxDxG3TYTj', 'HWLxKhqIJN', 'FqlxRinrUL', 'SiBxrtTWSp', 'Pyix5rckT0', 'Eeex0RY9Ca' |
Source: 0.2.SIP_20252701095738583757327401213.bat.exe.35a7580.2.raw.unpack, bbYYxF3SErdu6s5aXh.cs | High entropy of concatenated method names: 'Lyr9UcECKG', 'q2X9xs2MG9', 'Cfe9ZwiFS6', 'OJR9CYVHqK', 'ofk9YunUYm', 'k2oZG3dF9S', 'bD6ZKDi3Nn', 's67ZR9sgGv', 'ctIZrQr9Un', 'dLtZ5UikMd' |
Source: 0.2.SIP_20252701095738583757327401213.bat.exe.35a7580.2.raw.unpack, GIN969p26ehoNHS6Jy.cs | High entropy of concatenated method names: 'gIQ98RZh8b', 'OiR9Pxqd2j', 'iMp9FOYxav', 'Ak19mycQQc', 'SjM9JNBhWI', 'wjB9dpYI90', 'nFQ9gIlbPU', 'BTV9L6Jr7k', 'l8uARaCP3l6wftXrW3N', 't44RwICwbg1XIHn2lrm' |
Source: 0.2.SIP_20252701095738583757327401213.bat.exe.35a7580.2.raw.unpack, CjVCnTzbdp2nMZgNV1.cs | High entropy of concatenated method names: 'KmSbJ0MD3S', 'ae3bDTIwu0', 'nyGbgig6sP', 'qnbb33cQcU', 'rW9bBSMqjd', 'FeHbpQYlmg', 'IZ9byjo9SA', 'srPb8mgIDg', 'jsBbPaJZs5', 'SkybTHK2xB' |
Source: 0.2.SIP_20252701095738583757327401213.bat.exe.35a7580.2.raw.unpack, YpRJK7Kf6BsPf4wUhW.cs | High entropy of concatenated method names: 'Og9IrHQtEp', 'IAVI0IvVD2', 'BijevO1rno', 'g7peujNojR', 'rsPI1Ab4ps', 'oHPI41QL1d', 'VXJIWNBEmm', 'dIaIaelZrm', 'jIoI2ddDn9', 'XNmIjkpHYL' |
Source: 0.2.SIP_20252701095738583757327401213.bat.exe.6aa0000.6.raw.unpack, gp9e8nuurPapEMh55ef.cs | High entropy of concatenated method names: 'CZub0lVavd', 'Lq8bz9JCtJ', 'DGtOv0UAl5', 'RDEOuPMJIS', 'bDOOh4GZWB', 'd4IOMNcKuE', 'lhhOA35Aus', 'ffvOU2WCmd', 'KJ9O7lBgfF', 'kNhOxVaJ3T' |
Source: 0.2.SIP_20252701095738583757327401213.bat.exe.6aa0000.6.raw.unpack, SaoQMVga0dKmqCmBUR.cs | High entropy of concatenated method names: 'DKOcm7sdF5', 'nlycJhlLwT', 'LjVcDmSdta', 'aA5cgWQJP1', 'OnKcEE1U39', 'A7ycSxeUvj', 'wOCcIKWjWV', 'dLZceWZguS', 'YEQcHImwvA', 'ucgcbnpYkD' |
Source: 0.2.SIP_20252701095738583757327401213.bat.exe.6aa0000.6.raw.unpack, YS9xHGajdZDpHY6vxG.cs | High entropy of concatenated method names: 'g4XEXHjeI8', 'alPE4iyNwm', 'XcUEaCEIJb', 'omEE2Dew9H', 'mtjEBtaxUS', 'EQYE66vQBV', 'DJmEpui7W5', 'BMuEyykcDv', 'vrIENyvX07', 'GjiEfThyD6' |
Source: 0.2.SIP_20252701095738583757327401213.bat.exe.6aa0000.6.raw.unpack, cEjiH4AkU4FRKdjpu9.cs | High entropy of concatenated method names: 'MuiuC8I7Qa', 'gXkuY2PYsI', 'ma0usdKmqC', 'ABUuVRtBum', 'jOsuEYlubY', 'kxFuSSErdu', 'EXGA2L9FO63Rf1DElX', 'B6YGfSrgw8xHfYSoG3', 'FIpuu7gKVt', 'YbnuM2HvM2' |
Source: 0.2.SIP_20252701095738583757327401213.bat.exe.6aa0000.6.raw.unpack, WnZmKV0mcDiJCxdulQ.cs | High entropy of concatenated method names: 'L85bc51HGp', 'OfybZmE5ex', 'yV4b9LU7fQ', 'LCPbCkBTtY', 'FW2bHrbi71', 'OydbYakoso', 'Next', 'Next', 'Next', 'NextBytes' |
Source: 0.2.SIP_20252701095738583757327401213.bat.exe.6aa0000.6.raw.unpack, SqGbmHuAlvtiiBPP0Ki.cs | High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'FYHlHTZqfo', 'vEFlbPpWtq', 'fMJlO7YCfj', 'KQ9llFSglD', 'l5LlwwZuvP', 'gjZlqXXFWG', 'uAql8sTvVy' |
Source: 0.2.SIP_20252701095738583757327401213.bat.exe.6aa0000.6.raw.unpack, NKvZieN2X0WbeJmkQa.cs | High entropy of concatenated method names: 'oae9jp5D1J', 'KQG9QXHv9Z', 'r8A9GUCDfV', 'ToString', 'jjx9KMhUHB', 'G5q9RtYH6H', 'obWvyICnpDwkN4OAjVy', 'psUMfYCaqo4DvMDcXX9', 'D6mlebCbfj07qy06LYh' |
Source: 0.2.SIP_20252701095738583757327401213.bat.exe.6aa0000.6.raw.unpack, ojy3lVuhXRFfXlUQUAp.cs | High entropy of concatenated method names: 'ToString', 'zsoODcRQS4', 'ULuOgnMvki', 'GbdOLoSy9T', 't9HO3RDUam', 'vatOBsLbKG', 'GuGO6pve13', 'USwOp8G7Yy', 'OnE6A1sQolr8yvTvSmJ', 'fwFwo9sW6j5dEP0he6Z' |
Source: 0.2.SIP_20252701095738583757327401213.bat.exe.6aa0000.6.raw.unpack, hphorVBVdgDdMyUfcY.cs | High entropy of concatenated method names: 'LcO3rwCvoULIt6LVBsw', 'XmDMs4CD5KXeRhoC0Ji', 'Ybr9eYAOPJ', 'v7Z9HWbkY2', 'oDH9bqH1YE', 'tkEY7uCXfwpkwKWdmuV', 'aOToiACjyDWxOjcZ4dv' |
Source: 0.2.SIP_20252701095738583757327401213.bat.exe.6aa0000.6.raw.unpack, pluHpQhoVyGOkcwkDA.cs | High entropy of concatenated method names: 'JXfF7QF1Y', 'HJ2mTIThI', 'd9hJ7bBdG', 'ITodUxTL4', 'O4Ag78upU', 'EfLL8iJqH', 'M4lVNleP8fBKvME5QG', 'GlcELnxEo50ruZAmUd', 'kWVeRBox0', 'UOPbbkGkx' |
Source: 0.2.SIP_20252701095738583757327401213.bat.exe.6aa0000.6.raw.unpack, JqM2EtcTMZICegRNmI.cs | High entropy of concatenated method names: 'EditValue', 'GetEditStyle', 'PrOh5njGPK', 'yUYh0TDZUb', 'tdOhzRj9xT', 'e2NMv28yFd', 'GDAMuZ3aKI', 'x0aMhTSfbj', 'wwcMM7qX8O', 'KRYBvxWSd6csPKNHfHi' |
Source: 0.2.SIP_20252701095738583757327401213.bat.exe.6aa0000.6.raw.unpack, P1sRiJjtmA026wQ8o5.cs | High entropy of concatenated method names: 'ToString', 'nPxS1n2xWT', 'VONSBkoTgK', 'GlcS6pibnk', 'jiySpSNmcE', 'FSXSyM2Rbv', 'UxySNxYaZU', 'OQTSfdR2pG', 'YlaSo29IoA', 'HLlSth9K5k' |
Source: 0.2.SIP_20252701095738583757327401213.bat.exe.6aa0000.6.raw.unpack, Obv90fQXEGtsvP0qgn.cs | High entropy of concatenated method names: 'UYuIsKA9go', 'HRgIV8ybXm', 'ToString', 'zmBI7RUaeT', 'AmfIxweHV1', 'RNsIcm7H2g', 'k2bIZwMpgW', 'ssfI9urFnh', 'SxwIChNlZZ', 'VniIYS9mtO' |
Source: 0.2.SIP_20252701095738583757327401213.bat.exe.6aa0000.6.raw.unpack, YkMb9uWWdZ2Z9Y2Fnm.cs | High entropy of concatenated method names: 'ptknDLQ2go', 'VCPngRJaAJ', 'p0En3nmYJi', 'r0dnB0JWh4', 'LGOnpGI8mL', 'eLtnyNAr0t', 'stynfMFiol', 'qplnoFdTmo', 'XgXnXc9RZi', 'GuXn1wkPGU' |
Source: 0.2.SIP_20252701095738583757327401213.bat.exe.6aa0000.6.raw.unpack, MBum3wL6jpxgSCOsYl.cs | High entropy of concatenated method names: 'nAnZkt7HkI', 'J1UZdtRg4f', 'T6oc6oREXF', 'MsEcpZXPso', 'FCHcyQau2G', 'pIycNLC65e', 'bKYcfSUTNa', 'eWJcor1Aae', 'CVgctnjres', 'kLycXuhPWn' |
Source: 0.2.SIP_20252701095738583757327401213.bat.exe.6aa0000.6.raw.unpack, ouDawY57Lhq0xKkI5d.cs | High entropy of concatenated method names: 'HhfH3A0Q0P', 'PtIHB3BlyE', 'JERH6yJIuk', 'UAFHp9mtsB', 'HTQHyK8HSe', 'JVWHNmSbu8', 'fiVHfMugHu', 'Q4xHoqowKv', 'ihUHtIfgLh', 'Cb0HXZ9e8i' |
Source: 0.2.SIP_20252701095738583757327401213.bat.exe.6aa0000.6.raw.unpack, Qs9jKmtgiShvwmS1ly.cs | High entropy of concatenated method names: 'J7uCP75lII', 'axWCTa9fqp', 'MYkCFMhYth', 'Fa9Cm8AyjX', 'rs4CkaGg3C', 'JCHCJJFDIM', 'xF0CdNkfZE', 'iZgCDaADHX', 'nDxCg2hhTD', 'VifCL1PA4H' |
Source: 0.2.SIP_20252701095738583757327401213.bat.exe.6aa0000.6.raw.unpack, fdMQ04uv5bAvd0x9Z7U.cs | High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'hqAb1HlWjT', 'Jt9b4Ob8e5', 'jyDbWuNCWG', 'k3Dbaqcb4X', 'vaob2mgMI5', 'PTjbjJkNYl', 'DmSbQf7GXd' |
Source: 0.2.SIP_20252701095738583757327401213.bat.exe.6aa0000.6.raw.unpack, TnLgrixmaqLqLuwAmt.cs | High entropy of concatenated method names: 'Dispose', 'DqLu5RToJZ', 'lpXhBvQDH1', 'cIQA4l1AVY', 'QRju0GPOkZ', 'G2VuzNbTP1', 'ProcessDialogKey', 'jpEhvuDawY', 'fLhhuq0xKk', 'q5dhhrnZmK' |
Source: 0.2.SIP_20252701095738583757327401213.bat.exe.6aa0000.6.raw.unpack, C0v2gSYfebBXrSIvND.cs | High entropy of concatenated method names: 'fbkMUbs8WG', 'QFfM78cwtD', 'ILgMx16RkJ', 'f7sMcChM3B', 'li7MZP9VR6', 'H5IM9Iri5j', 'wiMMCQivNx', 'TJTMYIxt3K', 'cqlMiOsFMa', 'CAUMsWEwdw' |
Source: 0.2.SIP_20252701095738583757327401213.bat.exe.6aa0000.6.raw.unpack, VSPvCwRdFDqLRToJZW.cs | High entropy of concatenated method names: 'V1cHEiu6in', 'WCCHI0XQPQ', 'gR9HHCx9ST', 'yJHHOblOaT', 'igcHw4yi8p', 'PfqH8IUNuB', 'Dispose', 'Vjqe70hyDh', 'S9Jex2L7kS', 'LrYecskHmP' |
Source: 0.2.SIP_20252701095738583757327401213.bat.exe.6aa0000.6.raw.unpack, l8I7QaDcXk2PYsIoYp.cs | High entropy of concatenated method names: 'gOkxavZCZa', 'xbDx28akws', 'dxfxjMKtse', 'XWfxQqq4q9', 'MxDxG3TYTj', 'HWLxKhqIJN', 'FqlxRinrUL', 'SiBxrtTWSp', 'Pyix5rckT0', 'Eeex0RY9Ca' |
Source: 0.2.SIP_20252701095738583757327401213.bat.exe.6aa0000.6.raw.unpack, bbYYxF3SErdu6s5aXh.cs | High entropy of concatenated method names: 'Lyr9UcECKG', 'q2X9xs2MG9', 'Cfe9ZwiFS6', 'OJR9CYVHqK', 'ofk9YunUYm', 'k2oZG3dF9S', 'bD6ZKDi3Nn', 's67ZR9sgGv', 'ctIZrQr9Un', 'dLtZ5UikMd' |
Source: 0.2.SIP_20252701095738583757327401213.bat.exe.6aa0000.6.raw.unpack, GIN969p26ehoNHS6Jy.cs | High entropy of concatenated method names: 'gIQ98RZh8b', 'OiR9Pxqd2j', 'iMp9FOYxav', 'Ak19mycQQc', 'SjM9JNBhWI', 'wjB9dpYI90', 'nFQ9gIlbPU', 'BTV9L6Jr7k', 'l8uARaCP3l6wftXrW3N', 't44RwICwbg1XIHn2lrm' |
Source: 0.2.SIP_20252701095738583757327401213.bat.exe.6aa0000.6.raw.unpack, CjVCnTzbdp2nMZgNV1.cs | High entropy of concatenated method names: 'KmSbJ0MD3S', 'ae3bDTIwu0', 'nyGbgig6sP', 'qnbb33cQcU', 'rW9bBSMqjd', 'FeHbpQYlmg', 'IZ9byjo9SA', 'srPb8mgIDg', 'jsBbPaJZs5', 'SkybTHK2xB' |
Source: 0.2.SIP_20252701095738583757327401213.bat.exe.6aa0000.6.raw.unpack, YpRJK7Kf6BsPf4wUhW.cs | High entropy of concatenated method names: 'Og9IrHQtEp', 'IAVI0IvVD2', 'BijevO1rno', 'g7peujNojR', 'rsPI1Ab4ps', 'oHPI41QL1d', 'VXJIWNBEmm', 'dIaIaelZrm', 'jIoI2ddDn9', 'XNmIjkpHYL' |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Queries volume information: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Queries volume information: C:\Windows\Fonts\micross.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\ VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-GroupPolicy-ClientTools-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-AppManagement-AppV-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\Microsoft.Management.Infrastructure.Native\v4.0_1.0.0.0__31bf3856ad364e35\Microsoft.Management.Infrastructure.Native.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\AppvClient\Microsoft.AppV.AppVClientPowerShell.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1865.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-WOW64-Package~31bf3856ad364e35~amd64~en-GB~10.0.19041.1.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\BitLocker\Microsoft.BitLocker.Structures.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management\v4.0_3.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Management.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Queries volume information: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Security\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Security.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.Extensions\v4.0_4.0.0.0__31bf3856ad364e35\System.Web.Extensions.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\SIP_20252701095738583757327401213.bat.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation | Jump to behavior |