Source: New Order Inquiry.PDF.exe, 00000002.00000002.493883297.00000000032E1000.00000004.00000001.sdmp |
String found in binary or memory: http://127.0.0.1:HTTP/1.1 |
Source: New Order Inquiry.PDF.exe, 00000002.00000002.493883297.00000000032E1000.00000004.00000001.sdmp |
String found in binary or memory: http://DynDns.comDynDNS |
Source: New Order Inquiry.PDF.exe, 00000002.00000002.496450719.00000000035FB000.00000004.00000001.sdmp |
String found in binary or memory: http://smtp.divasvalves.com |
Source: New Order Inquiry.PDF.exe, 00000002.00000002.496450719.00000000035FB000.00000004.00000001.sdmp |
String found in binary or memory: http://us2.smtp.mailhostbox.com |
Source: New Order Inquiry.PDF.exe, 00000002.00000002.493883297.00000000032E1000.00000004.00000001.sdmp |
String found in binary or memory: http://zwdNmL.com |
Source: New Order Inquiry.PDF.exe, 00000002.00000002.493883297.00000000032E1000.00000004.00000001.sdmp, New Order Inquiry.PDF.exe, 00000002.00000003.445087309.0000000001554000.00000004.00000001.sdmp |
String found in binary or memory: https://8vhVWmhsLg6p.com |
Source: New Order Inquiry.PDF.exe, 00000002.00000002.493883297.00000000032E1000.00000004.00000001.sdmp |
String found in binary or memory: https://8vhVWmhsLg6p.comH#7 |
Source: New Order Inquiry.PDF.exe, 00000002.00000002.493883297.00000000032E1000.00000004.00000001.sdmp |
String found in binary or memory: https://api.ipify.orgGETMozilla/5.0 |
Source: New Order Inquiry.PDF.exe, 00000000.00000002.231364054.0000000003469000.00000004.00000001.sdmp, New Order Inquiry.PDF.exe, 00000002.00000002.489798075.0000000000402000.00000040.00000001.sdmp |
String found in binary or memory: https://api.telegram.org/bot%telegramapi%/ |
Source: New Order Inquiry.PDF.exe, 00000002.00000002.493883297.00000000032E1000.00000004.00000001.sdmp |
String found in binary or memory: https://api.telegram.org/bot%telegramapi%/sendDocumentdocument---------------------------x |
Source: New Order Inquiry.PDF.exe, 00000000.00000002.231364054.0000000003469000.00000004.00000001.sdmp, New Order Inquiry.PDF.exe, 00000002.00000002.489798075.0000000000402000.00000040.00000001.sdmp |
String found in binary or memory: https://www.theonionrouter.com/dist.torproject.org/torbrowser/9.5.3/tor-win32-0.4.3.6.zip |
Source: New Order Inquiry.PDF.exe, 00000002.00000002.493883297.00000000032E1000.00000004.00000001.sdmp |
String found in binary or memory: https://www.theonionrouter.com/dist.torproject.org/torbrowser/9.5.3/tor-win32-0.4.3.6.zip%tordir%%ha |
Source: New Order Inquiry.PDF.exe, MMqB??p??W/??BuWDp??pvBH.cs |
Long String: Length: 81136 |
Source: 0.0.New Order Inquiry.PDF.exe.70000.0.unpack, MMqB??p??W/??BuWDp??pvBH.cs |
Long String: Length: 81136 |
Source: 0.2.New Order Inquiry.PDF.exe.70000.0.unpack, MMqB??p??W/??BuWDp??pvBH.cs |
Long String: Length: 81136 |
Source: 2.2.New Order Inquiry.PDF.exe.ed0000.1.unpack, MMqB??p??W/??BuWDp??pvBH.cs |
Long String: Length: 81136 |
Source: 2.0.New Order Inquiry.PDF.exe.ed0000.0.unpack, MMqB??p??W/??BuWDp??pvBH.cs |
Long String: Length: 81136 |
Source: C:\Users\user\Desktop\New Order Inquiry.PDF.exe |
Code function: 0_2_009CA908 |
0_2_009CA908 |
Source: C:\Users\user\Desktop\New Order Inquiry.PDF.exe |
Code function: 0_2_009C9CF0 |
0_2_009C9CF0 |
Source: C:\Users\user\Desktop\New Order Inquiry.PDF.exe |
Code function: 0_2_009C7F7E |
0_2_009C7F7E |
Source: C:\Users\user\Desktop\New Order Inquiry.PDF.exe |
Code function: 0_2_009C6B64 |
0_2_009C6B64 |
Source: C:\Users\user\Desktop\New Order Inquiry.PDF.exe |
Code function: 2_2_016E4860 |
2_2_016E4860 |
Source: C:\Users\user\Desktop\New Order Inquiry.PDF.exe |
Code function: 2_2_016E3D9C |
2_2_016E3D9C |
Source: C:\Users\user\Desktop\New Order Inquiry.PDF.exe |
Code function: 2_2_016E4770 |
2_2_016E4770 |
Source: C:\Users\user\Desktop\New Order Inquiry.PDF.exe |
Code function: 2_2_016E4852 |
2_2_016E4852 |
Source: C:\Users\user\Desktop\New Order Inquiry.PDF.exe |
Code function: 2_2_016E4810 |
2_2_016E4810 |
Source: C:\Users\user\Desktop\New Order Inquiry.PDF.exe |
Code function: 2_2_016E5550 |
2_2_016E5550 |
Source: C:\Users\user\Desktop\New Order Inquiry.PDF.exe |
Code function: 2_2_017059F8 |
2_2_017059F8 |
Source: C:\Users\user\Desktop\New Order Inquiry.PDF.exe |
Code function: 2_2_017008F6 |
2_2_017008F6 |
Source: C:\Users\user\Desktop\New Order Inquiry.PDF.exe |
Code function: 2_2_01704B30 |
2_2_01704B30 |
Source: C:\Users\user\Desktop\New Order Inquiry.PDF.exe |
Code function: 2_2_01708D98 |
2_2_01708D98 |
Source: C:\Users\user\Desktop\New Order Inquiry.PDF.exe |
Code function: 2_2_0170B420 |
2_2_0170B420 |
Source: C:\Users\user\Desktop\New Order Inquiry.PDF.exe |
Code function: 2_2_01700FB4 |
2_2_01700FB4 |
Source: C:\Users\user\Desktop\New Order Inquiry.PDF.exe |
Code function: 2_2_0170D928 |
2_2_0170D928 |
Source: C:\Users\user\Desktop\New Order Inquiry.PDF.exe |
Code function: 2_2_0170D550 |
2_2_0170D550 |
Source: C:\Users\user\Desktop\New Order Inquiry.PDF.exe |
Code function: 2_2_01709F88 |
2_2_01709F88 |
Source: C:\Users\user\Desktop\New Order Inquiry.PDF.exe |
Code function: 2_2_01736510 |
2_2_01736510 |
Source: C:\Users\user\Desktop\New Order Inquiry.PDF.exe |
Code function: 2_2_01735DD8 |
2_2_01735DD8 |
Source: C:\Users\user\Desktop\New Order Inquiry.PDF.exe |
Code function: 2_2_017323BB |
2_2_017323BB |
Source: C:\Users\user\Desktop\New Order Inquiry.PDF.exe |
Code function: 2_2_017357A0 |
2_2_017357A0 |
Source: New Order Inquiry.PDF.exe, 00000000.00000002.235583981.0000000005971000.00000004.00000001.sdmp |
Binary or memory string: OriginalFilenameNT1.dll, vs New Order Inquiry.PDF.exe |
Source: New Order Inquiry.PDF.exe, 00000000.00000002.230902914.0000000002461000.00000004.00000001.sdmp |
Binary or memory string: OriginalFilenamexQPaXEtXLxQxMXsDyBVeeCdxdcLaKUF.exe4 vs New Order Inquiry.PDF.exe |
Source: New Order Inquiry.PDF.exe, 00000000.00000000.221683014.0000000000118000.00000002.00020000.sdmp |
Binary or memory string: OriginalFilenameContinuationTaskFromTask.exe@ vs New Order Inquiry.PDF.exe |
Source: New Order Inquiry.PDF.exe, 00000000.00000002.231364054.0000000003469000.00000004.00000001.sdmp |
Binary or memory string: OriginalFilenameGlaxoSmithKline.dll@ vs New Order Inquiry.PDF.exe |
Source: New Order Inquiry.PDF.exe, 00000002.00000002.493347759.00000000018D0000.00000002.00000001.sdmp |
Binary or memory string: OriginalFilenamewshom.ocx.mui vs New Order Inquiry.PDF.exe |
Source: New Order Inquiry.PDF.exe, 00000002.00000002.489798075.0000000000402000.00000040.00000001.sdmp |
Binary or memory string: OriginalFilenamexQPaXEtXLxQxMXsDyBVeeCdxdcLaKUF.exe4 vs New Order Inquiry.PDF.exe |
Source: New Order Inquiry.PDF.exe, 00000002.00000002.499432901.0000000006720000.00000002.00000001.sdmp |
Binary or memory string: OriginalFilenamemscorrc.dllT vs New Order Inquiry.PDF.exe |
Source: New Order Inquiry.PDF.exe, 00000002.00000002.491234427.0000000001338000.00000004.00000001.sdmp |
Binary or memory string: OriginalFilenameUNKNOWN_FILET vs New Order Inquiry.PDF.exe |
Source: New Order Inquiry.PDF.exe, 00000002.00000002.493326344.00000000018C0000.00000002.00000001.sdmp |
Binary or memory string: OriginalFilenamewshom.ocx vs New Order Inquiry.PDF.exe |
Source: New Order Inquiry.PDF.exe, 00000002.00000002.491149432.0000000000F78000.00000002.00020000.sdmp |
Binary or memory string: OriginalFilenameContinuationTaskFromTask.exe@ vs New Order Inquiry.PDF.exe |
Source: New Order Inquiry.PDF.exe |
Binary or memory string: OriginalFilenameContinuationTaskFromTask.exe@ vs New Order Inquiry.PDF.exe |
Source: C:\Users\user\Desktop\New Order Inquiry.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\New Order Inquiry.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\New Order Inquiry.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\New Order Inquiry.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\New Order Inquiry.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\New Order Inquiry.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\New Order Inquiry.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\New Order Inquiry.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\New Order Inquiry.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\New Order Inquiry.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\New Order Inquiry.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\New Order Inquiry.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\New Order Inquiry.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\New Order Inquiry.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\New Order Inquiry.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\New Order Inquiry.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\New Order Inquiry.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\New Order Inquiry.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\New Order Inquiry.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\New Order Inquiry.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\New Order Inquiry.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\New Order Inquiry.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\New Order Inquiry.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\New Order Inquiry.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\New Order Inquiry.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\New Order Inquiry.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\New Order Inquiry.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\New Order Inquiry.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\New Order Inquiry.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\New Order Inquiry.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\New Order Inquiry.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\New Order Inquiry.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\New Order Inquiry.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\New Order Inquiry.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\New Order Inquiry.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\New Order Inquiry.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\New Order Inquiry.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\New Order Inquiry.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\New Order Inquiry.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\New Order Inquiry.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\New Order Inquiry.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\New Order Inquiry.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\New Order Inquiry.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\New Order Inquiry.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\New Order Inquiry.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\New Order Inquiry.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\New Order Inquiry.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\New Order Inquiry.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\New Order Inquiry.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\New Order Inquiry.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\New Order Inquiry.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\New Order Inquiry.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\New Order Inquiry.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\New Order Inquiry.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\New Order Inquiry.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\New Order Inquiry.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\New Order Inquiry.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\New Order Inquiry.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\New Order Inquiry.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\New Order Inquiry.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\New Order Inquiry.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\New Order Inquiry.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\New Order Inquiry.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\New Order Inquiry.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\New Order Inquiry.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\New Order Inquiry.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\New Order Inquiry.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\New Order Inquiry.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\New Order Inquiry.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\New Order Inquiry.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\New Order Inquiry.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\New Order Inquiry.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\New Order Inquiry.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\New Order Inquiry.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\New Order Inquiry.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\New Order Inquiry.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\New Order Inquiry.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\New Order Inquiry.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\New Order Inquiry.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\New Order Inquiry.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\New Order Inquiry.PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\New Order Inquiry.PDF.exe |
Queries volume information: C:\Users\user\Desktop\New Order Inquiry.PDF.exe VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\New Order Inquiry.PDF.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\New Order Inquiry.PDF.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\New Order Inquiry.PDF.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\New Order Inquiry.PDF.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\New Order Inquiry.PDF.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\New Order Inquiry.PDF.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\New Order Inquiry.PDF.exe |
Queries volume information: C:\Users\user\Desktop\New Order Inquiry.PDF.exe VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\New Order Inquiry.PDF.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\New Order Inquiry.PDF.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\New Order Inquiry.PDF.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\CustomMarshalers\v4.0_4.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\New Order Inquiry.PDF.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\CustomMarshalers\v4.0_4.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\New Order Inquiry.PDF.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\CustomMarshalers\v4.0_4.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\New Order Inquiry.PDF.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Management\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Management.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\New Order Inquiry.PDF.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\New Order Inquiry.PDF.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation |
Jump to behavior |