Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exe

Overview

General Information

Sample Name:Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exe
Analysis ID:791299
MD5:17388d36388d280c4e2d724c9ab58002
SHA1:ee660100dfbad59a2796244514bff64c66cd0ca7
SHA256:5f20a33e263b8b8f5388b8e2512d0678312257b8fdf592b8a83aa481076048ca
Infos:

Detection

GuLoader
Score:64
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Multi AV Scanner detection for submitted file
Yara detected GuLoader
Mass process execution to delay analysis
Obfuscated command line found
Uses 32bit PE files
PE file does not import any functions
Sample file is different than original file name gathered from version info
Drops PE files
Tries to load missing DLLs
Contains functionality to shutdown / reboot the system
Uses code obfuscation techniques (call, push, ret)
Creates files inside the system directory
Detected potential crypto function
Too many similar processes found
PE / OLE file has an invalid certificate
Contains functionality to dynamically determine API calls
Creates processes with suspicious names
Found dropped PE file which has not been started or loaded
Creates a process in suspended mode (likely to inject code)
Abnormal high CPU Usage
Contains functionality for read data from the clipboard

Classification

  • System is w10x64
  • Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exe (PID: 6056 cmdline: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exe MD5: 17388D36388D280C4E2D724C9AB58002)
    • cmd.exe (PID: 6104 cmdline: cmd.exe /c set /A "0x0E^75" MD5: F3BDBE3BB6F734E357235F4D5898582D)
      • Conhost.exe (PID: 6112 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • cmd.exe (PID: 1116 cmdline: cmd.exe /c set /A "0x19^75" MD5: F3BDBE3BB6F734E357235F4D5898582D)
      • Conhost.exe (PID: 5176 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • cmd.exe (PID: 5136 cmdline: cmd.exe /c set /A "0x05^75" MD5: F3BDBE3BB6F734E357235F4D5898582D)
      • Conhost.exe (PID: 5152 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • cmd.exe (PID: 5352 cmdline: cmd.exe /c set /A "0x0E^75" MD5: F3BDBE3BB6F734E357235F4D5898582D)
      • Conhost.exe (PID: 5328 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • cmd.exe (PID: 5348 cmdline: cmd.exe /c set /A "0x07^75" MD5: F3BDBE3BB6F734E357235F4D5898582D)
      • Conhost.exe (PID: 5436 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • cmd.exe (PID: 5408 cmdline: cmd.exe /c set /A "0x78^75" MD5: F3BDBE3BB6F734E357235F4D5898582D)
      • Conhost.exe (PID: 5380 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • cmd.exe (PID: 5516 cmdline: cmd.exe /c set /A "0x79^75" MD5: F3BDBE3BB6F734E357235F4D5898582D)
      • Conhost.exe (PID: 5500 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • cmd.exe (PID: 4696 cmdline: cmd.exe /c set /A "0x71^75" MD5: F3BDBE3BB6F734E357235F4D5898582D)
      • Conhost.exe (PID: 3424 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • cmd.exe (PID: 1400 cmdline: cmd.exe /c set /A "0x71^75" MD5: F3BDBE3BB6F734E357235F4D5898582D)
      • Conhost.exe (PID: 4912 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • cmd.exe (PID: 4908 cmdline: cmd.exe /c set /A "0x08^75" MD5: F3BDBE3BB6F734E357235F4D5898582D)
      • Conhost.exe (PID: 1852 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • cmd.exe (PID: 1556 cmdline: cmd.exe /c set /A "0x39^75" MD5: F3BDBE3BB6F734E357235F4D5898582D)
      • Conhost.exe (PID: 576 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • cmd.exe (PID: 2360 cmdline: cmd.exe /c set /A "0x2E^75" MD5: F3BDBE3BB6F734E357235F4D5898582D)
      • Conhost.exe (PID: 240 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • cmd.exe (PID: 3384 cmdline: cmd.exe /c set /A "0x2A^75" MD5: F3BDBE3BB6F734E357235F4D5898582D)
      • Conhost.exe (PID: 5672 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • cmd.exe (PID: 1176 cmdline: cmd.exe /c set /A "0x3F^75" MD5: F3BDBE3BB6F734E357235F4D5898582D)
      • Conhost.exe (PID: 1540 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • cmd.exe (PID: 688 cmdline: cmd.exe /c set /A "0x2E^75" MD5: F3BDBE3BB6F734E357235F4D5898582D)
      • Conhost.exe (PID: 676 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • cmd.exe (PID: 5760 cmdline: cmd.exe /c set /A "0x0D^75" MD5: F3BDBE3BB6F734E357235F4D5898582D)
      • Conhost.exe (PID: 5748 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • cmd.exe (PID: 5836 cmdline: cmd.exe /c set /A "0x22^75" MD5: F3BDBE3BB6F734E357235F4D5898582D)
      • Conhost.exe (PID: 5792 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • cmd.exe (PID: 5860 cmdline: cmd.exe /c set /A "0x27^75" MD5: F3BDBE3BB6F734E357235F4D5898582D)
      • Conhost.exe (PID: 4996 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • cmd.exe (PID: 4964 cmdline: cmd.exe /c set /A "0x2E^75" MD5: F3BDBE3BB6F734E357235F4D5898582D)
      • Conhost.exe (PID: 4932 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • cmd.exe (PID: 5808 cmdline: cmd.exe /c set /A "0x0A^75" MD5: F3BDBE3BB6F734E357235F4D5898582D)
      • Conhost.exe (PID: 5700 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • cmd.exe (PID: 5884 cmdline: cmd.exe /c set /A "0x63^75" MD5: F3BDBE3BB6F734E357235F4D5898582D)
      • Conhost.exe (PID: 5892 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • cmd.exe (PID: 5448 cmdline: cmd.exe /c set /A "0x26^75" MD5: F3BDBE3BB6F734E357235F4D5898582D)
      • Conhost.exe (PID: 5452 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • cmd.exe (PID: 5736 cmdline: cmd.exe /c set /A "0x6B^75" MD5: F3BDBE3BB6F734E357235F4D5898582D)
      • Conhost.exe (PID: 5744 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • cmd.exe (PID: 5928 cmdline: cmd.exe /c set /A "0x39^75" MD5: F3BDBE3BB6F734E357235F4D5898582D)
      • Conhost.exe (PID: 5948 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • cmd.exe (PID: 6136 cmdline: cmd.exe /c set /A "0x7F^75" MD5: F3BDBE3BB6F734E357235F4D5898582D)
      • Conhost.exe (PID: 6132 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • cmd.exe (PID: 684 cmdline: cmd.exe /c set /A "0x6B^75" MD5: F3BDBE3BB6F734E357235F4D5898582D)
      • Conhost.exe (PID: 1672 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • cmd.exe (PID: 5360 cmdline: cmd.exe /c set /A "0x67^75" MD5: F3BDBE3BB6F734E357235F4D5898582D)
      • Conhost.exe (PID: 5356 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • cmd.exe (PID: 5316 cmdline: cmd.exe /c set /A "0x6B^75" MD5: F3BDBE3BB6F734E357235F4D5898582D)
      • Conhost.exe (PID: 5312 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • cmd.exe (PID: 5412 cmdline: cmd.exe /c set /A "0x22^75" MD5: F3BDBE3BB6F734E357235F4D5898582D)
      • Conhost.exe (PID: 5428 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • cmd.exe (PID: 5456 cmdline: cmd.exe /c set /A "0x6B^75" MD5: F3BDBE3BB6F734E357235F4D5898582D)
      • Conhost.exe (PID: 5404 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • cmd.exe (PID: 4228 cmdline: cmd.exe /c set /A "0x7B^75" MD5: F3BDBE3BB6F734E357235F4D5898582D)
      • Conhost.exe (PID: 4768 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • cmd.exe (PID: 5008 cmdline: cmd.exe /c set /A "0x33^75" MD5: F3BDBE3BB6F734E357235F4D5898582D)
      • Conhost.exe (PID: 648 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • cmd.exe (PID: 2056 cmdline: cmd.exe /c set /A "0x73^75" MD5: F3BDBE3BB6F734E357235F4D5898582D)
      • Conhost.exe (PID: 4224 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • cmd.exe (PID: 4556 cmdline: cmd.exe /c set /A "0x7B^75" MD5: F3BDBE3BB6F734E357235F4D5898582D)
      • Conhost.exe (PID: 816 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • cmd.exe (PID: 496 cmdline: cmd.exe /c set /A "0x7B^75" MD5: F3BDBE3BB6F734E357235F4D5898582D)
      • Conhost.exe (PID: 1500 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • cmd.exe (PID: 1296 cmdline: cmd.exe /c set /A "0x7B^75" MD5: F3BDBE3BB6F734E357235F4D5898582D)
      • Conhost.exe (PID: 1212 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • cmd.exe (PID: 3092 cmdline: cmd.exe /c set /A "0x7B^75" MD5: F3BDBE3BB6F734E357235F4D5898582D)
      • Conhost.exe (PID: 4648 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • cmd.exe (PID: 3236 cmdline: cmd.exe /c set /A "0x7B^75" MD5: F3BDBE3BB6F734E357235F4D5898582D)
      • Conhost.exe (PID: 5816 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • cmd.exe (PID: 5872 cmdline: cmd.exe /c set /A "0x7B^75" MD5: F3BDBE3BB6F734E357235F4D5898582D)
      • Conhost.exe (PID: 5864 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • cmd.exe (PID: 4988 cmdline: cmd.exe /c set /A "0x7B^75" MD5: F3BDBE3BB6F734E357235F4D5898582D)
      • Conhost.exe (PID: 4972 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • cmd.exe (PID: 4920 cmdline: cmd.exe /c set /A "0x67^75" MD5: F3BDBE3BB6F734E357235F4D5898582D)
      • Conhost.exe (PID: 5956 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • cmd.exe (PID: 5484 cmdline: cmd.exe /c set /A "0x6B^75" MD5: F3BDBE3BB6F734E357235F4D5898582D)
      • Conhost.exe (PID: 5476 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • cmd.exe (PID: 5908 cmdline: cmd.exe /c set /A "0x22^75" MD5: F3BDBE3BB6F734E357235F4D5898582D)
      • Conhost.exe (PID: 5472 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • cmd.exe (PID: 5732 cmdline: cmd.exe /c set /A "0x6B^75" MD5: F3BDBE3BB6F734E357235F4D5898582D)
      • Conhost.exe (PID: 3196 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • cmd.exe (PID: 5768 cmdline: cmd.exe /c set /A "0x7B^75" MD5: F3BDBE3BB6F734E357235F4D5898582D)
      • Conhost.exe (PID: 5776 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • cmd.exe (PID: 2576 cmdline: cmd.exe /c set /A "0x67^75" MD5: F3BDBE3BB6F734E357235F4D5898582D)
      • Conhost.exe (PID: 6040 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • cmd.exe (PID: 6112 cmdline: cmd.exe /c set /A "0x6B^75" MD5: F3BDBE3BB6F734E357235F4D5898582D)
      • Conhost.exe (PID: 5156 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • cmd.exe (PID: 5164 cmdline: cmd.exe /c set /A "0x3B^75" MD5: F3BDBE3BB6F734E357235F4D5898582D)
      • Conhost.exe (PID: 5176 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • cmd.exe (PID: 5152 cmdline: cmd.exe /c set /A "0x6B^75" MD5: F3BDBE3BB6F734E357235F4D5898582D)
      • Conhost.exe (PID: 5320 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • cmd.exe (PID: 5344 cmdline: cmd.exe /c set /A "0x7B^75" MD5: F3BDBE3BB6F734E357235F4D5898582D)
      • Conhost.exe (PID: 5332 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • cmd.exe (PID: 5436 cmdline: cmd.exe /c set /A "0x67^75" MD5: F3BDBE3BB6F734E357235F4D5898582D)
      • Conhost.exe (PID: 5440 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • cmd.exe (PID: 5380 cmdline: cmd.exe /c set /A "0x6B^75" MD5: F3BDBE3BB6F734E357235F4D5898582D)
      • Conhost.exe (PID: 5396 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • cmd.exe (PID: 1768 cmdline: cmd.exe /c set /A "0x22^75" MD5: F3BDBE3BB6F734E357235F4D5898582D)
      • Conhost.exe (PID: 3408 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • cmd.exe (PID: 4252 cmdline: cmd.exe /c set /A "0x6B^75" MD5: F3BDBE3BB6F734E357235F4D5898582D)
      • Conhost.exe (PID: 648 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • cmd.exe (PID: 576 cmdline: cmd.exe /c set /A "0x7F^75" MD5: F3BDBE3BB6F734E357235F4D5898582D)
      • Conhost.exe (PID: 3780 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • cmd.exe (PID: 1412 cmdline: cmd.exe /c set /A "0x67^75" MD5: F3BDBE3BB6F734E357235F4D5898582D)
      • Conhost.exe (PID: 416 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • cmd.exe (PID: 3988 cmdline: cmd.exe /c set /A "0x6B^75" MD5: F3BDBE3BB6F734E357235F4D5898582D)
      • Conhost.exe (PID: 2300 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • cmd.exe (PID: 5752 cmdline: cmd.exe /c set /A "0x22^75" MD5: F3BDBE3BB6F734E357235F4D5898582D)
      • Conhost.exe (PID: 1216 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • cmd.exe (PID: 4852 cmdline: cmd.exe /c set /A "0x6B^75" MD5: F3BDBE3BB6F734E357235F4D5898582D)
      • Conhost.exe (PID: 5788 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • cmd.exe (PID: 5760 cmdline: cmd.exe /c set /A "0x7B^75" MD5: F3BDBE3BB6F734E357235F4D5898582D)
      • Conhost.exe (PID: 5848 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • cmd.exe (PID: 4984 cmdline: cmd.exe /c set /A "0x33^75" MD5: F3BDBE3BB6F734E357235F4D5898582D)
      • Conhost.exe (PID: 4976 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • cmd.exe (PID: 5860 cmdline: cmd.exe /c set /A "0x73^75" MD5: F3BDBE3BB6F734E357235F4D5898582D)
      • Conhost.exe (PID: 4928 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • cmd.exe (PID: 4956 cmdline: cmd.exe /c set /A "0x7B^75" MD5: F3BDBE3BB6F734E357235F4D5898582D)
      • Conhost.exe (PID: 5784 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
    • cmd.exe (PID: 5808 cmdline: cmd.exe /c set /A "0x67^75" MD5: F3BDBE3BB6F734E357235F4D5898582D)
      • Conhost.exe (PID: 5896 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
  • cleanup
No configs have been found
SourceRuleDescriptionAuthorStrings
00000000.00000002.514197554.0000000000613000.00000004.00000020.00020000.00000000.sdmpJoeSecurity_GuLoader_3Yara detected GuLoaderJoe Security
    Process Memory Space: Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exe PID: 6056JoeSecurity_GuLoader_3Yara detected GuLoaderJoe Security
      No Sigma rule has matched
      No Snort rule has matched

      Click to jump to signature section

      Show All Signature Results

      AV Detection

      barindex
      Source: Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeVirustotal: Detection: 32%Perma Link
      Source: Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeStatic PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE
      Source: Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeStatic PE information: DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
      Source: Binary string: f:\bluetooth8.0.1.57\sw\src\WIN8_Mainline\ExtArch\UI\Win7UI\Prism\Composite.UnityExtensions\obj\x64\Release\Microsoft.Practices.Composite.UnityExtensions.pdb source: Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exe, 00000000.00000003.248079149.0000000002891000.00000004.00000020.00020000.00000000.sdmp, Microsoft.Practices.Composite.UnityExtensions.dll.0.dr
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeCode function: 0_2_00405FFD FindFirstFileA,FindClose,
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeCode function: 0_2_0040559B GetTempPathA,DeleteFileA,lstrcatA,lstrcatA,lstrlenA,FindFirstFileA,FindNextFileA,FindClose,
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeCode function: 0_2_00402688 FindFirstFileA,
      Source: application-x-executable.png.0.drString found in binary or memory: http://creativecommons.org/licenses/by-sa/4.0/
      Source: Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exe, 00000000.00000003.248538306.0000000002890000.00000004.00000020.00020000.00000000.sdmp, default.css.0.drString found in binary or memory: http://mozilla.org/MPL/2.0/.
      Source: Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeString found in binary or memory: http://nsis.sf.net/NSIS_Error
      Source: Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeString found in binary or memory: http://nsis.sf.net/NSIS_ErrorError
      Source: Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exe, 00000000.00000003.248538306.0000000002890000.00000004.00000020.00020000.00000000.sdmp, default.css.0.drString found in binary or memory: http://www.apache.org/licenses/LICENSE-2.0
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeCode function: 0_2_00405050 GetDlgItem,GetDlgItem,GetDlgItem,GetDlgItem,GetClientRect,GetSystemMetrics,SendMessageA,SendMessageA,SendMessageA,SendMessageA,SendMessageA,SendMessageA,ShowWindow,ShowWindow,GetDlgItem,SendMessageA,SendMessageA,SendMessageA,GetDlgItem,CreateThread,FindCloseChangeNotification,ShowWindow,ShowWindow,ShowWindow,SendMessageA,CreatePopupMenu,AppendMenuA,GetWindowRect,TrackPopupMenu,SendMessageA,OpenClipboard,EmptyClipboard,GlobalAlloc,GlobalLock,SendMessageA,GlobalUnlock,SetClipboardData,CloseClipboard,
      Source: Conhost.exeProcess created: 87
      Source: Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeStatic PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE
      Source: Microsoft.Practices.Composite.UnityExtensions.dll.0.drStatic PE information: No import functions for PE file found
      Source: Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exe, 00000000.00000003.248079149.0000000002891000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenameMicrosoft.Practices.Composite.UnityExtensions.dll\ vs Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeSection loaded: havegangenes.dll
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeCode function: 0_2_004030D9 EntryPoint,SetErrorMode,GetVersion,lstrlenA,#17,OleInitialize,SHGetFileInfoA,GetCommandLineA,GetModuleHandleA,CharNextA,GetTempPathA,GetTempPathA,GetWindowsDirectoryA,lstrcatA,GetTempPathA,lstrcatA,SetEnvironmentVariableA,SetEnvironmentVariableA,SetEnvironmentVariableA,DeleteFileA,OleUninitialize,ExitProcess,lstrcatA,lstrcatA,lstrcatA,lstrcmpiA,SetCurrentDirectoryA,DeleteFileA,CopyFileA,CloseHandle,GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueA,AdjustTokenPrivileges,ExitWindowsEx,ExitProcess,
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: C:\Windows\resources\0409Jump to behavior
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeCode function: 0_2_00406344
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeCode function: 0_2_0040488F
      Source: Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeStatic PE information: invalid certificate
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess Stats: CPU usage > 98%
      Source: Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeVirustotal: Detection: 32%
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile read: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeJump to behavior
      Source: Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers
      Source: unknownProcess created: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exe C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x0E^75"
      Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x19^75"
      Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x05^75"
      Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x0E^75"
      Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x07^75"
      Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x78^75"
      Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x79^75"
      Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x71^75"
      Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x71^75"
      Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x08^75"
      Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x39^75"
      Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x2E^75"
      Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x2A^75"
      Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x3F^75"
      Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x2E^75"
      Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x0D^75"
      Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x22^75"
      Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x27^75"
      Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x2E^75"
      Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x0A^75"
      Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x63^75"
      Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x26^75"
      Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x6B^75"
      Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x39^75"
      Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x7F^75"
      Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x6B^75"
      Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x67^75"
      Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x6B^75"
      Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x22^75"
      Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x6B^75"
      Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x7B^75"
      Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x33^75"
      Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x73^75"
      Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x7B^75"
      Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x7B^75"
      Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x7B^75"
      Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x7B^75"
      Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x7B^75"
      Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x7B^75"
      Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x7B^75"
      Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x67^75"
      Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x6B^75"
      Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x22^75"
      Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x6B^75"
      Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x7B^75"
      Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x67^75"
      Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x6B^75"
      Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x3B^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x6B^75"
      Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x7B^75"
      Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x67^75"
      Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x6B^75"
      Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x22^75"
      Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x6B^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x7F^75"
      Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x67^75"
      Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x6B^75"
      Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x22^75"
      Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x6B^75"
      Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
      Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x33^75"
      Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
      Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x7B^75"
      Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
      Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x0E^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x19^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x05^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x0E^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x07^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x78^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x79^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x71^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x71^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x08^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x39^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x2E^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x2A^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x3F^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x2E^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x0D^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x22^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x27^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x2E^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x0A^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x63^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x26^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x6B^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x39^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x7F^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x6B^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x67^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x6B^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x22^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x6B^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x7B^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x33^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x73^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x7B^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x7B^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x7B^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x7B^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x7B^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x7B^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x7B^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x67^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x6B^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x22^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x6B^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x7B^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x67^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x3B^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x7B^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x22^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x6B^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x67^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x6B^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x22^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x6B^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x0D^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x33^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x27^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x7B^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x0A^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x6B^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x73^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x2A^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x22^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x67^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x7F^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x7B^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x7B^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x7B^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x6B^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x7B^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x33^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x6B^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x79^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x6B^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x79^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x79^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x7B^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x7B^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x7B^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x0E^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}\InProcServer32
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeCode function: 0_2_004030D9 EntryPoint,SetErrorMode,GetVersion,lstrlenA,#17,OleInitialize,SHGetFileInfoA,GetCommandLineA,GetModuleHandleA,CharNextA,GetTempPathA,GetTempPathA,GetWindowsDirectoryA,lstrcatA,GetTempPathA,lstrcatA,SetEnvironmentVariableA,SetEnvironmentVariableA,SetEnvironmentVariableA,DeleteFileA,OleUninitialize,ExitProcess,lstrcatA,lstrcatA,lstrcatA,lstrcmpiA,SetCurrentDirectoryA,DeleteFileA,CopyFileA,CloseHandle,GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueA,AdjustTokenPrivileges,ExitWindowsEx,ExitProcess,
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: C:\Users\user\PacifisterneJump to behavior
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: C:\Users\user\AppData\Local\Temp\nswCDB0.tmpJump to behavior
      Source: classification engineClassification label: mal64.troj.evad.winEXE@410/8@0/0
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeCode function: 0_2_0040205E CoCreateInstance,MultiByteToWideChar,
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile read: C:\Users\desktop.iniJump to behavior
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeCode function: 0_2_0040431C GetDlgItem,SetWindowTextA,SHBrowseForFolderA,CoTaskMemFree,lstrcmpiA,lstrcatA,SetDlgItemTextA,GetDiskFreeSpaceA,MulDiv,SetDlgItemTextA,
      Source: Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeStatic PE information: DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
      Source: Binary string: f:\bluetooth8.0.1.57\sw\src\WIN8_Mainline\ExtArch\UI\Win7UI\Prism\Composite.UnityExtensions\obj\x64\Release\Microsoft.Practices.Composite.UnityExtensions.pdb source: Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exe, 00000000.00000003.248079149.0000000002891000.00000004.00000020.00020000.00000000.sdmp, Microsoft.Practices.Composite.UnityExtensions.dll.0.dr

      Data Obfuscation

      barindex
      Source: Yara matchFile source: 00000000.00000002.514197554.0000000000613000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
      Source: Yara matchFile source: Process Memory Space: Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exe PID: 6056, type: MEMORYSTR
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x0E^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x19^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x05^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x0E^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x07^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x78^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x79^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x71^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x71^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x08^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x39^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x2E^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x2A^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x3F^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x2E^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x0D^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x22^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x27^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x2E^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x0A^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x63^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x26^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x6B^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x39^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x7F^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x6B^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x67^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x6B^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x22^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x6B^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x7B^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x33^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x73^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x7B^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x7B^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x7B^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x7B^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x7B^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x7B^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x7B^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x67^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x6B^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x22^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x6B^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x7B^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x67^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x6B^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x3B^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x6B^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x7B^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x67^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x6B^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x22^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x6B^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x7F^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x67^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x6B^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x22^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x6B^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x33^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x7B^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x0E^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x19^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x05^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x0E^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x07^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x78^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x79^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x71^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x71^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x08^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x39^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x2E^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x2A^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x3F^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x2E^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x0D^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x22^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x27^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x2E^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x0A^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x63^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x26^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x6B^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x39^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x7F^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x6B^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x67^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x6B^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x22^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x6B^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x7B^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x33^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x73^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x7B^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x7B^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x7B^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x7B^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x7B^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x7B^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x7B^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x67^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x6B^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x22^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x6B^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x7B^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x67^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x3B^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x7B^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x22^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x6B^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x67^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x6B^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x22^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x6B^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x0D^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x33^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x27^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x7B^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x0A^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x6B^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x73^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x2A^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x22^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x67^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x7F^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x7B^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x7B^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x7B^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x6B^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x7B^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x33^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x6B^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x79^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x6B^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x79^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x79^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x7B^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x7B^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x7B^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x0E^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeCode function: 0_2_10002D20 push eax; ret
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeCode function: 0_2_10001A5D GlobalAlloc,lstrcpyA,lstrcpyA,GlobalFree,GlobalFree,GlobalFree,GlobalFree,GlobalFree,GlobalFree,lstrcpyA,GetModuleHandleA,LoadLibraryA,GetProcAddress,lstrlenA,
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: C:\Users\user\Pacifisterne\Automatcafeer\Nedrustningspolitikken\Dilemmaers146\Glasgaibleanir\Nodebilledet\Microsoft.Practices.Composite.UnityExtensions.dllJump to dropped file
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: C:\Users\user\AppData\Local\Temp\nsgFEE3.tmp\System.dllJump to dropped file
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: C:\Users\user\AppData\Local\Temp\nsgFEE3.tmp\nsExec.dllJump to dropped file
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeFile created: \pilne zamowienie nr5363582 utech maszyny i urzadzenia techniczne jaroslaw koenig sp. k..exe
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess information set: NOOPENFILEERRORBOX

      Malware Analysis System Evasion

      barindex
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x0E^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x19^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x05^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x0E^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x07^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x78^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x79^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x71^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x71^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x08^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeDropped PE file which has not been started: C:\Users\user\Pacifisterne\Automatcafeer\Nedrustningspolitikken\Dilemmaers146\Glasgaibleanir\Nodebilledet\Microsoft.Practices.Composite.UnityExtensions.dllJump to dropped file
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeCode function: 0_2_00405FFD FindFirstFileA,FindClose,
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeCode function: 0_2_0040559B GetTempPathA,DeleteFileA,lstrcatA,lstrcatA,lstrlenA,FindFirstFileA,FindNextFileA,FindClose,
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeCode function: 0_2_00402688 FindFirstFileA,
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeAPI call chain: ExitProcess graph end node
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeAPI call chain: ExitProcess graph end node
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeCode function: 0_2_10001A5D GlobalAlloc,lstrcpyA,lstrcpyA,GlobalFree,GlobalFree,GlobalFree,GlobalFree,GlobalFree,GlobalFree,lstrcpyA,GetModuleHandleA,LoadLibraryA,GetProcAddress,lstrlenA,
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x0E^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x19^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x05^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x0E^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x07^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x78^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x79^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x71^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x71^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x08^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x39^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x2E^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x2A^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x3F^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x2E^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x0D^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x22^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x27^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x2E^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x0A^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x63^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x26^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x6B^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x39^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x7F^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x6B^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x67^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x6B^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x22^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x6B^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x7B^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x33^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x73^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x7B^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x7B^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x7B^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x7B^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x7B^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x7B^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x7B^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x67^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x6B^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x22^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x6B^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x7B^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x67^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x3B^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x7B^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x22^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x6B^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x67^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x6B^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x22^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x6B^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x0D^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x33^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x27^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x7B^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x0A^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x6B^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x73^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x2A^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x22^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x67^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x7F^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x7B^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x7B^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x7B^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x6B^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x7B^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x33^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x6B^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x79^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x6B^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x79^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x79^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x7B^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x7B^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x7B^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /A "0x0E^75"
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeProcess created: unknown unknown
      Source: C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exeCode function: 0_2_00405D1B GetVersion,GetSystemDirectoryA,GetWindowsDirectoryA,SHGetSpecialFolderLocation,SHGetPathFromIDListA,CoTaskMemFree,lstrcatA,lstrlenA,
      Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
      Valid Accounts1
      Command and Scripting Interpreter
      1
      DLL Side-Loading
      1
      Access Token Manipulation
      11
      Masquerading
      OS Credential Dumping1
      Time Based Evasion
      Remote Services1
      Archive Collected Data
      Exfiltration Over Other Network Medium1
      Encrypted Channel
      Eavesdrop on Insecure Network CommunicationRemotely Track Device Without Authorization1
      System Shutdown/Reboot
      Default Accounts1
      Native API
      Boot or Logon Initialization Scripts11
      Process Injection
      1
      Access Token Manipulation
      LSASS Memory2
      File and Directory Discovery
      Remote Desktop Protocol1
      Clipboard Data
      Exfiltration Over BluetoothJunk DataExploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
      Domain AccountsAt (Linux)Logon Script (Windows)1
      DLL Side-Loading
      11
      Process Injection
      Security Account Manager3
      System Information Discovery
      SMB/Windows Admin SharesData from Network Shared DriveAutomated ExfiltrationSteganographyExploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
      Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)1
      Deobfuscate/Decode Files or Information
      NTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureScheduled TransferProtocol ImpersonationSIM Card SwapCarrier Billing Fraud
      Cloud AccountsCronNetwork Logon ScriptNetwork Logon Script1
      Time Based Evasion
      LSA SecretsRemote System DiscoverySSHKeyloggingData Transfer Size LimitsFallback ChannelsManipulate Device CommunicationManipulate App Store Rankings or Ratings
      Replication Through Removable MediaLaunchdRc.commonRc.common1
      Obfuscated Files or Information
      Cached Domain CredentialsSystem Owner/User DiscoveryVNCGUI Input CaptureExfiltration Over C2 ChannelMultiband CommunicationJamming or Denial of ServiceAbuse Accessibility Features
      External Remote ServicesScheduled TaskStartup ItemsStartup Items1
      DLL Side-Loading
      DCSyncNetwork SniffingWindows Remote ManagementWeb Portal CaptureExfiltration Over Alternative ProtocolCommonly Used PortRogue Wi-Fi Access PointsData Encrypted for Impact
      Hide Legend

      Legend:

      • Process
      • Signature
      • Created File
      • DNS/IP Info
      • Is Dropped
      • Is Windows Process
      • Number of created Registry Values
      • Number of created Files
      • Visual Basic
      • Delphi
      • Java
      • .Net C# or VB.NET
      • C, C++ or other language
      • Is malicious
      • Internet
      behaviorgraph top1 signatures2 2 Behavior Graph ID: 791299 Sample: Pilne zamowienie nr5363582 ... Startdate: 25/01/2023 Architecture: WINDOWS Score: 64 39 Multi AV Scanner detection for submitted file 2->39 41 Yara detected GuLoader 2->41 43 Obfuscated command line found 2->43 45 Mass process execution to delay analysis 2->45 7 Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exe 1 34 2->7         started        process3 file4 33 Microsoft.Practice...UnityExtensions.dll, PE32+ 7->33 dropped 35 C:\Users\user\AppData\Local\...\nsExec.dll, PE32 7->35 dropped 37 C:\Users\user\AppData\Local\...\System.dll, PE32 7->37 dropped 47 Obfuscated command line found 7->47 11 cmd.exe 7->11         started        13 cmd.exe 7->13         started        15 cmd.exe 7->15         started        17 61 other processes 7->17 signatures5 process6 process7 19 Conhost.exe 11->19         started        21 Conhost.exe 13->21         started        23 Conhost.exe 15->23         started        25 Conhost.exe 17->25         started        27 Conhost.exe 17->27         started        29 Conhost.exe 17->29         started        31 58 other processes 17->31

      This section contains all screenshots as thumbnails, including those not shown in the slideshow.


      windows-stand
      SourceDetectionScannerLabelLink
      Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exe10%ReversingLabs
      Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exe33%VirustotalBrowse
      SourceDetectionScannerLabelLink
      C:\Users\user\AppData\Local\Temp\nsgFEE3.tmp\System.dll0%ReversingLabs
      C:\Users\user\AppData\Local\Temp\nsgFEE3.tmp\System.dll1%VirustotalBrowse
      C:\Users\user\AppData\Local\Temp\nsgFEE3.tmp\nsExec.dll2%ReversingLabs
      C:\Users\user\AppData\Local\Temp\nsgFEE3.tmp\nsExec.dll1%VirustotalBrowse
      C:\Users\user\Pacifisterne\Automatcafeer\Nedrustningspolitikken\Dilemmaers146\Glasgaibleanir\Nodebilledet\Microsoft.Practices.Composite.UnityExtensions.dll0%ReversingLabs
      C:\Users\user\Pacifisterne\Automatcafeer\Nedrustningspolitikken\Dilemmaers146\Glasgaibleanir\Nodebilledet\Microsoft.Practices.Composite.UnityExtensions.dll0%VirustotalBrowse
      SourceDetectionScannerLabelLinkDownload
      0.2.Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exe.400000.0.unpack100%AviraHEUR/AGEN.1223491Download File
      0.0.Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exe.400000.0.unpack100%AviraHEUR/AGEN.1223491Download File
      No Antivirus matches
      No Antivirus matches
      No contacted domains info
      NameSourceMaliciousAntivirus DetectionReputation
      http://www.apache.org/licenses/LICENSE-2.0Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exe, 00000000.00000003.248538306.0000000002890000.00000004.00000020.00020000.00000000.sdmp, default.css.0.drfalse
        high
        http://creativecommons.org/licenses/by-sa/4.0/application-x-executable.png.0.drfalse
          high
          http://nsis.sf.net/NSIS_ErrorPilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exefalse
            high
            http://nsis.sf.net/NSIS_ErrorErrorPilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exefalse
              high
              http://mozilla.org/MPL/2.0/.Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exe, 00000000.00000003.248538306.0000000002890000.00000004.00000020.00020000.00000000.sdmp, default.css.0.drfalse
                high
                No contacted IP infos
                Joe Sandbox Version:36.0.0 Rainbow Opal
                Analysis ID:791299
                Start date and time:2023-01-25 09:52:49 +01:00
                Joe Sandbox Product:CloudBasic
                Overall analysis duration:0h 8m 20s
                Hypervisor based Inspection enabled:false
                Report type:light
                Sample file name:Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exe
                Cookbook file name:default.jbs
                Analysis system description:Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 104, IE 11, Adobe Reader DC 19, Java 8 Update 211
                Number of analysed new started processes analysed:161
                Number of new started drivers analysed:0
                Number of existing processes analysed:0
                Number of existing drivers analysed:0
                Number of injected processes analysed:0
                Technologies:
                • HCA enabled
                • EGA enabled
                • HDC enabled
                • AMSI enabled
                Analysis Mode:default
                Analysis stop reason:Timeout
                Detection:MAL
                Classification:mal64.troj.evad.winEXE@410/8@0/0
                EGA Information:
                • Successful, ratio: 100%
                HDC Information:
                • Successful, ratio: 63% (good quality ratio 61.6%)
                • Quality average: 88.6%
                • Quality standard deviation: 21.8%
                HCA Information:
                • Successful, ratio: 99%
                • Number of executed functions: 0
                • Number of non-executed functions: 0
                Cookbook Comments:
                • Found application associated with file extension: .exe
                • Exclude process from analysis (whitelisted): MpCmdRun.exe, BackgroundTransferHost.exe, RuntimeBroker.exe, backgroundTaskHost.exe, SgrmBroker.exe, conhost.exe, svchost.exe
                • Excluded IPs from analysis (whitelisted): 13.107.5.88, 13.107.42.16, 40.126.31.69, 20.190.159.23, 20.190.159.2, 20.190.159.0, 20.190.159.68, 20.190.159.4, 40.126.31.67, 20.190.159.73, 131.253.33.200, 13.107.22.200
                • Excluded domains from analysis (whitelisted): ocos-office365-s2s.msedge.net, client-office365-tas.msedge.net, config.edge.skype.com.trafficmanager.net, eudb.ris.api.iris.microsoft.com, e-0009.e-msedge.net, arc.msn.com, prda.aadg.msidentity.com, config-edge-skype.l-0007.l-msedge.net, login.live.com, www-bing-com.dual-a-0001.a-msedge.net, img-prod-cms-rt-microsoft-com.akamaized.net, cdn.onenote.net, l-0007.l-msedge.net, config.edge.skype.com, storeedgefd.dsx.mp.microsoft.com, www.bing.com, fs.microsoft.com, afdo-tas-offload.trafficmanager.net, ctldl.windowsupdate.com, www.tm.a.prd.aadg.akadns.net, www-www.bing.com.trafficmanager.net, login.msa.msidentity.com, ris.api.iris.microsoft.com, ocos-office365-s2s-msedge-net.e-0009.e-msedge.net, dual-a-0001.dc-msedge.net, store-images.s-microsoft.com, l-0007.config.skype.com, www.tm.lg.prod.aadmsa.trafficmanager.net
                • Not all processes where analyzed, report is missing behavior information
                • Report size getting too big, too many NtWriteVirtualMemory calls found.
                TimeTypeDescription
                09:53:43API Interceptor1x Sleep call for process: Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exe modified
                No context
                No context
                No context
                No context
                No context
                Process:C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exe
                File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                Category:dropped
                Size (bytes):11264
                Entropy (8bit):5.770803561213006
                Encrypted:false
                SSDEEP:192:vPtkumJX7zB22kGwfy0mtVgkCPOsE1un:k702k5qpdsEQn
                MD5:2AE993A2FFEC0C137EB51C8832691BCB
                SHA1:98E0B37B7C14890F8A599F35678AF5E9435906E1
                SHA-256:681382F3134DE5C6272A49DD13651C8C201B89C247B471191496E7335702FA59
                SHA-512:2501371EB09C01746119305BA080F3B8C41E64535FF09CEE4F51322530366D0BD5322EA5290A466356598027E6CDA8AB360CAEF62DCAF560D630742E2DD9BCD9
                Malicious:false
                Antivirus:
                • Antivirus: ReversingLabs, Detection: 0%
                • Antivirus: Virustotal, Detection: 1%, Browse
                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......)...m.m.m...k.m.~....j.9..i....l....l.Richm.........................PE..L...tc.W...........!.................'.......0...............................`.......................................2.......0..P............................P.......................................................0..X............................text...O........................... ..`.rdata..S....0......."..............@..@.data...h....@.......&..............@....reloc..`....P.......(..............@..B................................................................................................................................................................................................................................................................................................................................................................................
                Process:C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exe
                File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                Category:dropped
                Size (bytes):6656
                Entropy (8bit):4.994861218233575
                Encrypted:false
                SSDEEP:96:U7GUxNkO6GR0t9GKKr1Zd8NHYVVHp4dEeY3kRnHdMqqyVgNN3e:mXhHR0aTQN4gRHdMqJVgNE
                MD5:B648C78981C02C434D6A04D4422A6198
                SHA1:74D99EED1EAE76C7F43454C01CDB7030E5772FC2
                SHA-256:3E3D516D4F28948A474704D5DC9907DBE39E3B3F98E7299F536337278C59C5C9
                SHA-512:219C88C0EF9FD6E3BE34C56D8458443E695BADD27861D74C486143306A94B8318E6593BF4DA81421E88E4539B238557DD4FE1F5BEDF3ECEC59727917099E90D2
                Malicious:false
                Antivirus:
                • Antivirus: ReversingLabs, Detection: 2%
                • Antivirus: Virustotal, Detection: 1%, Browse
                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........d..7..7..7..7..7,..7..7..7..7..7..7Rich..7........PE..L...rc.W...........!......................... ...............................P.......................................$..l.... ..P............................@....................................................... ...............................text............................... ..`.rdata..,.... ......................@..@.data........0......................@....reloc.......@......................@..B................................................................................................................................................................................................................................................................................................................................................................................................................
                Process:C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exe
                File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                Category:dropped
                Size (bytes):18048
                Entropy (8bit):5.781710632242959
                Encrypted:false
                SSDEEP:384:PDNDRvozv1hgXptjLrzs4AvgWOMrq0eMDI/:ZRvA4r77ARg/
                MD5:270209B12F7C117C539F574CE2576C0A
                SHA1:184B447F6364FA0760F862B84CBC6E717C9F5C3D
                SHA-256:C5DB3358A184147D6FFB41F05BBF9BA9356038A0867A783F266EA62813EF6CF4
                SHA-512:BB062EF832EB2B477D92FDF71C0B6B30AA590A735DEC1920400C3DA74EC07FF1F1DBF9E50E63EE2FDD68E9E48FC39F5522DFF0A029E47658A41F88EEC9FD250A
                Malicious:false
                Antivirus:
                • Antivirus: ReversingLabs, Detection: 0%
                • Antivirus: Virustotal, Detection: 0%, Browse
                Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...W..S.........." .....0............... .....@..... ....................................@...@......@............... ...............................`...............8..............dM............................................................... ..H............text...6.... ...0.................. ..`.rsrc........`.......2..............@..@.reloc...............8..............@..BH........*..\#..........`&........................................................{....*"..}....*..{....*"..(....*...0............}.....o......-.(....s....z.r...p..o......o....(.....(....-.(....s....z.r3..p..o.....(....o...+&.o.....r_..p..o.....o....&.o....&.o.....r...p..o.....o......,...(....o...+(....(.....r...p..o.....o.....r...p..o....*..(...(....(.....+...(....(.....,...(....(....*2.(....o...+*...0..%..........(.....o....o...+&.o......,..(.....o...+&.{....9......-...(.........(.
                Process:C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exe
                File Type:ASCII text, with very long lines (50244), with no line terminators
                Category:dropped
                Size (bytes):50244
                Entropy (8bit):3.999625167208849
                Encrypted:false
                SSDEEP:768:4Kt0hO4obUZX9nvBHp7RJ+CqqSK0haV6RTFA9yu7m1HK0TWgKL383w6gW:81oq9nvjqqSiUu9yu7m1HzT4L38AhW
                MD5:21337BAB1F65E60A88523B4DDB961E52
                SHA1:AD9C448F53AB48C3110D25650BACFE44C1988D51
                SHA-256:E2565D3B49D70ACDAD0AB4162BA0FBF738F227A0EC224982A813E874C46C0FCE
                SHA-512:A6DAE16844C6A433AFF4EDE77F0E77984073CEC0E38D439B57144670EE0F4034BD5F2FFCB6647010F6717A7F39928A6F04E7F05BA9511745F38CF6A49891FFDA
                Malicious:false
                Preview:56E3E082070CC707B0B701B836A6FEDCB0D7E6E50989CF2DA81B4311EF928EBF02F09C7EB977BC9031BA864CC44F17929BE2524D78FC507F411DCBC91BE502D51D27CA45924DFC91765F6EB7845C91C0D665E583A8AD0203D0E4E6E6CD17355A6BEE2CB460D8FEE6D05422DDF5EE3A100E5B5DF7E16AF5EE06574C03F45CF5AB392237D86BD7BA856648AFC8934A58C5CB26436F55DDADFBBF10B9B4879334CB8EC34E3188C13AB624B5BD476E64AE8E29F5D01B1F4990A3C97BFCFF07D4B1C9164FF864EC64F66817B8CB32DEDF9FCDD8BFEA77F0E8FA2FF734E9693AB8DB0E567BF76D363F5446629BF43E8658F94A657CA3A4E1F8CBE2A0DF2079A857E95B935916B09270CBD505DC004B5398C830A48C5BEC0BF51F45B3CF8B5BB54C379E941830FBE112B9AA311E3DDCB33515B088213DF149B237AA4C2FDEF37D6456FA22C12527A4B8369506B1AD0523F47A8479C3F96173652E3E9D10BC37BBDA514166816FEB43067D30B2F3AF7514968878341027AC20B0A426E2E7C25DCBA0B6FED381151DDA1B09092FF33782B8325E6B87234F9652F4DB96B3783CDA3D515E98CEDAACDBA19D8B6F8900215829145E262A081177B80AA3834EDBFF2F96C95ED77E31546A6F59C87BE0A467B5CF31606F7D2E6453A34C7B7AF3DAFCFB71E6B5770C2B1BC25C472C3653338393230C4F9FFB4398AD
                Process:C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exe
                File Type:data
                Category:dropped
                Size (bytes):285823
                Entropy (8bit):7.384888860358361
                Encrypted:false
                SSDEEP:3072:RPwTCrZk0BdcUdJ9bh2df3UvT1q3olHbVfvco8uKbtfEqL42V9oCWRtTT5sEgZOF:hTe00ykdvUvT1XGcofEmopbtlXF
                MD5:6CD4A3E95E9C6BA051D63C5177522F4B
                SHA1:38CBCD09C46F8637421F4D604C9C634A755D7EB0
                SHA-256:98BBC8D8E0B70E12F3A2C541CA197D27FFBC4B25BEDB517E0C510A20F0EEAC17
                SHA-512:E23F984A19945EB3A0595F5AB74D9C7D5EFDDC03B12CB376AAC4FF301B614619C7DB625387DCB8F9339F1F0EB148C329652FF9303FD053A74618E51CF8232116
                Malicious:false
                Preview:XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
                Process:C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exe
                File Type:Unicode text, UTF-8 text
                Category:dropped
                Size (bytes):19729
                Entropy (8bit):4.854870578875106
                Encrypted:false
                SSDEEP:384:SfWIec2c8Fn9khSO774VZE+HDxYADgab6YDrvCEE5c:SfWpc8Fn9khSO3yZE+HFYADJv/E5c
                MD5:A9006B652EBD39E033121BBAD1D45AC9
                SHA1:A9A681BD5801984388334C85B8E09561A21913FF
                SHA-256:E84FAFC9058C23AD27C2BE6BB8ED9CAC9AAC1744376330D53D7D531C1EA3EABE
                SHA-512:0B2F899C1FB7030F5ACA15E4F23F250CC62D5014ECBAE0E5CE738F9172895AB82C2B93693F3A078EC3642B3549355E25DA16834A9714CCF8B33087ED3BACAF1B
                Malicious:false
                Preview:/*. * This file is part of the LibreOffice project.. *. * This Source Code Form is subject to the terms of the Mozilla Public. * License, v. 2.0. If a copy of the MPL was not distributed with this. * file, You can obtain one at http://mozilla.org/MPL/2.0/.. *. * This file incorporates work covered by the following license notice:. *. * Licensed to the Apache Software Foundation (ASF) under one or more. * contributor license agreements. See the NOTICE file distributed. * with this work for additional information regarding copyright. * ownership. The ASF licenses this file to you under the Apache. * License, Version 2.0 (the "License"); you may not use this file. * except in compliance with the License. You may obtain a copy of. * the License at http://www.apache.org/licenses/LICENSE-2.0 .. */./*.+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++.+ LIBREOFFICE HELP IN BROWSER +.+ DEFAULT STYLE
                Process:C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exe
                File Type:SVG Scalable Vector Graphics image
                Category:dropped
                Size (bytes):660
                Entropy (8bit):4.929915592008811
                Encrypted:false
                SSDEEP:12:t4CDqaZnoUJgiCydrkeYRAerAFFLAmLRHGdK5D9DME:t4C9ZoUJyyKbRAecFxfRHGMRtME
                MD5:96756F6658DD20BCB387DECC6C2FB720
                SHA1:42E06BBF711B5F71D07B965A0654AFF6249B99D6
                SHA-256:C15238E9B65995BDADC206340B33E7B7E50EF00031F5B61DF9700BBB5350F635
                SHA-512:F64F1B4C96611ADF276F87F242501534DA8D9D2A17A00749A4FE05DE051DA5CAEDF545D39D574BB7E6447CC272C5F9BF2E8B0EE88B277EDDB46D1E263C08FA1B
                Malicious:false
                Preview:<svg xmlns="http://www.w3.org/2000/svg" width="16" height="16"><path d="M8 4v11h3V4zm4-3v14h3V1zM4 7v8h3V7zm-4 3v5h3v-5z" style="line-height:normal;font-variant-ligatures:normal;font-variant-position:normal;font-variant-caps:normal;font-variant-numeric:normal;font-variant-alternates:normal;font-feature-settings:normal;text-indent:0;text-align:start;text-decoration-line:none;text-decoration-style:solid;text-decoration-color:#000;text-transform:none;text-orientation:mixed;shape-padding:0;isolation:auto;mix-blend-mode:normal" overflow="visible" opacity=".35" color="#000" font-weight="400" font-family="sans-serif" fill="#474747" fill-rule="evenodd"/></svg>
                Process:C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exe
                File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                Category:dropped
                Size (bytes):981
                Entropy (8bit):7.490445024712213
                Encrypted:false
                SSDEEP:24:Xtk15wEzJDA4IttcJtoyV+i2FgT17uiW1cWhncisE:XtkHj2t2HoyQxgJY/bsE
                MD5:57788EB5F2415CF88CDDF86A995B497F
                SHA1:CDF8E6B6E0F823C6A77EA66569B61BE5D760BF96
                SHA-256:08F67C366FB7F3371CA2E3B65DA0A4F9AEBD57D18A2990CB7571A8C2ECAD5D41
                SHA-512:024EF704154FC9D0DC38679F1C017691A69E5282E58297F018C40C5957C409B74CFE5F70ACB6BF35CDE8631265366F4E987DF80C1D2E57639253D1CE6FCD5B68
                Malicious:false
                Preview:.PNG........IHDR................a....sBIT....|.d.....pHYs..........+......tEXtSoftware.www.inkscape.org..<.....tEXtTitle.Adwaita Icon Template...?....tEXtAuthor.GNOME Design Team`.v~...RtEXtCopyright.CC Attribution-ShareAlike http://creativecommons.org/licenses/by-sa/4.0/.Tb.....IDAT8...KHTa....w_s.<n3..dY..ZH.hW.ET+.R.....,.ha.hQ...m-J..,.....0(j.0.Ef..L.c53w.w.|-"m|.Y......p....9..0....2.r.{...t..G- ..hU%oU.B26..R.(j../.k.>.....*.(.e..b[nNE#....Q..?......'...Nj.x..h.....!'..Zsu......0p7.....+&..Q.a.;A)..l(.QU^".O.7............m/c..D....@. H..V.P...Qy.uJ.]...S[..z).x..\..G...I6.tn"N.`.YP.PP....0..1...v....f..>N\.o..Z.....r..yw.. ..@.H..1W.....7.2fP0V..&..h.........T...9=.L:..D7...H..........`....39d...z*...[..........8...u.........X..1$..p6.G..`...}'.)..}'o.|.Ttb(-..xAD......D....T>.n..Nw..A...w...!-2....N.....U....Hhq.._$..i.~v.k.!.@b.oH....E&vj.).f.t...8^.{Sy=s1.{.._f./$G...5....x..........@...O[..........`.NB@e.o......t.....V..`U....IEND.B`.
                File type:PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
                Entropy (8bit):6.874744026790643
                TrID:
                • Win32 Executable (generic) a (10002005/4) 99.96%
                • Generic Win/DOS Executable (2004/3) 0.02%
                • DOS Executable Generic (2002/1) 0.02%
                • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.00%
                File name:Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exe
                File size:669600
                MD5:17388d36388d280c4e2d724c9ab58002
                SHA1:ee660100dfbad59a2796244514bff64c66cd0ca7
                SHA256:5f20a33e263b8b8f5388b8e2512d0678312257b8fdf592b8a83aa481076048ca
                SHA512:b49d055149f26ce72cd04ecd6fd581523fdeaf7f3234e8b547fa0fedbaf52aae6b408480c4cebdb7359422d9ae7664dcd8a083d99f13d9fbc1692d4914895ce4
                SSDEEP:12288:Pkvld8NVtfkug41IDHQ215k5P5x2/dKRy6i5y:PeHiMrQ2HkLI/ki5y
                TLSH:40E4F6527059808AE8A738F3685FC07014A02EAD92EDD25E66F67B2645F2313CC5FF9D
                File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........(...F...F...F.*.....F...G.v.F.*.....F...v...F...@...F.Rich..F.........................PE..L....c.W.................^.........
                Icon Hash:3319396623190917
                Entrypoint:0x4030d9
                Entrypoint Section:.text
                Digitally signed:true
                Imagebase:0x400000
                Subsystem:windows gui
                Image File Characteristics:RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE
                DLL Characteristics:DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
                Time Stamp:0x5795638D [Mon Jul 25 00:55:41 2016 UTC]
                TLS Callbacks:
                CLR (.Net) Version:
                OS Version Major:4
                OS Version Minor:0
                File Version Major:4
                File Version Minor:0
                Subsystem Version Major:4
                Subsystem Version Minor:0
                Import Hash:b78ecf47c0a3e24a6f4af114e2d1f5de
                Signature Valid:false
                Signature Issuer:CN=Dictatorialism, OU="Innervational Chloropal Stald ", E=Covalency@Bedrveligheds.Sl, O=Dictatorialism, L=Tarrant Rushton, S=England, C=GB
                Signature Validation Error:A certificate chain processed, but terminated in a root certificate which is not trusted by the trust provider
                Error Number:-2146762487
                Not Before, Not After
                • 1/24/2023 12:31:02 AM 1/23/2026 12:31:02 AM
                Subject Chain
                • CN=Dictatorialism, OU="Innervational Chloropal Stald ", E=Covalency@Bedrveligheds.Sl, O=Dictatorialism, L=Tarrant Rushton, S=England, C=GB
                Version:3
                Thumbprint MD5:7F1F45BD7FCC95B4458C5EC8BFA17430
                Thumbprint SHA-1:31BE90317316BB6D5DBEDE711C3E03BCD2EF533A
                Thumbprint SHA-256:801CB0CF2041D9240AC71DE2FCEEC2FA0C23383EF6BEA436ECE5CCF3C1CB066D
                Serial:E5205A57DA732B09
                Instruction
                sub esp, 00000184h
                push ebx
                push esi
                push edi
                xor ebx, ebx
                push 00008001h
                mov dword ptr [esp+18h], ebx
                mov dword ptr [esp+10h], 00409198h
                mov dword ptr [esp+20h], ebx
                mov byte ptr [esp+14h], 00000020h
                call dword ptr [004070A8h]
                call dword ptr [004070A4h]
                cmp ax, 00000006h
                je 00007FF410ED2933h
                push ebx
                call 00007FF410ED58A1h
                cmp eax, ebx
                je 00007FF410ED2929h
                push 00000C00h
                call eax
                mov esi, 00407298h
                push esi
                call 00007FF410ED581Dh
                push esi
                call dword ptr [004070A0h]
                lea esi, dword ptr [esi+eax+01h]
                cmp byte ptr [esi], bl
                jne 00007FF410ED290Dh
                push ebp
                push 00000009h
                call 00007FF410ED5874h
                push 00000007h
                call 00007FF410ED586Dh
                mov dword ptr [00423704h], eax
                call dword ptr [00407044h]
                push ebx
                call dword ptr [00407288h]
                mov dword ptr [004237B8h], eax
                push ebx
                lea eax, dword ptr [esp+38h]
                push 00000160h
                push eax
                push ebx
                push 0041ECC8h
                call dword ptr [00407174h]
                push 00409188h
                push 00422F00h
                call 00007FF410ED5497h
                call dword ptr [0040709Ch]
                mov ebp, 00429000h
                push eax
                push ebp
                call 00007FF410ED5485h
                push ebx
                call dword ptr [00407154h]
                Programming Language:
                • [EXP] VC++ 6.0 SP5 build 8804
                NameVirtual AddressVirtual Size Is in Section
                IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
                IMAGE_DIRECTORY_ENTRY_IMPORT0x74280xa0.rdata
                IMAGE_DIRECTORY_ENTRY_RESOURCE0x3e0000x5aec8.rsrc
                IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
                IMAGE_DIRECTORY_ENTRY_SECURITY0xa30780x728
                IMAGE_DIRECTORY_ENTRY_BASERELOC0x00x0
                IMAGE_DIRECTORY_ENTRY_DEBUG0x00x0
                IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
                IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
                IMAGE_DIRECTORY_ENTRY_TLS0x00x0
                IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x00x0
                IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
                IMAGE_DIRECTORY_ENTRY_IAT0x70000x298.rdata
                IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
                IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
                IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
                NameVirtual AddressVirtual SizeRaw SizeXored PEZLIB ComplexityFile TypeEntropyCharacteristics
                .text0x10000x5c5b0x5e00False0.6603640292553191data6.411456379497882IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                .rdata0x70000x12460x1400False0.42734375data5.005029341587408IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                .data0x90000x1a7f80x400False0.6376953125data5.108396988130901IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                .ndata0x240000x1a0000x0False0empty0.0IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                .rsrc0x3e0000x5aec80x5b000False0.23903245192307693data5.402063687419607IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                NameRVASizeTypeLanguageCountry
                RT_ICON0x3e2b00x42028Device independent bitmap graphic, 256 x 512 x 32, image size 270336EnglishUnited States
                RT_ICON0x802d80x10828Device independent bitmap graphic, 128 x 256 x 32, image size 67584EnglishUnited States
                RT_ICON0x90b000x4228Device independent bitmap graphic, 64 x 128 x 32, image size 16896EnglishUnited States
                RT_ICON0x94d280x25a8Device independent bitmap graphic, 48 x 96 x 32, image size 9600EnglishUnited States
                RT_ICON0x972d00x10a8Device independent bitmap graphic, 32 x 64 x 32, image size 4224EnglishUnited States
                RT_ICON0x983780x468Device independent bitmap graphic, 16 x 32 x 32, image size 1088EnglishUnited States
                RT_DIALOG0x987e00x100dataEnglishUnited States
                RT_DIALOG0x988e00x11cdataEnglishUnited States
                RT_DIALOG0x98a000xc4dataEnglishUnited States
                RT_DIALOG0x98ac80x60dataEnglishUnited States
                RT_GROUP_ICON0x98b280x5adataEnglishUnited States
                RT_MANIFEST0x98b880x33dXML 1.0 document, ASCII text, with very long lines (829), with no line terminatorsEnglishUnited States
                DLLImport
                KERNEL32.dllSetEnvironmentVariableA, Sleep, GetTickCount, GetFileSize, GetModuleFileNameA, GetCurrentProcess, CopyFileA, GetFileAttributesA, SetFileAttributesA, GetWindowsDirectoryA, GetTempPathA, GetCommandLineA, lstrlenA, GetVersion, SetErrorMode, lstrcpynA, ExitProcess, GetFullPathNameA, GlobalLock, CreateThread, GetLastError, CreateDirectoryA, CreateProcessA, RemoveDirectoryA, CreateFileA, GetTempFileNameA, ReadFile, WriteFile, lstrcpyA, MoveFileExA, lstrcatA, GetSystemDirectoryA, GetProcAddress, CloseHandle, SetCurrentDirectoryA, MoveFileA, CompareFileTime, GetShortPathNameA, SearchPathA, lstrcmpiA, SetFileTime, lstrcmpA, ExpandEnvironmentStringsA, GlobalUnlock, GetDiskFreeSpaceA, GlobalFree, FindFirstFileA, FindNextFileA, DeleteFileA, SetFilePointer, GetPrivateProfileStringA, FindClose, MultiByteToWideChar, FreeLibrary, MulDiv, WritePrivateProfileStringA, LoadLibraryExA, GetModuleHandleA, GetExitCodeProcess, WaitForSingleObject, GlobalAlloc
                USER32.dllScreenToClient, GetSystemMenu, SetClassLongA, IsWindowEnabled, SetWindowPos, GetSysColor, GetWindowLongA, SetCursor, LoadCursorA, CheckDlgButton, GetMessagePos, LoadBitmapA, CallWindowProcA, IsWindowVisible, CloseClipboard, SetClipboardData, EmptyClipboard, PostQuitMessage, GetWindowRect, EnableMenuItem, CreatePopupMenu, GetSystemMetrics, SetDlgItemTextA, GetDlgItemTextA, MessageBoxIndirectA, CharPrevA, DispatchMessageA, PeekMessageA, ReleaseDC, EnableWindow, InvalidateRect, SendMessageA, DefWindowProcA, BeginPaint, GetClientRect, FillRect, DrawTextA, EndDialog, RegisterClassA, SystemParametersInfoA, CreateWindowExA, GetClassInfoA, DialogBoxParamA, CharNextA, ExitWindowsEx, GetDC, CreateDialogParamA, SetTimer, GetDlgItem, SetWindowLongA, SetForegroundWindow, LoadImageA, IsWindow, SendMessageTimeoutA, FindWindowExA, OpenClipboard, TrackPopupMenu, AppendMenuA, EndPaint, DestroyWindow, wsprintfA, ShowWindow, SetWindowTextA
                GDI32.dllSelectObject, SetBkMode, CreateFontIndirectA, SetTextColor, DeleteObject, GetDeviceCaps, CreateBrushIndirect, SetBkColor
                SHELL32.dllSHGetSpecialFolderLocation, SHGetPathFromIDListA, SHBrowseForFolderA, SHGetFileInfoA, ShellExecuteA, SHFileOperationA
                ADVAPI32.dllRegDeleteKeyA, SetFileSecurityA, OpenProcessToken, LookupPrivilegeValueA, AdjustTokenPrivileges, RegOpenKeyExA, RegEnumValueA, RegDeleteValueA, RegCloseKey, RegCreateKeyExA, RegSetValueExA, RegQueryValueExA, RegEnumKeyA
                COMCTL32.dllImageList_Create, ImageList_AddMasked, ImageList_Destroy
                ole32.dllOleUninitialize, OleInitialize, CoTaskMemFree, CoCreateInstance
                Language of compilation systemCountry where language is spokenMap
                EnglishUnited States
                No network behavior found

                Click to jump to process

                Target ID:0
                Start time:09:53:42
                Start date:25/01/2023
                Path:C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exe
                Wow64 process (32bit):true
                Commandline:C:\Users\user\Desktop\Pilne zamowienie nr5363582 UTECH Maszyny i Urzadzenia Techniczne Jaroslaw Koenig sp. k..exe
                Imagebase:0x400000
                File size:669600 bytes
                MD5 hash:17388D36388D280C4E2D724C9AB58002
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Yara matches:
                • Rule: JoeSecurity_GuLoader_3, Description: Yara detected GuLoader, Source: 00000000.00000002.514197554.0000000000613000.00000004.00000020.00020000.00000000.sdmp, Author: Joe Security
                Reputation:low

                Target ID:1
                Start time:09:53:44
                Start date:25/01/2023
                Path:C:\Windows\SysWOW64\cmd.exe
                Wow64 process (32bit):
                Commandline:cmd.exe /c set /A "0x0E^75"
                Imagebase:
                File size:232960 bytes
                MD5 hash:F3BDBE3BB6F734E357235F4D5898582D
                Has elevated privileges:
                Has administrator privileges:
                Programmed in:C, C++ or other language
                Reputation:high

                Target ID:2
                Start time:09:53:44
                Start date:25/01/2023
                Path:C:\Windows\System32\Conhost.exe
                Wow64 process (32bit):
                Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                Imagebase:
                File size:625664 bytes
                MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                Has elevated privileges:
                Has administrator privileges:
                Programmed in:C, C++ or other language
                Reputation:high

                Target ID:3
                Start time:09:53:44
                Start date:25/01/2023
                Path:C:\Windows\SysWOW64\cmd.exe
                Wow64 process (32bit):
                Commandline:cmd.exe /c set /A "0x19^75"
                Imagebase:
                File size:232960 bytes
                MD5 hash:F3BDBE3BB6F734E357235F4D5898582D
                Has elevated privileges:
                Has administrator privileges:
                Programmed in:C, C++ or other language
                Reputation:high

                Target ID:4
                Start time:09:53:44
                Start date:25/01/2023
                Path:C:\Windows\System32\Conhost.exe
                Wow64 process (32bit):
                Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                Imagebase:
                File size:625664 bytes
                MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                Has elevated privileges:
                Has administrator privileges:
                Programmed in:C, C++ or other language
                Reputation:high

                Target ID:5
                Start time:09:53:44
                Start date:25/01/2023
                Path:C:\Windows\SysWOW64\cmd.exe
                Wow64 process (32bit):
                Commandline:cmd.exe /c set /A "0x05^75"
                Imagebase:
                File size:232960 bytes
                MD5 hash:F3BDBE3BB6F734E357235F4D5898582D
                Has elevated privileges:
                Has administrator privileges:
                Programmed in:C, C++ or other language
                Reputation:high

                Target ID:6
                Start time:09:53:44
                Start date:25/01/2023
                Path:C:\Windows\System32\Conhost.exe
                Wow64 process (32bit):
                Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                Imagebase:
                File size:625664 bytes
                MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                Has elevated privileges:
                Has administrator privileges:
                Programmed in:C, C++ or other language
                Reputation:high

                Target ID:7
                Start time:09:53:44
                Start date:25/01/2023
                Path:C:\Windows\SysWOW64\cmd.exe
                Wow64 process (32bit):
                Commandline:cmd.exe /c set /A "0x0E^75"
                Imagebase:
                File size:232960 bytes
                MD5 hash:F3BDBE3BB6F734E357235F4D5898582D
                Has elevated privileges:
                Has administrator privileges:
                Programmed in:C, C++ or other language
                Reputation:high

                Target ID:8
                Start time:09:53:44
                Start date:25/01/2023
                Path:C:\Windows\System32\Conhost.exe
                Wow64 process (32bit):
                Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                Imagebase:
                File size:625664 bytes
                MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                Has elevated privileges:
                Has administrator privileges:
                Programmed in:C, C++ or other language
                Reputation:high

                Target ID:9
                Start time:09:53:44
                Start date:25/01/2023
                Path:C:\Windows\SysWOW64\cmd.exe
                Wow64 process (32bit):
                Commandline:cmd.exe /c set /A "0x07^75"
                Imagebase:
                File size:232960 bytes
                MD5 hash:F3BDBE3BB6F734E357235F4D5898582D
                Has elevated privileges:
                Has administrator privileges:
                Programmed in:C, C++ or other language

                Target ID:10
                Start time:09:53:44
                Start date:25/01/2023
                Path:C:\Windows\System32\Conhost.exe
                Wow64 process (32bit):
                Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                Imagebase:
                File size:625664 bytes
                MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                Has elevated privileges:
                Has administrator privileges:
                Programmed in:C, C++ or other language

                Target ID:11
                Start time:09:53:44
                Start date:25/01/2023
                Path:C:\Windows\SysWOW64\cmd.exe
                Wow64 process (32bit):
                Commandline:cmd.exe /c set /A "0x78^75"
                Imagebase:
                File size:232960 bytes
                MD5 hash:F3BDBE3BB6F734E357235F4D5898582D
                Has elevated privileges:
                Has administrator privileges:
                Programmed in:C, C++ or other language

                Target ID:12
                Start time:09:53:44
                Start date:25/01/2023
                Path:C:\Windows\System32\Conhost.exe
                Wow64 process (32bit):
                Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                Imagebase:
                File size:625664 bytes
                MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                Has elevated privileges:
                Has administrator privileges:
                Programmed in:C, C++ or other language

                Target ID:13
                Start time:09:53:44
                Start date:25/01/2023
                Path:C:\Windows\SysWOW64\cmd.exe
                Wow64 process (32bit):
                Commandline:cmd.exe /c set /A "0x79^75"
                Imagebase:
                File size:232960 bytes
                MD5 hash:F3BDBE3BB6F734E357235F4D5898582D
                Has elevated privileges:
                Has administrator privileges:
                Programmed in:C, C++ or other language

                Target ID:14
                Start time:09:53:45
                Start date:25/01/2023
                Path:C:\Windows\System32\Conhost.exe
                Wow64 process (32bit):
                Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                Imagebase:
                File size:625664 bytes
                MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                Has elevated privileges:
                Has administrator privileges:
                Programmed in:C, C++ or other language

                Target ID:15
                Start time:09:53:45
                Start date:25/01/2023
                Path:C:\Windows\SysWOW64\cmd.exe
                Wow64 process (32bit):
                Commandline:cmd.exe /c set /A "0x71^75"
                Imagebase:
                File size:232960 bytes
                MD5 hash:F3BDBE3BB6F734E357235F4D5898582D
                Has elevated privileges:
                Has administrator privileges:
                Programmed in:C, C++ or other language

                Target ID:16
                Start time:09:53:45
                Start date:25/01/2023
                Path:C:\Windows\System32\Conhost.exe
                Wow64 process (32bit):
                Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                Imagebase:
                File size:625664 bytes
                MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                Has elevated privileges:
                Has administrator privileges:
                Programmed in:C, C++ or other language

                Target ID:17
                Start time:09:53:45
                Start date:25/01/2023
                Path:C:\Windows\SysWOW64\cmd.exe
                Wow64 process (32bit):
                Commandline:cmd.exe /c set /A "0x71^75"
                Imagebase:
                File size:232960 bytes
                MD5 hash:F3BDBE3BB6F734E357235F4D5898582D
                Has elevated privileges:
                Has administrator privileges:
                Programmed in:C, C++ or other language

                Target ID:18
                Start time:09:53:45
                Start date:25/01/2023
                Path:C:\Windows\System32\Conhost.exe
                Wow64 process (32bit):
                Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                Imagebase:
                File size:625664 bytes
                MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                Has elevated privileges:
                Has administrator privileges:
                Programmed in:C, C++ or other language

                Target ID:19
                Start time:09:53:45
                Start date:25/01/2023
                Path:C:\Windows\SysWOW64\cmd.exe
                Wow64 process (32bit):
                Commandline:cmd.exe /c set /A "0x08^75"
                Imagebase:
                File size:232960 bytes
                MD5 hash:F3BDBE3BB6F734E357235F4D5898582D
                Has elevated privileges:
                Has administrator privileges:
                Programmed in:C, C++ or other language

                Target ID:20
                Start time:09:53:45
                Start date:25/01/2023
                Path:C:\Windows\System32\Conhost.exe
                Wow64 process (32bit):
                Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                Imagebase:
                File size:625664 bytes
                MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                Has elevated privileges:
                Has administrator privileges:
                Programmed in:C, C++ or other language

                Target ID:21
                Start time:09:53:45
                Start date:25/01/2023
                Path:C:\Windows\SysWOW64\cmd.exe
                Wow64 process (32bit):
                Commandline:cmd.exe /c set /A "0x39^75"
                Imagebase:
                File size:232960 bytes
                MD5 hash:F3BDBE3BB6F734E357235F4D5898582D
                Has elevated privileges:
                Has administrator privileges:
                Programmed in:C, C++ or other language

                Target ID:22
                Start time:09:53:45
                Start date:25/01/2023
                Path:C:\Windows\System32\Conhost.exe
                Wow64 process (32bit):
                Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                Imagebase:
                File size:625664 bytes
                MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                Has elevated privileges:
                Has administrator privileges:
                Programmed in:C, C++ or other language

                Target ID:23
                Start time:09:53:45
                Start date:25/01/2023
                Path:C:\Windows\SysWOW64\cmd.exe
                Wow64 process (32bit):
                Commandline:cmd.exe /c set /A "0x2E^75"
                Imagebase:
                File size:232960 bytes
                MD5 hash:F3BDBE3BB6F734E357235F4D5898582D
                Has elevated privileges:
                Has administrator privileges:
                Programmed in:C, C++ or other language

                Target ID:24
                Start time:09:53:45
                Start date:25/01/2023
                Path:C:\Windows\System32\Conhost.exe
                Wow64 process (32bit):
                Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                Imagebase:
                File size:625664 bytes
                MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                Has elevated privileges:
                Has administrator privileges:
                Programmed in:C, C++ or other language

                Target ID:25
                Start time:09:53:45
                Start date:25/01/2023
                Path:C:\Windows\SysWOW64\cmd.exe
                Wow64 process (32bit):
                Commandline:cmd.exe /c set /A "0x2A^75"
                Imagebase:
                File size:232960 bytes
                MD5 hash:F3BDBE3BB6F734E357235F4D5898582D
                Has elevated privileges:
                Has administrator privileges:
                Programmed in:C, C++ or other language

                Target ID:26
                Start time:09:53:45
                Start date:25/01/2023
                Path:C:\Windows\System32\Conhost.exe
                Wow64 process (32bit):
                Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                Imagebase:
                File size:625664 bytes
                MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                Has elevated privileges:
                Has administrator privileges:
                Programmed in:C, C++ or other language

                Target ID:27
                Start time:09:53:45
                Start date:25/01/2023
                Path:C:\Windows\SysWOW64\cmd.exe
                Wow64 process (32bit):
                Commandline:cmd.exe /c set /A "0x3F^75"
                Imagebase:
                File size:232960 bytes
                MD5 hash:F3BDBE3BB6F734E357235F4D5898582D
                Has elevated privileges:
                Has administrator privileges:
                Programmed in:C, C++ or other language

                Target ID:28
                Start time:09:53:45
                Start date:25/01/2023
                Path:C:\Windows\System32\Conhost.exe
                Wow64 process (32bit):
                Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                Imagebase:
                File size:625664 bytes
                MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                Has elevated privileges:
                Has administrator privileges:
                Programmed in:C, C++ or other language

                Target ID:29
                Start time:09:53:46
                Start date:25/01/2023
                Path:C:\Windows\SysWOW64\cmd.exe
                Wow64 process (32bit):
                Commandline:cmd.exe /c set /A "0x2E^75"
                Imagebase:
                File size:232960 bytes
                MD5 hash:F3BDBE3BB6F734E357235F4D5898582D
                Has elevated privileges:
                Has administrator privileges:
                Programmed in:C, C++ or other language

                Target ID:30
                Start time:09:53:46
                Start date:25/01/2023
                Path:C:\Windows\System32\Conhost.exe
                Wow64 process (32bit):
                Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                Imagebase:
                File size:625664 bytes
                MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                Has elevated privileges:
                Has administrator privileges:
                Programmed in:C, C++ or other language

                Target ID:31
                Start time:09:53:46
                Start date:25/01/2023
                Path:C:\Windows\SysWOW64\cmd.exe
                Wow64 process (32bit):
                Commandline:cmd.exe /c set /A "0x0D^75"
                Imagebase:
                File size:232960 bytes
                MD5 hash:F3BDBE3BB6F734E357235F4D5898582D
                Has elevated privileges:
                Has administrator privileges:
                Programmed in:C, C++ or other language

                Target ID:32
                Start time:09:53:46
                Start date:25/01/2023
                Path:C:\Windows\System32\Conhost.exe
                Wow64 process (32bit):
                Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                Imagebase:
                File size:625664 bytes
                MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                Has elevated privileges:
                Has administrator privileges:
                Programmed in:C, C++ or other language

                Target ID:33
                Start time:09:53:46
                Start date:25/01/2023
                Path:C:\Windows\SysWOW64\cmd.exe
                Wow64 process (32bit):
                Commandline:cmd.exe /c set /A "0x22^75"
                Imagebase:
                File size:232960 bytes
                MD5 hash:F3BDBE3BB6F734E357235F4D5898582D
                Has elevated privileges:
                Has administrator privileges:
                Programmed in:C, C++ or other language

                Target ID:34
                Start time:09:53:46
                Start date:25/01/2023
                Path:C:\Windows\System32\Conhost.exe
                Wow64 process (32bit):
                Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                Imagebase:
                File size:625664 bytes
                MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                Has elevated privileges:
                Has administrator privileges:
                Programmed in:C, C++ or other language

                Target ID:35
                Start time:09:53:46
                Start date:25/01/2023
                Path:C:\Windows\SysWOW64\cmd.exe
                Wow64 process (32bit):
                Commandline:cmd.exe /c set /A "0x27^75"
                Imagebase:
                File size:232960 bytes
                MD5 hash:F3BDBE3BB6F734E357235F4D5898582D
                Has elevated privileges:
                Has administrator privileges:
                Programmed in:C, C++ or other language

                Target ID:36
                Start time:09:53:46
                Start date:25/01/2023
                Path:C:\Windows\System32\Conhost.exe
                Wow64 process (32bit):
                Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                Imagebase:
                File size:625664 bytes
                MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                Has elevated privileges:
                Has administrator privileges:
                Programmed in:C, C++ or other language

                Target ID:37
                Start time:09:53:46
                Start date:25/01/2023
                Path:C:\Windows\SysWOW64\cmd.exe
                Wow64 process (32bit):
                Commandline:cmd.exe /c set /A "0x2E^75"
                Imagebase:
                File size:232960 bytes
                MD5 hash:F3BDBE3BB6F734E357235F4D5898582D
                Has elevated privileges:
                Has administrator privileges:
                Programmed in:C, C++ or other language

                Target ID:38
                Start time:09:53:46
                Start date:25/01/2023
                Path:C:\Windows\System32\Conhost.exe
                Wow64 process (32bit):
                Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                Imagebase:
                File size:625664 bytes
                MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                Has elevated privileges:
                Has administrator privileges:
                Programmed in:C, C++ or other language

                Target ID:39
                Start time:09:53:46
                Start date:25/01/2023
                Path:C:\Windows\SysWOW64\cmd.exe
                Wow64 process (32bit):
                Commandline:cmd.exe /c set /A "0x0A^75"
                Imagebase:
                File size:232960 bytes
                MD5 hash:F3BDBE3BB6F734E357235F4D5898582D
                Has elevated privileges:
                Has administrator privileges:
                Programmed in:C, C++ or other language

                Target ID:40
                Start time:09:53:46
                Start date:25/01/2023
                Path:C:\Windows\System32\Conhost.exe
                Wow64 process (32bit):
                Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                Imagebase:
                File size:625664 bytes
                MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                Has elevated privileges:
                Has administrator privileges:
                Programmed in:C, C++ or other language

                Target ID:41
                Start time:09:53:46
                Start date:25/01/2023
                Path:C:\Windows\SysWOW64\cmd.exe
                Wow64 process (32bit):
                Commandline:cmd.exe /c set /A "0x63^75"
                Imagebase:
                File size:232960 bytes
                MD5 hash:F3BDBE3BB6F734E357235F4D5898582D
                Has elevated privileges:
                Has administrator privileges:
                Programmed in:C, C++ or other language

                Target ID:42
                Start time:09:53:46
                Start date:25/01/2023
                Path:C:\Windows\System32\Conhost.exe
                Wow64 process (32bit):
                Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                Imagebase:
                File size:625664 bytes
                MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                Has elevated privileges:
                Has administrator privileges:
                Programmed in:C, C++ or other language

                Target ID:43
                Start time:09:53:47
                Start date:25/01/2023
                Path:C:\Windows\SysWOW64\cmd.exe
                Wow64 process (32bit):
                Commandline:cmd.exe /c set /A "0x26^75"
                Imagebase:
                File size:232960 bytes
                MD5 hash:F3BDBE3BB6F734E357235F4D5898582D
                Has elevated privileges:
                Has administrator privileges:
                Programmed in:C, C++ or other language

                Target ID:44
                Start time:09:53:47
                Start date:25/01/2023
                Path:C:\Windows\System32\Conhost.exe
                Wow64 process (32bit):false
                Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                Imagebase:0x7ff745070000
                File size:625664 bytes
                MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                Has elevated privileges:
                Has administrator privileges:
                Programmed in:C, C++ or other language

                Target ID:45
                Start time:09:53:47
                Start date:25/01/2023
                Path:C:\Windows\SysWOW64\cmd.exe
                Wow64 process (32bit):
                Commandline:cmd.exe /c set /A "0x6B^75"
                Imagebase:
                File size:232960 bytes
                MD5 hash:F3BDBE3BB6F734E357235F4D5898582D
                Has elevated privileges:
                Has administrator privileges:
                Programmed in:C, C++ or other language

                Target ID:46
                Start time:09:53:47
                Start date:25/01/2023
                Path:C:\Windows\System32\Conhost.exe
                Wow64 process (32bit):
                Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                Imagebase:
                File size:625664 bytes
                MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                Has elevated privileges:
                Has administrator privileges:
                Programmed in:C, C++ or other language

                Target ID:47
                Start time:09:53:47
                Start date:25/01/2023
                Path:C:\Windows\SysWOW64\cmd.exe
                Wow64 process (32bit):
                Commandline:cmd.exe /c set /A "0x39^75"
                Imagebase:
                File size:232960 bytes
                MD5 hash:F3BDBE3BB6F734E357235F4D5898582D
                Has elevated privileges:
                Has administrator privileges:
                Programmed in:C, C++ or other language

                Target ID:48
                Start time:09:53:47
                Start date:25/01/2023
                Path:C:\Windows\System32\Conhost.exe
                Wow64 process (32bit):
                Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                Imagebase:
                File size:625664 bytes
                MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                Has elevated privileges:
                Has administrator privileges:
                Programmed in:C, C++ or other language

                Target ID:49
                Start time:09:53:47
                Start date:25/01/2023
                Path:C:\Windows\SysWOW64\cmd.exe
                Wow64 process (32bit):
                Commandline:cmd.exe /c set /A "0x7F^75"
                Imagebase:
                File size:232960 bytes
                MD5 hash:F3BDBE3BB6F734E357235F4D5898582D
                Has elevated privileges:
                Has administrator privileges:
                Programmed in:C, C++ or other language

                Target ID:50
                Start time:09:53:47
                Start date:25/01/2023
                Path:C:\Windows\System32\Conhost.exe
                Wow64 process (32bit):
                Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                Imagebase:
                File size:625664 bytes
                MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                Has elevated privileges:
                Has administrator privileges:
                Programmed in:C, C++ or other language

                Target ID:51
                Start time:09:53:47
                Start date:25/01/2023
                Path:C:\Windows\SysWOW64\cmd.exe
                Wow64 process (32bit):
                Commandline:cmd.exe /c set /A "0x6B^75"
                Imagebase:
                File size:232960 bytes
                MD5 hash:F3BDBE3BB6F734E357235F4D5898582D
                Has elevated privileges:
                Has administrator privileges:
                Programmed in:C, C++ or other language

                Target ID:52
                Start time:09:53:47
                Start date:25/01/2023
                Path:C:\Windows\System32\Conhost.exe
                Wow64 process (32bit):
                Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                Imagebase:
                File size:625664 bytes
                MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                Has elevated privileges:
                Has administrator privileges:
                Programmed in:C, C++ or other language

                Target ID:53
                Start time:09:53:47
                Start date:25/01/2023
                Path:C:\Windows\SysWOW64\cmd.exe
                Wow64 process (32bit):
                Commandline:cmd.exe /c set /A "0x67^75"
                Imagebase:
                File size:232960 bytes
                MD5 hash:F3BDBE3BB6F734E357235F4D5898582D
                Has elevated privileges:
                Has administrator privileges:
                Programmed in:C, C++ or other language

                Target ID:54
                Start time:09:53:47
                Start date:25/01/2023
                Path:C:\Windows\System32\Conhost.exe
                Wow64 process (32bit):
                Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                Imagebase:
                File size:625664 bytes
                MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                Has elevated privileges:
                Has administrator privileges:
                Programmed in:C, C++ or other language

                Target ID:55
                Start time:09:53:47
                Start date:25/01/2023
                Path:C:\Windows\SysWOW64\cmd.exe
                Wow64 process (32bit):
                Commandline:cmd.exe /c set /A "0x6B^75"
                Imagebase:
                File size:232960 bytes
                MD5 hash:F3BDBE3BB6F734E357235F4D5898582D
                Has elevated privileges:
                Has administrator privileges:
                Programmed in:C, C++ or other language

                Target ID:56
                Start time:09:53:47
                Start date:25/01/2023
                Path:C:\Windows\System32\Conhost.exe
                Wow64 process (32bit):
                Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                Imagebase:
                File size:625664 bytes
                MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                Has elevated privileges:
                Has administrator privileges:
                Programmed in:C, C++ or other language

                Target ID:57
                Start time:09:53:47
                Start date:25/01/2023
                Path:C:\Windows\SysWOW64\cmd.exe
                Wow64 process (32bit):
                Commandline:cmd.exe /c set /A "0x22^75"
                Imagebase:
                File size:232960 bytes
                MD5 hash:F3BDBE3BB6F734E357235F4D5898582D
                Has elevated privileges:
                Has administrator privileges:
                Programmed in:C, C++ or other language

                Target ID:58
                Start time:09:53:48
                Start date:25/01/2023
                Path:C:\Windows\System32\Conhost.exe
                Wow64 process (32bit):
                Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                Imagebase:
                File size:625664 bytes
                MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                Has elevated privileges:
                Has administrator privileges:
                Programmed in:C, C++ or other language

                Target ID:59
                Start time:09:53:48
                Start date:25/01/2023
                Path:C:\Windows\SysWOW64\cmd.exe
                Wow64 process (32bit):
                Commandline:cmd.exe /c set /A "0x6B^75"
                Imagebase:
                File size:232960 bytes
                MD5 hash:F3BDBE3BB6F734E357235F4D5898582D
                Has elevated privileges:
                Has administrator privileges:
                Programmed in:C, C++ or other language

                Target ID:60
                Start time:09:53:48
                Start date:25/01/2023
                Path:C:\Windows\System32\Conhost.exe
                Wow64 process (32bit):
                Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                Imagebase:
                File size:625664 bytes
                MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                Has elevated privileges:
                Has administrator privileges:
                Programmed in:C, C++ or other language

                Target ID:61
                Start time:09:53:48
                Start date:25/01/2023
                Path:C:\Windows\SysWOW64\cmd.exe
                Wow64 process (32bit):
                Commandline:cmd.exe /c set /A "0x7B^75"
                Imagebase:
                File size:232960 bytes
                MD5 hash:F3BDBE3BB6F734E357235F4D5898582D
                Has elevated privileges:
                Has administrator privileges:
                Programmed in:C, C++ or other language

                Target ID:62
                Start time:09:53:48
                Start date:25/01/2023
                Path:C:\Windows\System32\Conhost.exe
                Wow64 process (32bit):
                Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                Imagebase:
                File size:625664 bytes
                MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                Has elevated privileges:
                Has administrator privileges:
                Programmed in:C, C++ or other language

                Target ID:63
                Start time:09:53:48
                Start date:25/01/2023
                Path:C:\Windows\SysWOW64\cmd.exe
                Wow64 process (32bit):
                Commandline:cmd.exe /c set /A "0x33^75"
                Imagebase:
                File size:232960 bytes
                MD5 hash:F3BDBE3BB6F734E357235F4D5898582D
                Has elevated privileges:
                Has administrator privileges:
                Programmed in:C, C++ or other language

                Target ID:64
                Start time:09:53:48
                Start date:25/01/2023
                Path:C:\Windows\System32\Conhost.exe
                Wow64 process (32bit):
                Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                Imagebase:
                File size:625664 bytes
                MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                Has elevated privileges:
                Has administrator privileges:
                Programmed in:C, C++ or other language

                Target ID:65
                Start time:09:53:48
                Start date:25/01/2023
                Path:C:\Windows\SysWOW64\cmd.exe
                Wow64 process (32bit):
                Commandline:cmd.exe /c set /A "0x73^75"
                Imagebase:
                File size:232960 bytes
                MD5 hash:F3BDBE3BB6F734E357235F4D5898582D
                Has elevated privileges:
                Has administrator privileges:
                Programmed in:C, C++ or other language

                Target ID:66
                Start time:09:53:48
                Start date:25/01/2023
                Path:C:\Windows\System32\Conhost.exe
                Wow64 process (32bit):
                Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                Imagebase:
                File size:625664 bytes
                MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                Has elevated privileges:
                Has administrator privileges:
                Programmed in:C, C++ or other language

                Target ID:67
                Start time:09:53:48
                Start date:25/01/2023
                Path:C:\Windows\SysWOW64\cmd.exe
                Wow64 process (32bit):
                Commandline:cmd.exe /c set /A "0x7B^75"
                Imagebase:
                File size:232960 bytes
                MD5 hash:F3BDBE3BB6F734E357235F4D5898582D
                Has elevated privileges:
                Has administrator privileges:
                Programmed in:C, C++ or other language

                Target ID:68
                Start time:09:53:48
                Start date:25/01/2023
                Path:C:\Windows\System32\Conhost.exe
                Wow64 process (32bit):
                Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                Imagebase:
                File size:625664 bytes
                MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                Has elevated privileges:
                Has administrator privileges:
                Programmed in:C, C++ or other language

                Target ID:69
                Start time:09:53:48
                Start date:25/01/2023
                Path:C:\Windows\SysWOW64\cmd.exe
                Wow64 process (32bit):
                Commandline:cmd.exe /c set /A "0x7B^75"
                Imagebase:
                File size:232960 bytes
                MD5 hash:F3BDBE3BB6F734E357235F4D5898582D
                Has elevated privileges:
                Has administrator privileges:
                Programmed in:C, C++ or other language

                Target ID:70
                Start time:09:53:48
                Start date:25/01/2023
                Path:C:\Windows\System32\Conhost.exe
                Wow64 process (32bit):
                Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                Imagebase:
                File size:625664 bytes
                MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                Has elevated privileges:
                Has administrator privileges:
                Programmed in:C, C++ or other language

                Target ID:71
                Start time:09:53:48
                Start date:25/01/2023
                Path:C:\Windows\SysWOW64\cmd.exe
                Wow64 process (32bit):
                Commandline:cmd.exe /c set /A "0x7B^75"
                Imagebase:
                File size:232960 bytes
                MD5 hash:F3BDBE3BB6F734E357235F4D5898582D
                Has elevated privileges:
                Has administrator privileges:
                Programmed in:C, C++ or other language

                Target ID:72
                Start time:09:53:48
                Start date:25/01/2023
                Path:C:\Windows\System32\Conhost.exe
                Wow64 process (32bit):
                Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                Imagebase:
                File size:625664 bytes
                MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                Has elevated privileges:
                Has administrator privileges:
                Programmed in:C, C++ or other language

                Target ID:73
                Start time:09:53:49
                Start date:25/01/2023
                Path:C:\Windows\SysWOW64\cmd.exe
                Wow64 process (32bit):
                Commandline:cmd.exe /c set /A "0x7B^75"
                Imagebase:
                File size:232960 bytes
                MD5 hash:F3BDBE3BB6F734E357235F4D5898582D
                Has elevated privileges:
                Has administrator privileges:
                Programmed in:C, C++ or other language

                Target ID:74
                Start time:09:53:49
                Start date:25/01/2023
                Path:C:\Windows\System32\Conhost.exe
                Wow64 process (32bit):
                Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                Imagebase:
                File size:625664 bytes
                MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                Has elevated privileges:
                Has administrator privileges:
                Programmed in:C, C++ or other language

                Target ID:75
                Start time:09:53:49
                Start date:25/01/2023
                Path:C:\Windows\SysWOW64\cmd.exe
                Wow64 process (32bit):
                Commandline:cmd.exe /c set /A "0x7B^75"
                Imagebase:
                File size:232960 bytes
                MD5 hash:F3BDBE3BB6F734E357235F4D5898582D
                Has elevated privileges:
                Has administrator privileges:
                Programmed in:C, C++ or other language

                Target ID:76
                Start time:09:53:49
                Start date:25/01/2023
                Path:C:\Windows\System32\Conhost.exe
                Wow64 process (32bit):
                Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                Imagebase:
                File size:625664 bytes
                MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                Has elevated privileges:
                Has administrator privileges:
                Programmed in:C, C++ or other language

                Target ID:77
                Start time:09:53:49
                Start date:25/01/2023
                Path:C:\Windows\SysWOW64\cmd.exe
                Wow64 process (32bit):
                Commandline:cmd.exe /c set /A "0x7B^75"
                Imagebase:
                File size:232960 bytes
                MD5 hash:F3BDBE3BB6F734E357235F4D5898582D
                Has elevated privileges:
                Has administrator privileges:
                Programmed in:C, C++ or other language

                Target ID:78
                Start time:09:53:49
                Start date:25/01/2023
                Path:C:\Windows\System32\Conhost.exe
                Wow64 process (32bit):
                Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                Imagebase:
                File size:625664 bytes
                MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                Has elevated privileges:
                Has administrator privileges:
                Programmed in:C, C++ or other language

                Target ID:79
                Start time:09:53:49
                Start date:25/01/2023
                Path:C:\Windows\SysWOW64\cmd.exe
                Wow64 process (32bit):
                Commandline:cmd.exe /c set /A "0x7B^75"
                Imagebase:
                File size:232960 bytes
                MD5 hash:F3BDBE3BB6F734E357235F4D5898582D
                Has elevated privileges:
                Has administrator privileges:
                Programmed in:C, C++ or other language

                Target ID:80
                Start time:09:53:49
                Start date:25/01/2023
                Path:C:\Windows\System32\Conhost.exe
                Wow64 process (32bit):
                Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                Imagebase:
                File size:625664 bytes
                MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                Has elevated privileges:
                Has administrator privileges:
                Programmed in:C, C++ or other language

                Target ID:81
                Start time:09:53:49
                Start date:25/01/2023
                Path:C:\Windows\SysWOW64\cmd.exe
                Wow64 process (32bit):
                Commandline:cmd.exe /c set /A "0x67^75"
                Imagebase:
                File size:232960 bytes
                MD5 hash:F3BDBE3BB6F734E357235F4D5898582D
                Has elevated privileges:
                Has administrator privileges:
                Programmed in:C, C++ or other language

                Target ID:82
                Start time:09:53:49
                Start date:25/01/2023
                Path:C:\Windows\System32\Conhost.exe
                Wow64 process (32bit):
                Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                Imagebase:
                File size:625664 bytes
                MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                Has elevated privileges:
                Has administrator privileges:
                Programmed in:C, C++ or other language

                Target ID:83
                Start time:09:53:49
                Start date:25/01/2023
                Path:C:\Windows\SysWOW64\cmd.exe
                Wow64 process (32bit):
                Commandline:cmd.exe /c set /A "0x6B^75"
                Imagebase:
                File size:232960 bytes
                MD5 hash:F3BDBE3BB6F734E357235F4D5898582D
                Has elevated privileges:
                Has administrator privileges:
                Programmed in:C, C++ or other language

                Target ID:84
                Start time:09:53:49
                Start date:25/01/2023
                Path:C:\Windows\System32\Conhost.exe
                Wow64 process (32bit):
                Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                Imagebase:
                File size:625664 bytes
                MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                Has elevated privileges:
                Has administrator privileges:
                Programmed in:C, C++ or other language

                Target ID:85
                Start time:09:53:49
                Start date:25/01/2023
                Path:C:\Windows\SysWOW64\cmd.exe
                Wow64 process (32bit):
                Commandline:cmd.exe /c set /A "0x22^75"
                Imagebase:
                File size:232960 bytes
                MD5 hash:F3BDBE3BB6F734E357235F4D5898582D
                Has elevated privileges:
                Has administrator privileges:
                Programmed in:C, C++ or other language

                Target ID:86
                Start time:09:53:49
                Start date:25/01/2023
                Path:C:\Windows\System32\Conhost.exe
                Wow64 process (32bit):
                Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                Imagebase:
                File size:625664 bytes
                MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                Has elevated privileges:
                Has administrator privileges:
                Programmed in:C, C++ or other language

                Target ID:87
                Start time:09:53:50
                Start date:25/01/2023
                Path:C:\Windows\SysWOW64\cmd.exe
                Wow64 process (32bit):
                Commandline:cmd.exe /c set /A "0x6B^75"
                Imagebase:
                File size:232960 bytes
                MD5 hash:F3BDBE3BB6F734E357235F4D5898582D
                Has elevated privileges:
                Has administrator privileges:
                Programmed in:C, C++ or other language

                Target ID:88
                Start time:09:53:50
                Start date:25/01/2023
                Path:C:\Windows\System32\Conhost.exe
                Wow64 process (32bit):
                Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                Imagebase:
                File size:625664 bytes
                MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                Has elevated privileges:
                Has administrator privileges:
                Programmed in:C, C++ or other language

                Target ID:89
                Start time:09:53:50
                Start date:25/01/2023
                Path:C:\Windows\SysWOW64\cmd.exe
                Wow64 process (32bit):
                Commandline:cmd.exe /c set /A "0x7B^75"
                Imagebase:
                File size:232960 bytes
                MD5 hash:F3BDBE3BB6F734E357235F4D5898582D
                Has elevated privileges:
                Has administrator privileges:
                Programmed in:C, C++ or other language

                Target ID:90
                Start time:09:53:50
                Start date:25/01/2023
                Path:C:\Windows\System32\Conhost.exe
                Wow64 process (32bit):
                Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                Imagebase:
                File size:625664 bytes
                MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                Has elevated privileges:
                Has administrator privileges:
                Programmed in:C, C++ or other language

                Target ID:91
                Start time:09:53:50
                Start date:25/01/2023
                Path:C:\Windows\SysWOW64\cmd.exe
                Wow64 process (32bit):
                Commandline:cmd.exe /c set /A "0x67^75"
                Imagebase:
                File size:232960 bytes
                MD5 hash:F3BDBE3BB6F734E357235F4D5898582D
                Has elevated privileges:
                Has administrator privileges:
                Programmed in:C, C++ or other language

                Target ID:92
                Start time:09:53:50
                Start date:25/01/2023
                Path:C:\Windows\System32\Conhost.exe
                Wow64 process (32bit):
                Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                Imagebase:
                File size:625664 bytes
                MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                Has elevated privileges:
                Has administrator privileges:
                Programmed in:C, C++ or other language

                Target ID:93
                Start time:09:53:50
                Start date:25/01/2023
                Path:C:\Windows\SysWOW64\cmd.exe
                Wow64 process (32bit):
                Commandline:cmd.exe /c set /A "0x6B^75"
                Imagebase:
                File size:232960 bytes
                MD5 hash:F3BDBE3BB6F734E357235F4D5898582D
                Has elevated privileges:
                Has administrator privileges:
                Programmed in:C, C++ or other language

                Target ID:94
                Start time:09:53:50
                Start date:25/01/2023
                Path:C:\Windows\System32\Conhost.exe
                Wow64 process (32bit):
                Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                Imagebase:
                File size:625664 bytes
                MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                Has elevated privileges:
                Has administrator privileges:
                Programmed in:C, C++ or other language

                Target ID:95
                Start time:09:53:50
                Start date:25/01/2023
                Path:C:\Windows\SysWOW64\cmd.exe
                Wow64 process (32bit):
                Commandline:cmd.exe /c set /A "0x3B^75"
                Imagebase:
                File size:232960 bytes
                MD5 hash:F3BDBE3BB6F734E357235F4D5898582D
                Has elevated privileges:
                Has administrator privileges:
                Programmed in:C, C++ or other language

                Target ID:96
                Start time:09:53:50
                Start date:25/01/2023
                Path:C:\Windows\System32\Conhost.exe
                Wow64 process (32bit):
                Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                Imagebase:
                File size:625664 bytes
                MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                Has elevated privileges:
                Has administrator privileges:
                Programmed in:C, C++ or other language

                Target ID:97
                Start time:09:53:50
                Start date:25/01/2023
                Path:C:\Windows\SysWOW64\cmd.exe
                Wow64 process (32bit):
                Commandline:cmd.exe /c set /A "0x6B^75"
                Imagebase:
                File size:232960 bytes
                MD5 hash:F3BDBE3BB6F734E357235F4D5898582D
                Has elevated privileges:
                Has administrator privileges:
                Programmed in:C, C++ or other language

                Target ID:98
                Start time:09:53:50
                Start date:25/01/2023
                Path:C:\Windows\System32\Conhost.exe
                Wow64 process (32bit):
                Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                Imagebase:
                File size:625664 bytes
                MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                Has elevated privileges:
                Has administrator privileges:
                Programmed in:C, C++ or other language

                Target ID:99
                Start time:09:53:50
                Start date:25/01/2023
                Path:C:\Windows\SysWOW64\cmd.exe
                Wow64 process (32bit):
                Commandline:cmd.exe /c set /A "0x7B^75"
                Imagebase:
                File size:232960 bytes
                MD5 hash:F3BDBE3BB6F734E357235F4D5898582D
                Has elevated privileges:
                Has administrator privileges:
                Programmed in:C, C++ or other language

                Target ID:100
                Start time:09:53:50
                Start date:25/01/2023
                Path:C:\Windows\System32\Conhost.exe
                Wow64 process (32bit):
                Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                Imagebase:
                File size:625664 bytes
                MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                Has elevated privileges:
                Has administrator privileges:
                Programmed in:C, C++ or other language

                Target ID:101
                Start time:09:53:50
                Start date:25/01/2023
                Path:C:\Windows\SysWOW64\cmd.exe
                Wow64 process (32bit):
                Commandline:cmd.exe /c set /A "0x67^75"
                Imagebase:
                File size:232960 bytes
                MD5 hash:F3BDBE3BB6F734E357235F4D5898582D
                Has elevated privileges:
                Has administrator privileges:
                Programmed in:C, C++ or other language

                Target ID:102
                Start time:09:53:50
                Start date:25/01/2023
                Path:C:\Windows\System32\Conhost.exe
                Wow64 process (32bit):
                Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                Imagebase:
                File size:625664 bytes
                MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                Has elevated privileges:
                Has administrator privileges:
                Programmed in:C, C++ or other language

                Target ID:103
                Start time:09:53:51
                Start date:25/01/2023
                Path:C:\Windows\SysWOW64\cmd.exe
                Wow64 process (32bit):
                Commandline:cmd.exe /c set /A "0x6B^75"
                Imagebase:
                File size:232960 bytes
                MD5 hash:F3BDBE3BB6F734E357235F4D5898582D
                Has elevated privileges:
                Has administrator privileges:
                Programmed in:C, C++ or other language

                Target ID:104
                Start time:09:53:51
                Start date:25/01/2023
                Path:C:\Windows\System32\Conhost.exe
                Wow64 process (32bit):
                Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                Imagebase:
                File size:625664 bytes
                MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                Has elevated privileges:
                Has administrator privileges:
                Programmed in:C, C++ or other language

                Target ID:105
                Start time:09:53:51
                Start date:25/01/2023
                Path:C:\Windows\SysWOW64\cmd.exe
                Wow64 process (32bit):
                Commandline:cmd.exe /c set /A "0x22^75"
                Imagebase:
                File size:232960 bytes
                MD5 hash:F3BDBE3BB6F734E357235F4D5898582D
                Has elevated privileges:
                Has administrator privileges:
                Programmed in:C, C++ or other language

                Target ID:106
                Start time:09:53:51
                Start date:25/01/2023
                Path:C:\Windows\System32\Conhost.exe
                Wow64 process (32bit):
                Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                Imagebase:
                File size:625664 bytes
                MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                Has elevated privileges:
                Has administrator privileges:
                Programmed in:C, C++ or other language

                Target ID:107
                Start time:09:53:51
                Start date:25/01/2023
                Path:C:\Windows\SysWOW64\cmd.exe
                Wow64 process (32bit):
                Commandline:cmd.exe /c set /A "0x6B^75"
                Imagebase:
                File size:232960 bytes
                MD5 hash:F3BDBE3BB6F734E357235F4D5898582D
                Has elevated privileges:
                Has administrator privileges:
                Programmed in:C, C++ or other language

                Target ID:108
                Start time:09:53:51
                Start date:25/01/2023
                Path:C:\Windows\System32\Conhost.exe
                Wow64 process (32bit):
                Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                Imagebase:
                File size:625664 bytes
                MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                Has elevated privileges:
                Has administrator privileges:
                Programmed in:C, C++ or other language

                Target ID:109
                Start time:09:53:51
                Start date:25/01/2023
                Path:C:\Windows\SysWOW64\cmd.exe
                Wow64 process (32bit):
                Commandline:cmd.exe /c set /A "0x7F^75"
                Imagebase:
                File size:232960 bytes
                MD5 hash:F3BDBE3BB6F734E357235F4D5898582D
                Has elevated privileges:
                Has administrator privileges:
                Programmed in:C, C++ or other language

                Target ID:110
                Start time:09:53:51
                Start date:25/01/2023
                Path:C:\Windows\System32\Conhost.exe
                Wow64 process (32bit):
                Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                Imagebase:
                File size:625664 bytes
                MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                Has elevated privileges:
                Has administrator privileges:
                Programmed in:C, C++ or other language

                Target ID:111
                Start time:09:53:51
                Start date:25/01/2023
                Path:C:\Windows\SysWOW64\cmd.exe
                Wow64 process (32bit):
                Commandline:cmd.exe /c set /A "0x67^75"
                Imagebase:
                File size:232960 bytes
                MD5 hash:F3BDBE3BB6F734E357235F4D5898582D
                Has elevated privileges:
                Has administrator privileges:
                Programmed in:C, C++ or other language

                Target ID:112
                Start time:09:53:51
                Start date:25/01/2023
                Path:C:\Windows\System32\Conhost.exe
                Wow64 process (32bit):
                Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                Imagebase:
                File size:625664 bytes
                MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                Has elevated privileges:
                Has administrator privileges:
                Programmed in:C, C++ or other language

                Target ID:113
                Start time:09:53:51
                Start date:25/01/2023
                Path:C:\Windows\SysWOW64\cmd.exe
                Wow64 process (32bit):
                Commandline:cmd.exe /c set /A "0x6B^75"
                Imagebase:
                File size:232960 bytes
                MD5 hash:F3BDBE3BB6F734E357235F4D5898582D
                Has elevated privileges:
                Has administrator privileges:
                Programmed in:C, C++ or other language

                Target ID:114
                Start time:09:53:51
                Start date:25/01/2023
                Path:C:\Windows\System32\Conhost.exe
                Wow64 process (32bit):
                Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                Imagebase:
                File size:625664 bytes
                MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                Has elevated privileges:
                Has administrator privileges:
                Programmed in:C, C++ or other language

                Target ID:115
                Start time:09:53:51
                Start date:25/01/2023
                Path:C:\Windows\SysWOW64\cmd.exe
                Wow64 process (32bit):
                Commandline:cmd.exe /c set /A "0x22^75"
                Imagebase:
                File size:232960 bytes
                MD5 hash:F3BDBE3BB6F734E357235F4D5898582D
                Has elevated privileges:
                Has administrator privileges:
                Programmed in:C, C++ or other language

                Target ID:116
                Start time:09:53:51
                Start date:25/01/2023
                Path:C:\Windows\System32\Conhost.exe
                Wow64 process (32bit):
                Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                Imagebase:
                File size:625664 bytes
                MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                Has elevated privileges:
                Has administrator privileges:
                Programmed in:C, C++ or other language

                Target ID:117
                Start time:09:53:52
                Start date:25/01/2023
                Path:C:\Windows\SysWOW64\cmd.exe
                Wow64 process (32bit):
                Commandline:cmd.exe /c set /A "0x6B^75"
                Imagebase:
                File size:232960 bytes
                MD5 hash:F3BDBE3BB6F734E357235F4D5898582D
                Has elevated privileges:
                Has administrator privileges:
                Programmed in:C, C++ or other language

                Target ID:118
                Start time:09:53:52
                Start date:25/01/2023
                Path:C:\Windows\System32\Conhost.exe
                Wow64 process (32bit):
                Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                Imagebase:
                File size:625664 bytes
                MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                Has elevated privileges:
                Has administrator privileges:
                Programmed in:C, C++ or other language

                Target ID:119
                Start time:09:53:52
                Start date:25/01/2023
                Path:C:\Windows\SysWOW64\cmd.exe
                Wow64 process (32bit):
                Commandline:cmd.exe /c set /A "0x7B^75"
                Imagebase:
                File size:232960 bytes
                MD5 hash:F3BDBE3BB6F734E357235F4D5898582D
                Has elevated privileges:
                Has administrator privileges:
                Programmed in:C, C++ or other language

                Target ID:120
                Start time:09:53:52
                Start date:25/01/2023
                Path:C:\Windows\System32\Conhost.exe
                Wow64 process (32bit):
                Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                Imagebase:
                File size:625664 bytes
                MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                Has elevated privileges:
                Has administrator privileges:
                Programmed in:C, C++ or other language

                Target ID:121
                Start time:09:53:52
                Start date:25/01/2023
                Path:C:\Windows\SysWOW64\cmd.exe
                Wow64 process (32bit):
                Commandline:cmd.exe /c set /A "0x33^75"
                Imagebase:
                File size:232960 bytes
                MD5 hash:F3BDBE3BB6F734E357235F4D5898582D
                Has elevated privileges:
                Has administrator privileges:
                Programmed in:C, C++ or other language

                Target ID:122
                Start time:09:53:52
                Start date:25/01/2023
                Path:C:\Windows\System32\Conhost.exe
                Wow64 process (32bit):
                Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                Imagebase:
                File size:625664 bytes
                MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                Has elevated privileges:
                Has administrator privileges:
                Programmed in:C, C++ or other language

                Target ID:123
                Start time:09:53:52
                Start date:25/01/2023
                Path:C:\Windows\SysWOW64\cmd.exe
                Wow64 process (32bit):
                Commandline:cmd.exe /c set /A "0x73^75"
                Imagebase:
                File size:232960 bytes
                MD5 hash:F3BDBE3BB6F734E357235F4D5898582D
                Has elevated privileges:
                Has administrator privileges:
                Programmed in:C, C++ or other language

                Target ID:124
                Start time:09:53:52
                Start date:25/01/2023
                Path:C:\Windows\System32\Conhost.exe
                Wow64 process (32bit):
                Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                Imagebase:
                File size:625664 bytes
                MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                Has elevated privileges:
                Has administrator privileges:
                Programmed in:C, C++ or other language

                Target ID:125
                Start time:09:53:52
                Start date:25/01/2023
                Path:C:\Windows\SysWOW64\cmd.exe
                Wow64 process (32bit):
                Commandline:cmd.exe /c set /A "0x7B^75"
                Imagebase:
                File size:232960 bytes
                MD5 hash:F3BDBE3BB6F734E357235F4D5898582D
                Has elevated privileges:
                Has administrator privileges:
                Programmed in:C, C++ or other language

                Target ID:126
                Start time:09:53:52
                Start date:25/01/2023
                Path:C:\Windows\System32\Conhost.exe
                Wow64 process (32bit):
                Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                Imagebase:
                File size:625664 bytes
                MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                Has elevated privileges:
                Has administrator privileges:
                Programmed in:C, C++ or other language

                Target ID:127
                Start time:09:53:52
                Start date:25/01/2023
                Path:C:\Windows\SysWOW64\cmd.exe
                Wow64 process (32bit):
                Commandline:cmd.exe /c set /A "0x67^75"
                Imagebase:
                File size:232960 bytes
                MD5 hash:F3BDBE3BB6F734E357235F4D5898582D
                Has elevated privileges:
                Has administrator privileges:
                Programmed in:C, C++ or other language

                Target ID:128
                Start time:09:53:52
                Start date:25/01/2023
                Path:C:\Windows\System32\Conhost.exe
                Wow64 process (32bit):
                Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                Imagebase:
                File size:625664 bytes
                MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                Has elevated privileges:
                Has administrator privileges:
                Programmed in:C, C++ or other language

                No disassembly