Source: DOC031022-03102022004246_Squamose_10-2022-06.exe, 00000000.00000002.512795226.00000000027A6000.00000004.00000800.00020000.00000000.sdmp, DOC031022-03102022004246_Squamose_10-2022-06.exe, 00000000.00000002.512094248.000000000040A000.00000004.00000001.01000000.00000003.sdmp, lang-1026.dll.0.dr |
String found in binary or memory: http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0 |
Source: DOC031022-03102022004246_Squamose_10-2022-06.exe, 00000000.00000002.512795226.00000000027A6000.00000004.00000800.00020000.00000000.sdmp, DOC031022-03102022004246_Squamose_10-2022-06.exe, 00000000.00000002.512094248.000000000040A000.00000004.00000001.01000000.00000003.sdmp, lang-1026.dll.0.dr |
String found in binary or memory: http://cacerts.digicert.com/DigiCertSHA2AssuredIDCodeSigningCA.crt0 |
Source: DOC031022-03102022004246_Squamose_10-2022-06.exe, 00000000.00000002.512795226.00000000027A6000.00000004.00000800.00020000.00000000.sdmp, DOC031022-03102022004246_Squamose_10-2022-06.exe, 00000000.00000002.512094248.000000000040A000.00000004.00000001.01000000.00000003.sdmp, lang-1026.dll.0.dr |
String found in binary or memory: http://cacerts.digicert.com/DigiCertSHA2AssuredIDTimestampingCA.crt0 |
Source: DOC031022-03102022004246_Squamose_10-2022-06.exe, 00000000.00000002.512795226.00000000027A6000.00000004.00000800.00020000.00000000.sdmp, DOC031022-03102022004246_Squamose_10-2022-06.exe, 00000000.00000002.512094248.000000000040A000.00000004.00000001.01000000.00000003.sdmp, lang-1026.dll.0.dr |
String found in binary or memory: http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0O |
Source: DOC031022-03102022004246_Squamose_10-2022-06.exe, 00000000.00000002.512795226.00000000027A6000.00000004.00000800.00020000.00000000.sdmp, DOC031022-03102022004246_Squamose_10-2022-06.exe, 00000000.00000002.512094248.000000000040A000.00000004.00000001.01000000.00000003.sdmp, lang-1026.dll.0.dr |
String found in binary or memory: http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0P |
Source: DOC031022-03102022004246_Squamose_10-2022-06.exe, 00000000.00000002.512795226.00000000027A6000.00000004.00000800.00020000.00000000.sdmp, DOC031022-03102022004246_Squamose_10-2022-06.exe, 00000000.00000002.512094248.000000000040A000.00000004.00000001.01000000.00000003.sdmp, lang-1026.dll.0.dr |
String found in binary or memory: http://crl3.digicert.com/sha2-assured-cs-g1.crl05 |
Source: DOC031022-03102022004246_Squamose_10-2022-06.exe, 00000000.00000002.512795226.00000000027A6000.00000004.00000800.00020000.00000000.sdmp, DOC031022-03102022004246_Squamose_10-2022-06.exe, 00000000.00000002.512094248.000000000040A000.00000004.00000001.01000000.00000003.sdmp, lang-1026.dll.0.dr |
String found in binary or memory: http://crl3.digicert.com/sha2-assured-ts.crl02 |
Source: DOC031022-03102022004246_Squamose_10-2022-06.exe, 00000000.00000002.512795226.00000000027A6000.00000004.00000800.00020000.00000000.sdmp, DOC031022-03102022004246_Squamose_10-2022-06.exe, 00000000.00000002.512094248.000000000040A000.00000004.00000001.01000000.00000003.sdmp, lang-1026.dll.0.dr |
String found in binary or memory: http://crl4.digicert.com/DigiCertAssuredIDRootCA.crl0: |
Source: DOC031022-03102022004246_Squamose_10-2022-06.exe, 00000000.00000002.512795226.00000000027A6000.00000004.00000800.00020000.00000000.sdmp, DOC031022-03102022004246_Squamose_10-2022-06.exe, 00000000.00000002.512094248.000000000040A000.00000004.00000001.01000000.00000003.sdmp, lang-1026.dll.0.dr |
String found in binary or memory: http://crl4.digicert.com/sha2-assured-cs-g1.crl0L |
Source: DOC031022-03102022004246_Squamose_10-2022-06.exe, 00000000.00000002.512795226.00000000027A6000.00000004.00000800.00020000.00000000.sdmp, DOC031022-03102022004246_Squamose_10-2022-06.exe, 00000000.00000002.512094248.000000000040A000.00000004.00000001.01000000.00000003.sdmp, lang-1026.dll.0.dr |
String found in binary or memory: http://crl4.digicert.com/sha2-assured-ts.crl0 |
Source: DOC031022-03102022004246_Squamose_10-2022-06.exe |
String found in binary or memory: http://nsis.sf.net/NSIS_Error |
Source: DOC031022-03102022004246_Squamose_10-2022-06.exe |
String found in binary or memory: http://nsis.sf.net/NSIS_ErrorError |
Source: DOC031022-03102022004246_Squamose_10-2022-06.exe, 00000000.00000002.512795226.00000000027A6000.00000004.00000800.00020000.00000000.sdmp, DOC031022-03102022004246_Squamose_10-2022-06.exe, 00000000.00000002.512094248.000000000040A000.00000004.00000001.01000000.00000003.sdmp, lang-1026.dll.0.dr |
String found in binary or memory: http://ocsp.digicert.com0C |
Source: DOC031022-03102022004246_Squamose_10-2022-06.exe, 00000000.00000002.512795226.00000000027A6000.00000004.00000800.00020000.00000000.sdmp, DOC031022-03102022004246_Squamose_10-2022-06.exe, 00000000.00000002.512094248.000000000040A000.00000004.00000001.01000000.00000003.sdmp, lang-1026.dll.0.dr |
String found in binary or memory: http://ocsp.digicert.com0N |
Source: DOC031022-03102022004246_Squamose_10-2022-06.exe, 00000000.00000002.512795226.00000000027A6000.00000004.00000800.00020000.00000000.sdmp, DOC031022-03102022004246_Squamose_10-2022-06.exe, 00000000.00000002.512094248.000000000040A000.00000004.00000001.01000000.00000003.sdmp, lang-1026.dll.0.dr |
String found in binary or memory: http://ocsp.digicert.com0O |
Source: DOC031022-03102022004246_Squamose_10-2022-06.exe, 00000000.00000002.512795226.00000000027A6000.00000004.00000800.00020000.00000000.sdmp, DOC031022-03102022004246_Squamose_10-2022-06.exe, 00000000.00000002.512094248.000000000040A000.00000004.00000001.01000000.00000003.sdmp, lang-1026.dll.0.dr |
String found in binary or memory: http://www.avast.com0/ |
Source: DOC031022-03102022004246_Squamose_10-2022-06.exe, 00000000.00000002.512795226.00000000027A6000.00000004.00000800.00020000.00000000.sdmp, DOC031022-03102022004246_Squamose_10-2022-06.exe, 00000000.00000002.512094248.000000000040A000.00000004.00000001.01000000.00000003.sdmp, lang-1026.dll.0.dr |
String found in binary or memory: http://www.digicert.com/CPS0 |
Source: DOC031022-03102022004246_Squamose_10-2022-06.exe, 00000000.00000002.512795226.00000000027A6000.00000004.00000800.00020000.00000000.sdmp, DOC031022-03102022004246_Squamose_10-2022-06.exe, 00000000.00000002.512094248.000000000040A000.00000004.00000001.01000000.00000003.sdmp, lang-1026.dll.0.dr |
String found in binary or memory: https://www.digicert.com/CPS0 |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Code function: 0_2_00406725 |
0_2_00406725 |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Code function: 0_2_00404B3D |
0_2_00404B3D |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Code function: 0_2_00651C64 |
0_2_00651C64 |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Code function: 0_2_0065186F |
0_2_0065186F |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Code function: 0_2_00651872 |
0_2_00651872 |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Code function: 0_2_00655044 |
0_2_00655044 |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Code function: 0_2_00650054 |
0_2_00650054 |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Code function: 0_2_0065045E |
0_2_0065045E |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Code function: 0_2_00651C28 |
0_2_00651C28 |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Code function: 0_2_00651837 |
0_2_00651837 |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Code function: 0_2_00650001 |
0_2_00650001 |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Code function: 0_2_0065D40E |
0_2_0065D40E |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Code function: 0_2_0065E409 |
0_2_0065E409 |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Code function: 0_2_00650814 |
0_2_00650814 |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Code function: 0_2_00650410 |
0_2_00650410 |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Code function: 0_2_006524EB |
0_2_006524EB |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Code function: 0_2_006500CC |
0_2_006500CC |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Code function: 0_2_006504C9 |
0_2_006504C9 |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Code function: 0_2_006508DF |
0_2_006508DF |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Code function: 0_2_006518DE |
0_2_006518DE |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Code function: 0_2_00651CA4 |
0_2_00651CA4 |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Code function: 0_2_006518A3 |
0_2_006518A3 |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Code function: 0_2_0065048F |
0_2_0065048F |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Code function: 0_2_00655492 |
0_2_00655492 |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Code function: 0_2_0065009C |
0_2_0065009C |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Code function: 0_2_00655166 |
0_2_00655166 |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Code function: 0_2_00651D7C |
0_2_00651D7C |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Code function: 0_2_0065057A |
0_2_0065057A |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Code function: 0_2_0065F145 |
0_2_0065F145 |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Code function: 0_2_0065014A |
0_2_0065014A |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Code function: 0_2_0065555F |
0_2_0065555F |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Code function: 0_2_0065095A |
0_2_0065095A |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Code function: 0_2_00651927 |
0_2_00651927 |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Code function: 0_2_00655123 |
0_2_00655123 |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Code function: 0_2_0065053F |
0_2_0065053F |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Code function: 0_2_0065050D |
0_2_0065050D |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Code function: 0_2_0065010A |
0_2_0065010A |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Code function: 0_2_00651D14 |
0_2_00651D14 |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Code function: 0_2_0065091B |
0_2_0065091B |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Code function: 0_2_00660DE8 |
0_2_00660DE8 |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Code function: 0_2_006509F7 |
0_2_006509F7 |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Code function: 0_2_006505C4 |
0_2_006505C4 |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Code function: 0_2_006501C6 |
0_2_006501C6 |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Code function: 0_2_006519C6 |
0_2_006519C6 |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Code function: 0_2_006519C9 |
0_2_006519C9 |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Code function: 0_2_006565CB |
0_2_006565CB |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Code function: 0_2_00650DAF |
0_2_00650DAF |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Code function: 0_2_00650183 |
0_2_00650183 |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Code function: 0_2_00651988 |
0_2_00651988 |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Code function: 0_2_0065098A |
0_2_0065098A |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Code function: 0_2_00651660 |
0_2_00651660 |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Code function: 0_2_00650676 |
0_2_00650676 |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Code function: 0_2_00651670 |
0_2_00651670 |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Code function: 0_2_00650A42 |
0_2_00650A42 |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Code function: 0_2_00650251 |
0_2_00650251 |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Code function: 0_2_00658E5A |
0_2_00658E5A |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Code function: 0_2_0065DA32 |
0_2_0065DA32 |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Code function: 0_2_00651A04 |
0_2_00651A04 |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Code function: 0_2_00650600 |
0_2_00650600 |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Code function: 0_2_0065020A |
0_2_0065020A |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Code function: 0_2_00658AE5 |
0_2_00658AE5 |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Code function: 0_2_0065DEE9 |
0_2_0065DEE9 |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Code function: 0_2_006506EA |
0_2_006506EA |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Code function: 0_2_006516F6 |
0_2_006516F6 |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Code function: 0_2_006562D2 |
0_2_006562D2 |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Code function: 0_2_00650EB4 |
0_2_00650EB4 |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Code function: 0_2_00650ABD |
0_2_00650ABD |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Code function: 0_2_006502BC |
0_2_006502BC |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Code function: 0_2_006516B8 |
0_2_006516B8 |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Code function: 0_2_00650A83 |
0_2_00650A83 |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Code function: 0_2_00651A9A |
0_2_00651A9A |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Code function: 0_2_00650763 |
0_2_00650763 |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Code function: 0_2_00650340 |
0_2_00650340 |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Code function: 0_2_00651B53 |
0_2_00651B53 |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Code function: 0_2_0065F325 |
0_2_0065F325 |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Code function: 0_2_00650B27 |
0_2_00650B27 |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Code function: 0_2_00655F2F |
0_2_00655F2F |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Code function: 0_2_0065173C |
0_2_0065173C |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Code function: 0_2_00650306 |
0_2_00650306 |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Code function: 0_2_00658306 |
0_2_00658306 |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Code function: 0_2_00651B0D |
0_2_00651B0D |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Code function: 0_2_00650BF7 |
0_2_00650BF7 |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Code function: 0_2_006517FC |
0_2_006517FC |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Code function: 0_2_006517C5 |
0_2_006517C5 |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Code function: 0_2_006503CA |
0_2_006503CA |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Code function: 0_2_006507DD |
0_2_006507DD |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Code function: 0_2_00650BBF |
0_2_00650BBF |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Code function: 0_2_00651781 |
0_2_00651781 |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Code function: 0_2_00650380 |
0_2_00650380 |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Code function: 0_2_00651B83 |
0_2_00651B83 |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Code function: 0_2_00650B8C |
0_2_00650B8C |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Code function: 0_2_00650792 |
0_2_00650792 |
Source: unknown |
Process created: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
|
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x6B6570CB -bxor 677 |
|
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x656C3197 -bxor 677 |
|
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x3A3A41D7 -bxor 677 |
|
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x656176C0 -bxor 677 |
|
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x46696EC0 -bxor 677 |
|
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x41286F85 -bxor 677 |
|
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x72342289 -bxor 677 |
|
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x20692295 -bxor 677 |
|
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x78383295 -bxor 677 |
|
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x30303295 -bxor 677 |
|
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x302C22CC -bxor 677 |
|
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x20302E85 -bxor 677 |
|
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x70203289 -bxor 677 |
|
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x20692291 -bxor 677 |
|
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x2C206B85 -bxor 677 |
|
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x30783A95 -bxor 677 |
|
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x2C206B85 -bxor 677 |
|
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x30296B8B -bxor 677 |
|
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x723322FC -bxor 677 |
|
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x6B6570CB -bxor 677 |
|
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x656C3197 -bxor 677 |
|
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x3A3A54CC -bxor 677 |
|
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x727477C4 -bxor 677 |
|
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x6C416EC9 -bxor 677 |
|
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x6F632ACC -bxor 677 |
|
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x30783395 -bxor 677 |
|
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x30303295 -bxor 677 |
|
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x2C206B85 -bxor 677 |
|
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x30783195 -bxor 677 |
|
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x30302E85 -bxor 677 |
|
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x692032DD -bxor 677 |
|
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x34302BD5 -bxor 677 |
|
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x6B6570CB -bxor 677 |
|
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x656C3197 -bxor 677 |
|
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x3A3A51C0 -bxor 677 |
|
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x74466BC9 -bxor 677 |
|
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x65506DCC -bxor 677 |
|
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x6E7467D7 -bxor 677 |
|
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x28697096 -bxor 677 |
|
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x2C206B85 -bxor 677 |
|
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x31343091 -bxor 677 |
|
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x202C22CC -bxor 677 |
|
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x20302ECC -bxor 677 |
|
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x20302BCC -bxor 677 |
|
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x2E7230FC -bxor 677 |
|
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x6B6570CB -bxor 677 |
|
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x656C3197 -bxor 677 |
|
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x6C652ACC -bxor 677 |
|
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x72332E85 -bxor 677 |
|
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x69207094 -bxor 677 |
|
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x2C206B85 -bxor 677 |
|
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x30303295 -bxor 677 |
|
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x2C2A6B85 -bxor 677 |
|
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x20302BCC -bxor 677 |
|
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x3332389F -bxor 677 |
|
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x43616EC9 -bxor 677 |
|
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x57696CC1 -bxor 677 |
|
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x6F7752D7 -bxor 677 |
|
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x69723385 -bxor 677 |
|
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x2C692295 -bxor 677 |
|
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x2C206B85 -bxor 677 |
|
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x302C22CC -bxor 677 |
|
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x20302BFC -bxor 677 |
|
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x6B6570CB -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x656C3197 -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x3A3A41D7 -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x656176C0 -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x46696EC0 -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x41286F85 -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x72342289 -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x20692295 -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x78383295 -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x30303295 -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x302C22CC -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x20302E85 -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x70203289 -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x20692291 -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x2C206B85 -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x30783A95 -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x2C206B85 -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x30296B8B -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x723322FC -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x6B6570CB -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x656C3197 -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x3A3A54CC -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x727477C4 -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x6C416EC9 -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x20692291 -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x30783395 -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x30303295 -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x2C206B85 -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x30783195 -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x30302E85 -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x692032DD -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x34302BD5 -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x46696EC0 -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x6B6570CB -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x656C3197 -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x3A3A51C0 -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x74466BC9 -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x65506DCC -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x28697096 -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x2C206B85 -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x31343091 -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x202C22CC -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x20302ECC -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x20302BCC -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x2E7230FC -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x6B6570CB -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x656C3197 -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x28697096 -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x20692291 -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x6C652ACC -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x72332E85 -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x69207094 -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x2C206B85 -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x30783A95 -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x30303295 -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x2C2A6B85 -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x656C3197 -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x20302BCC -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x6B6570CB -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x31343091 -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x3332389F -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x43616EC9 -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x57696CC1 -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x656176C0 -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x2C692295 -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x6B6570CB -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x2C206B85 -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x302C22CC -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x20302BFC -bxor 677 |
Jump to behavior |
Source: C:\Windows\System32\conhost.exe |
Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:4976:120:WilError_01 |
Source: C:\Windows\System32\conhost.exe |
Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:5336:120:WilError_01 |
Source: C:\Windows\System32\conhost.exe |
Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:3104:120:WilError_01 |
Source: C:\Windows\System32\conhost.exe |
Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:1916:120:WilError_01 |
Source: C:\Windows\System32\conhost.exe |
Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:1076:120:WilError_01 |
Source: C:\Windows\System32\conhost.exe |
Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:3388:120:WilError_01 |
Source: C:\Windows\System32\conhost.exe |
Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:4404:120:WilError_01 |
Source: C:\Windows\System32\conhost.exe |
Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:1648:120:WilError_01 |
Source: C:\Windows\System32\conhost.exe |
Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:4800:120:WilError_01 |
Source: C:\Windows\System32\conhost.exe |
Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:5676:120:WilError_01 |
Source: C:\Windows\System32\conhost.exe |
Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:3180:120:WilError_01 |
Source: C:\Windows\System32\conhost.exe |
Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:3468:120:WilError_01 |
Source: C:\Windows\System32\conhost.exe |
Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:3920:120:WilError_01 |
Source: C:\Windows\System32\conhost.exe |
Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:2016:120:WilError_01 |
Source: C:\Windows\System32\conhost.exe |
Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:496:120:WilError_01 |
Source: C:\Windows\System32\conhost.exe |
Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:5660:120:WilError_01 |
Source: C:\Windows\System32\conhost.exe |
Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:3124:120:WilError_01 |
Source: C:\Windows\System32\conhost.exe |
Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:996:120:WilError_01 |
Source: C:\Windows\System32\conhost.exe |
Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:816:120:WilError_01 |
Source: C:\Windows\System32\conhost.exe |
Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:3592:120:WilError_01 |
Source: C:\Windows\System32\conhost.exe |
Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:5580:120:WilError_01 |
Source: C:\Windows\System32\conhost.exe |
Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:4928:120:WilError_01 |
Source: C:\Windows\System32\conhost.exe |
Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:4184:120:WilError_01 |
Source: C:\Windows\System32\conhost.exe |
Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:1860:120:WilError_01 |
Source: C:\Windows\System32\conhost.exe |
Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:4908:120:WilError_01 |
Source: C:\Windows\System32\conhost.exe |
Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:4724:120:WilError_01 |
Source: C:\Windows\System32\conhost.exe |
Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6136:120:WilError_01 |
Source: C:\Windows\System32\conhost.exe |
Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:5160:120:WilError_01 |
Source: C:\Windows\System32\conhost.exe |
Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:5172:120:WilError_01 |
Source: C:\Windows\System32\conhost.exe |
Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:5296:120:WilError_01 |
Source: C:\Windows\System32\conhost.exe |
Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:5228:120:WilError_01 |
Source: C:\Windows\System32\conhost.exe |
Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:4024:120:WilError_01 |
Source: C:\Windows\System32\conhost.exe |
Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:1772:120:WilError_01 |
Source: C:\Windows\System32\conhost.exe |
Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6104:120:WilError_01 |
Source: C:\Windows\System32\conhost.exe |
Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:2080:120:WilError_01 |
Source: C:\Windows\System32\conhost.exe |
Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:4840:120:WilError_01 |
Source: C:\Windows\System32\conhost.exe |
Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:3272:120:WilError_01 |
Source: C:\Windows\System32\conhost.exe |
Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:636:120:WilError_01 |
Source: C:\Windows\System32\conhost.exe |
Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:5396:120:WilError_01 |
Source: C:\Windows\System32\conhost.exe |
Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:4552:120:WilError_01 |
Source: C:\Windows\System32\conhost.exe |
Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:868:120:WilError_01 |
Source: C:\Windows\System32\conhost.exe |
Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:5220:120:WilError_01 |
Source: C:\Windows\System32\conhost.exe |
Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:5848:120:WilError_01 |
Source: C:\Windows\System32\conhost.exe |
Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:5140:120:WilError_01 |
Source: C:\Windows\System32\conhost.exe |
Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:5304:120:WilError_01 |
Source: C:\Windows\System32\conhost.exe |
Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:5332:120:WilError_01 |
Source: C:\Windows\System32\conhost.exe |
Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:1672:120:WilError_01 |
Source: C:\Windows\System32\conhost.exe |
Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6072:120:WilError_01 |
Source: C:\Windows\System32\conhost.exe |
Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:5276:120:WilError_01 |
Source: C:\Windows\System32\conhost.exe |
Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:4424:120:WilError_01 |
Source: C:\Windows\System32\conhost.exe |
Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:5888:120:WilError_01 |
Source: C:\Windows\System32\conhost.exe |
Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:5028:120:WilError_01 |
Source: C:\Windows\System32\conhost.exe |
Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:5672:120:WilError_01 |
Source: C:\Windows\System32\conhost.exe |
Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:5356:120:WilError_01 |
Source: C:\Windows\System32\conhost.exe |
Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:5288:120:WilError_01 |
Source: C:\Windows\System32\conhost.exe |
Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:3956:120:WilError_01 |
Source: C:\Windows\System32\conhost.exe |
Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:1560:120:WilError_01 |
Source: C:\Windows\System32\conhost.exe |
Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:5020:120:WilError_01 |
Source: C:\Windows\System32\conhost.exe |
Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:5300:120:WilError_01 |
Source: C:\Windows\System32\conhost.exe |
Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:5844:120:WilError_01 |
Source: C:\Windows\System32\conhost.exe |
Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:5856:120:WilError_01 |
Source: C:\Windows\System32\conhost.exe |
Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:5244:120:WilError_01 |
Source: C:\Windows\System32\conhost.exe |
Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:5380:120:WilError_01 |
Source: C:\Windows\System32\conhost.exe |
Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:1664:120:WilError_01 |
Source: C:\Windows\System32\conhost.exe |
Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:3268:120:WilError_01 |
Source: C:\Windows\System32\conhost.exe |
Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:5312:120:WilError_01 |
Source: C:\Windows\System32\conhost.exe |
Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:5788:120:WilError_01 |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\conhost.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\conhost.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\conhost.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\conhost.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\conhost.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\conhost.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\conhost.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\conhost.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\conhost.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\conhost.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\conhost.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\conhost.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\conhost.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\conhost.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\conhost.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\conhost.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\conhost.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\conhost.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\conhost.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\conhost.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\conhost.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\conhost.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\conhost.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\conhost.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\conhost.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\conhost.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\conhost.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\conhost.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\conhost.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\conhost.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\conhost.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\conhost.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\conhost.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\conhost.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\conhost.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\conhost.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\conhost.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\conhost.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\conhost.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\conhost.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\conhost.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\conhost.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\conhost.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\conhost.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\conhost.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\conhost.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\conhost.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\conhost.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\conhost.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\conhost.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\conhost.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\conhost.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\conhost.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\conhost.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\conhost.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\conhost.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\conhost.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\conhost.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\conhost.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\conhost.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\conhost.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\conhost.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\conhost.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\conhost.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\conhost.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\conhost.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\conhost.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\conhost.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\conhost.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\conhost.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\conhost.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\conhost.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Windows\System32\conhost.exe |
Process information set: NOOPENFILEERRORBOX |
|
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x6B6570CB -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x656C3197 -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x3A3A41D7 -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x656176C0 -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x46696EC0 -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x41286F85 -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x72342289 -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x20692295 -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x78383295 -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x30303295 -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x302C22CC -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x20302E85 -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x70203289 -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x20692291 -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x2C206B85 -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x30783A95 -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x2C206B85 -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x30296B8B -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x723322FC -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x6B6570CB -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x656C3197 -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x3A3A54CC -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x727477C4 -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x6C416EC9 -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x20692291 -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x30783395 -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x30303295 -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x2C206B85 -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x30783195 -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x30302E85 -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x692032DD -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x34302BD5 -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x46696EC0 -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x6B6570CB -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x656C3197 -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x3A3A51C0 -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x74466BC9 -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x65506DCC -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x28697096 -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x2C206B85 -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x31343091 -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x202C22CC -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x20302ECC -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x20302BCC -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x2E7230FC -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x6B6570CB -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x656C3197 -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x28697096 -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x20692291 -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x6C652ACC -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x72332E85 -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x69207094 -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x2C206B85 -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x30783A95 -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x30303295 -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x2C2A6B85 -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x656C3197 -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x20302BCC -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x6B6570CB -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x31343091 -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x3332389F -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x43616EC9 -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x57696CC1 -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x656176C0 -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x2C692295 -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x6B6570CB -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x2C206B85 -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x302C22CC -bxor 677 |
Jump to behavior |
Source: C:\Users\user\Desktop\DOC031022-03102022004246_Squamose_10-2022-06.exe |
Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe 0x20302BFC -bxor 677 |
Jump to behavior |