Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Section loaded: mscoree.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Section loaded: vcruntime140_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Section loaded: cryptsp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Section loaded: rsaenh.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Section loaded: cryptbase.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Section loaded: amsi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Section loaded: msasn1.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Section loaded: gpapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Section loaded: windowscodecs.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Section loaded: propsys.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Section loaded: edputil.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Section loaded: urlmon.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Section loaded: iertutil.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Section loaded: srvcli.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Section loaded: netutils.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Section loaded: windows.staterepositoryps.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Section loaded: appresolver.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Section loaded: bcp47langs.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Section loaded: slc.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Section loaded: sppc.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Section loaded: onecorecommonproxystub.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Section loaded: onecoreuapcommonproxystub.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: atl.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: mscoree.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: vcruntime140_clr0400.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: cryptsp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: rsaenh.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: cryptbase.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: amsi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: msasn1.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: msisip.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: wshext.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: appxsip.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: opcservices.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: gpapi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: secur32.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: urlmon.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: iertutil.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: srvcli.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: netutils.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: propsys.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: wininet.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: microsoft.management.infrastructure.native.unmanaged.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: mi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: miutils.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: wmidcom.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: dpapi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: wbemcomn.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Section loaded: mscoree.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Section loaded: vcruntime140_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Section loaded: cryptsp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Section loaded: rsaenh.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Section loaded: cryptbase.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Section loaded: wbemcomn.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Section loaded: amsi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Section loaded: vaultcli.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Section loaded: iphlpapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Section loaded: dnsapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Section loaded: dhcpcsvc6.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Section loaded: dhcpcsvc.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Section loaded: winnsi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Section loaded: mswsock.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Section loaded: rasadhlp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Section loaded: fwpuclnt.dll |
Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: fastprox.dll |
Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: ncobjapi.dll |
Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: wbemcomn.dll |
Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: wbemcomn.dll |
Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: mpclient.dll |
Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: msasn1.dll |
Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: wmitomi.dll |
Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: mi.dll |
Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: miutils.dll |
Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: gpapi.dll |
Jump to behavior |
Source: 0.2.DHL_734825514200.exe.4bf0000.10.raw.unpack, XG.cs |
High entropy of concatenated method names: 'S1d', 'RgtTUJcyZL', 'n1Q', 'M1r', 'Y1a', 'U1m', 'k2an4M', 'gt', 'kU', 'rK' |
Source: 0.2.DHL_734825514200.exe.2537450.5.raw.unpack, XG.cs |
High entropy of concatenated method names: 'S1d', 'RgtTUJcyZL', 'n1Q', 'M1r', 'Y1a', 'U1m', 'k2an4M', 'gt', 'kU', 'rK' |
Source: 0.2.DHL_734825514200.exe.25267d8.0.raw.unpack, XG.cs |
High entropy of concatenated method names: 'S1d', 'RgtTUJcyZL', 'n1Q', 'M1r', 'Y1a', 'U1m', 'k2an4M', 'gt', 'kU', 'rK' |
Source: 0.2.DHL_734825514200.exe.38b5930.8.raw.unpack, VmAl511krMmOe59lJa.cs |
High entropy of concatenated method names: 'HiJNDh1xrD', 'bJ6NP3PEaJ', 'LwuNj51d3R', 's5nNxIqZCk', 'cY9NBtPK1o', 'hnoNH8ZEOh', 'CxNNdw7JE9', 'iJGN4Etig9', 'RGoN2c8b99', 'WV0Nm0bFR4' |
Source: 0.2.DHL_734825514200.exe.38b5930.8.raw.unpack, CL82XRElcwGt3tZn7E.cs |
High entropy of concatenated method names: 'agGC16g75e', 'H7LC7AI3d4', 'YdlC0qga2d', 'Du4C6bvCn7', 'nFTCkltJgi', 'obqCZnD8gZ', 'zT3CWateP1', 'x6uCS5Zl67', 'fkiCTl4lSb', 'XrXCXaWGN2' |
Source: 0.2.DHL_734825514200.exe.38b5930.8.raw.unpack, C8ISlE20nTA5qbKi9A.cs |
High entropy of concatenated method names: 'J9t80xKojx', 'Vfs86R5l0v', 'nJF83hmBA3', 'QoK8kIp9Ye', 'G1Z8DNbyB0', 'C328Z4HgD1', 'Next', 'Next', 'Next', 'NextBytes' |
Source: 0.2.DHL_734825514200.exe.38b5930.8.raw.unpack, XAIdZDHc59O0vuFCMj.cs |
High entropy of concatenated method names: 'kQGV4UFXv9', 'aVGVmdgoiu', 'OvA8LPZbxP', 'lgy8KveS3W', 'f0HVXcmuXJ', 'ECpVJLBY2T', 'Rq8VEVgFTY', 'wr5VD6Pt5K', 'aOfVPv9MER', 'Wf8VjBFqU4' |
Source: 0.2.DHL_734825514200.exe.38b5930.8.raw.unpack, Qu7b5nNrTP1uSaPXch.cs |
High entropy of concatenated method names: 'Dispose', 'XhKK2JQJTK', 'xbj56ECf90', 'WWpIIPVbUX', 'upoKmucl6E', 'QoaKzpc1sr', 'ProcessDialogKey', 'xlv5L8ISlE', 'FnT5KA5qbK', 'x9A55Yftc6' |
Source: 0.2.DHL_734825514200.exe.38b5930.8.raw.unpack, lsl4W0Kw4PE5pKdYH5w.cs |
High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'x9SrDGd9n5', 'CBIrP2RLaN', 'ijnrjy6I7R', 'O81rxcNqUQ', 'BZXrBoC5Tb', 'cvLrHm4YhG', 'QQJrdgIZkI' |
Source: 0.2.DHL_734825514200.exe.38b5930.8.raw.unpack, qHi6VCj2P8LO8DiGKI.cs |
High entropy of concatenated method names: 'ToString', 'VGdpX9aIXr', 'isYp6vQXuL', 'xIcp3NG3fP', 'jF9pkfFl71', 'mQvpZOu9jH', 'tKdpaSijoj', 'PwGpWYWPYi', 'gCvpSOBQIV', 'tDjpRP4owy' |
Source: 0.2.DHL_734825514200.exe.38b5930.8.raw.unpack, cxC4bbYZl6eBcEU3wM.cs |
High entropy of concatenated method names: 'hkHKlmAl51', 'IrMKcmOe59', 'MXmK9TYyZX', 'lo5KfCwpah', 'jgKKOgjPs3', 'ClbKplcfM7', 'MNXrefurEfVoBvWW6w', 'sG09DCPC1UnKRSnh7K', 'JlLKKKWUfM', 'wDPKwWItbw' |
Source: 0.2.DHL_734825514200.exe.38b5930.8.raw.unpack, Pq9WxS7XmTYyZX9o5C.cs |
High entropy of concatenated method names: 'N8fUGGVM1f', 'xNLUv0MARA', 'HeWU1FnTKd', 'spaU7XYW3A', 'h1BUOeOCHk', 'KMNUpMkew5', 'Q0wUVtmJbh', 'LSGU8JAmId', 'rjnUQeNhmA', 'qXGUrsTUuR' |
Source: 0.2.DHL_734825514200.exe.38b5930.8.raw.unpack, tk7biFWC8WYhqrikIn.cs |
High entropy of concatenated method names: 'xxLltCtU9l', 'keXlUFit1e', 'opqlybyq6B', 'epaymFJsHa', 'Yeayzwe4Xa', 'Ys0lLFW5kw', 'bM9lKLVv4A', 'mQGl5UdRFf', 'A5nlwMwM27', 'lJwlY6xKWW' |
Source: 0.2.DHL_734825514200.exe.38b5930.8.raw.unpack, pxEb9pRFSjgO2kaKSC.cs |
High entropy of concatenated method names: 'rhElgMWxrB', 'zWXlodWHU7', 'J8BlFIvkkh', 'b9LlGNNMIl', 'ETZlI2aMRh', 'FH8lvlRPgr', 'DL4lemj2jQ', 'JbGl1HXhZa', 'F55l7CPs7b', 'RMOlAk4vEK' |
Source: 0.2.DHL_734825514200.exe.38b5930.8.raw.unpack, dftc6qmqxeZpIIMTcL.cs |
High entropy of concatenated method names: 'buaQKUyOZa', 'bxTQw2R7X7', 'vhoQYsBMWB', 'WPbQtLF77Y', 'QVkQNsaxsd', 'z5BQMSP7EA', 'wJBQylfUSM', 'YxA8ds5G7B', 'RK5846VKLT', 'YOe82Qgb8a' |
Source: 0.2.DHL_734825514200.exe.38b5930.8.raw.unpack, JsLk0mKLTcq2wr9pFtV.cs |
High entropy of concatenated method names: 'BsmQgE6RnQ', 't2dQorAeHy', 'fIbQFZQ3er', 'BEyQG4enES', 'skcQIy68Dp', 'XqOQvePPtC', 'AAxQevugxr', 'jPmQ1sd4S0', 'zVYQ7ArJGo', 'NJMQAN00xC' |
Source: 0.2.DHL_734825514200.exe.38b5930.8.raw.unpack, tKdTyLUYMYGxOE1SeH.cs |
High entropy of concatenated method names: 'EditValue', 'GetEditStyle', 'xEX52dvPqC', 'muZ5mdRjON', 'J7O5z21Skx', 'P8AwL83RhF', 'ySBwKo5agZ', 'h3rw5m1Og0', 'on2wwv8u1i', 'BGm2K84Y4vHjEEGCuMt' |
Source: 0.2.DHL_734825514200.exe.38b5930.8.raw.unpack, g3KUlacgmmUpTu6lIf.cs |
High entropy of concatenated method names: 'CgZwbaGbTo', 'htIwt0GyKK', 'DYfwNe45cD', 'qFTwUfExnX', 'urvwM55A0L', 'LAawyMRhLY', 'g9Gwlo1XoB', 'Sk1wckgky9', 'GPewsW7cyq', 'J7Zw9cPDSW' |
Source: 0.2.DHL_734825514200.exe.38b5930.8.raw.unpack, dpahhjAkOBgSplgKgj.cs |
High entropy of concatenated method names: 'jC3MI2i9pI', 'qofMev0H2H', 'XCmU3IGHEV', 'p91UkwgGb2', 'PYQUZRg6pi', 's4wUajKZPb', 'LOMUW5Pvlt', 'fhYUSUHYq9', 'kAHURi1Lyn', 'HwWUT0qtyl' |
Source: 0.2.DHL_734825514200.exe.38b5930.8.raw.unpack, Rs3vlb0lcfM77gAQMt.cs |
High entropy of concatenated method names: 'ztAybpaYwS', 'oLlyNVK6uO', 'e2FyMHOkUy', 'PnKylOdE3L', 'Y4Uyc6chd6', 'pmHMBWHcaM', 'sKXMHpemf8', 'FMHMdrlefc', 'yZoM4fUGg6', 'NJDM2AZIBG' |
Source: 0.2.DHL_734825514200.exe.38b5930.8.raw.unpack, gLCAp05FFGn89jcjAE.cs |
High entropy of concatenated method names: 'KgQFKf3PS', 'rpCGn0MYt', 'HhCv0xuf8', 'gtEexAchr', 'bUi7OL1et', 'PDhAKq0x3', 'JLmxdlgkyBqHyBN6vO', 'vU1PthwsVEMRwL0nQV', 'jPDMi4SN472BHnwIaN', 'TDg8vbEUe' |
Source: 0.2.DHL_734825514200.exe.38b5930.8.raw.unpack, poucl64EDoapc1sril.cs |
High entropy of concatenated method names: 'bmP8tjuSb4', 'fde8N6KvMK', 'pLQ8Ur8URr', 'fkb8MbM0Qt', 'FHM8yfxh5i', 'HiO8l5d8L1', 'Ukd8c3p3Rg', 'Ula8s6kEo1', 'Amq89kxluM', 'cKL8fkNj6U' |
Source: 0.2.DHL_734825514200.exe.58b0000.11.raw.unpack, VmAl511krMmOe59lJa.cs |
High entropy of concatenated method names: 'HiJNDh1xrD', 'bJ6NP3PEaJ', 'LwuNj51d3R', 's5nNxIqZCk', 'cY9NBtPK1o', 'hnoNH8ZEOh', 'CxNNdw7JE9', 'iJGN4Etig9', 'RGoN2c8b99', 'WV0Nm0bFR4' |
Source: 0.2.DHL_734825514200.exe.58b0000.11.raw.unpack, CL82XRElcwGt3tZn7E.cs |
High entropy of concatenated method names: 'agGC16g75e', 'H7LC7AI3d4', 'YdlC0qga2d', 'Du4C6bvCn7', 'nFTCkltJgi', 'obqCZnD8gZ', 'zT3CWateP1', 'x6uCS5Zl67', 'fkiCTl4lSb', 'XrXCXaWGN2' |
Source: 0.2.DHL_734825514200.exe.58b0000.11.raw.unpack, C8ISlE20nTA5qbKi9A.cs |
High entropy of concatenated method names: 'J9t80xKojx', 'Vfs86R5l0v', 'nJF83hmBA3', 'QoK8kIp9Ye', 'G1Z8DNbyB0', 'C328Z4HgD1', 'Next', 'Next', 'Next', 'NextBytes' |
Source: 0.2.DHL_734825514200.exe.58b0000.11.raw.unpack, XAIdZDHc59O0vuFCMj.cs |
High entropy of concatenated method names: 'kQGV4UFXv9', 'aVGVmdgoiu', 'OvA8LPZbxP', 'lgy8KveS3W', 'f0HVXcmuXJ', 'ECpVJLBY2T', 'Rq8VEVgFTY', 'wr5VD6Pt5K', 'aOfVPv9MER', 'Wf8VjBFqU4' |
Source: 0.2.DHL_734825514200.exe.58b0000.11.raw.unpack, Qu7b5nNrTP1uSaPXch.cs |
High entropy of concatenated method names: 'Dispose', 'XhKK2JQJTK', 'xbj56ECf90', 'WWpIIPVbUX', 'upoKmucl6E', 'QoaKzpc1sr', 'ProcessDialogKey', 'xlv5L8ISlE', 'FnT5KA5qbK', 'x9A55Yftc6' |
Source: 0.2.DHL_734825514200.exe.58b0000.11.raw.unpack, lsl4W0Kw4PE5pKdYH5w.cs |
High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'x9SrDGd9n5', 'CBIrP2RLaN', 'ijnrjy6I7R', 'O81rxcNqUQ', 'BZXrBoC5Tb', 'cvLrHm4YhG', 'QQJrdgIZkI' |
Source: 0.2.DHL_734825514200.exe.58b0000.11.raw.unpack, qHi6VCj2P8LO8DiGKI.cs |
High entropy of concatenated method names: 'ToString', 'VGdpX9aIXr', 'isYp6vQXuL', 'xIcp3NG3fP', 'jF9pkfFl71', 'mQvpZOu9jH', 'tKdpaSijoj', 'PwGpWYWPYi', 'gCvpSOBQIV', 'tDjpRP4owy' |
Source: 0.2.DHL_734825514200.exe.58b0000.11.raw.unpack, cxC4bbYZl6eBcEU3wM.cs |
High entropy of concatenated method names: 'hkHKlmAl51', 'IrMKcmOe59', 'MXmK9TYyZX', 'lo5KfCwpah', 'jgKKOgjPs3', 'ClbKplcfM7', 'MNXrefurEfVoBvWW6w', 'sG09DCPC1UnKRSnh7K', 'JlLKKKWUfM', 'wDPKwWItbw' |
Source: 0.2.DHL_734825514200.exe.58b0000.11.raw.unpack, Pq9WxS7XmTYyZX9o5C.cs |
High entropy of concatenated method names: 'N8fUGGVM1f', 'xNLUv0MARA', 'HeWU1FnTKd', 'spaU7XYW3A', 'h1BUOeOCHk', 'KMNUpMkew5', 'Q0wUVtmJbh', 'LSGU8JAmId', 'rjnUQeNhmA', 'qXGUrsTUuR' |
Source: 0.2.DHL_734825514200.exe.58b0000.11.raw.unpack, tk7biFWC8WYhqrikIn.cs |
High entropy of concatenated method names: 'xxLltCtU9l', 'keXlUFit1e', 'opqlybyq6B', 'epaymFJsHa', 'Yeayzwe4Xa', 'Ys0lLFW5kw', 'bM9lKLVv4A', 'mQGl5UdRFf', 'A5nlwMwM27', 'lJwlY6xKWW' |
Source: 0.2.DHL_734825514200.exe.58b0000.11.raw.unpack, pxEb9pRFSjgO2kaKSC.cs |
High entropy of concatenated method names: 'rhElgMWxrB', 'zWXlodWHU7', 'J8BlFIvkkh', 'b9LlGNNMIl', 'ETZlI2aMRh', 'FH8lvlRPgr', 'DL4lemj2jQ', 'JbGl1HXhZa', 'F55l7CPs7b', 'RMOlAk4vEK' |
Source: 0.2.DHL_734825514200.exe.58b0000.11.raw.unpack, dftc6qmqxeZpIIMTcL.cs |
High entropy of concatenated method names: 'buaQKUyOZa', 'bxTQw2R7X7', 'vhoQYsBMWB', 'WPbQtLF77Y', 'QVkQNsaxsd', 'z5BQMSP7EA', 'wJBQylfUSM', 'YxA8ds5G7B', 'RK5846VKLT', 'YOe82Qgb8a' |
Source: 0.2.DHL_734825514200.exe.58b0000.11.raw.unpack, JsLk0mKLTcq2wr9pFtV.cs |
High entropy of concatenated method names: 'BsmQgE6RnQ', 't2dQorAeHy', 'fIbQFZQ3er', 'BEyQG4enES', 'skcQIy68Dp', 'XqOQvePPtC', 'AAxQevugxr', 'jPmQ1sd4S0', 'zVYQ7ArJGo', 'NJMQAN00xC' |
Source: 0.2.DHL_734825514200.exe.58b0000.11.raw.unpack, tKdTyLUYMYGxOE1SeH.cs |
High entropy of concatenated method names: 'EditValue', 'GetEditStyle', 'xEX52dvPqC', 'muZ5mdRjON', 'J7O5z21Skx', 'P8AwL83RhF', 'ySBwKo5agZ', 'h3rw5m1Og0', 'on2wwv8u1i', 'BGm2K84Y4vHjEEGCuMt' |
Source: 0.2.DHL_734825514200.exe.58b0000.11.raw.unpack, g3KUlacgmmUpTu6lIf.cs |
High entropy of concatenated method names: 'CgZwbaGbTo', 'htIwt0GyKK', 'DYfwNe45cD', 'qFTwUfExnX', 'urvwM55A0L', 'LAawyMRhLY', 'g9Gwlo1XoB', 'Sk1wckgky9', 'GPewsW7cyq', 'J7Zw9cPDSW' |
Source: 0.2.DHL_734825514200.exe.58b0000.11.raw.unpack, dpahhjAkOBgSplgKgj.cs |
High entropy of concatenated method names: 'jC3MI2i9pI', 'qofMev0H2H', 'XCmU3IGHEV', 'p91UkwgGb2', 'PYQUZRg6pi', 's4wUajKZPb', 'LOMUW5Pvlt', 'fhYUSUHYq9', 'kAHURi1Lyn', 'HwWUT0qtyl' |
Source: 0.2.DHL_734825514200.exe.58b0000.11.raw.unpack, Rs3vlb0lcfM77gAQMt.cs |
High entropy of concatenated method names: 'ztAybpaYwS', 'oLlyNVK6uO', 'e2FyMHOkUy', 'PnKylOdE3L', 'Y4Uyc6chd6', 'pmHMBWHcaM', 'sKXMHpemf8', 'FMHMdrlefc', 'yZoM4fUGg6', 'NJDM2AZIBG' |
Source: 0.2.DHL_734825514200.exe.58b0000.11.raw.unpack, gLCAp05FFGn89jcjAE.cs |
High entropy of concatenated method names: 'KgQFKf3PS', 'rpCGn0MYt', 'HhCv0xuf8', 'gtEexAchr', 'bUi7OL1et', 'PDhAKq0x3', 'JLmxdlgkyBqHyBN6vO', 'vU1PthwsVEMRwL0nQV', 'jPDMi4SN472BHnwIaN', 'TDg8vbEUe' |
Source: 0.2.DHL_734825514200.exe.58b0000.11.raw.unpack, poucl64EDoapc1sril.cs |
High entropy of concatenated method names: 'bmP8tjuSb4', 'fde8N6KvMK', 'pLQ8Ur8URr', 'fkb8MbM0Qt', 'FHM8yfxh5i', 'HiO8l5d8L1', 'Ukd8c3p3Rg', 'Ula8s6kEo1', 'Amq89kxluM', 'cKL8fkNj6U' |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe TID: 5544 |
Thread sleep time: -922337203685477s >= -30000s |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe TID: 7264 |
Thread sleep time: -3689348814741908s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe TID: 7284 |
Thread sleep time: -21213755684765971s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe TID: 7284 |
Thread sleep time: -100000s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe TID: 7292 |
Thread sleep count: 1958 > 30 |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe TID: 7284 |
Thread sleep time: -99875s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe TID: 7292 |
Thread sleep count: 5616 > 30 |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe TID: 7284 |
Thread sleep time: -99739s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe TID: 7284 |
Thread sleep time: -99609s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe TID: 7284 |
Thread sleep time: -99500s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe TID: 7284 |
Thread sleep time: -99390s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe TID: 7284 |
Thread sleep time: -99281s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe TID: 7284 |
Thread sleep time: -99170s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe TID: 7284 |
Thread sleep time: -99057s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe TID: 7284 |
Thread sleep time: -98953s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe TID: 7284 |
Thread sleep time: -98843s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe TID: 7284 |
Thread sleep time: -98734s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe TID: 7284 |
Thread sleep time: -98625s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe TID: 7284 |
Thread sleep time: -98515s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe TID: 7284 |
Thread sleep time: -98405s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe TID: 7284 |
Thread sleep time: -98296s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe TID: 7284 |
Thread sleep time: -98187s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe TID: 7284 |
Thread sleep time: -98078s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe TID: 7284 |
Thread sleep time: -97968s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe TID: 7284 |
Thread sleep time: -97859s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe TID: 7284 |
Thread sleep time: -97750s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe TID: 7284 |
Thread sleep time: -97640s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe TID: 7284 |
Thread sleep time: -97531s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe TID: 7284 |
Thread sleep time: -97422s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe TID: 7284 |
Thread sleep time: -97312s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe TID: 7284 |
Thread sleep time: -97203s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe TID: 7284 |
Thread sleep time: -97093s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe TID: 7284 |
Thread sleep time: -96984s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe TID: 7284 |
Thread sleep time: -96875s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe TID: 7284 |
Thread sleep time: -96765s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe TID: 7284 |
Thread sleep time: -96656s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe TID: 7284 |
Thread sleep time: -96546s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe TID: 7284 |
Thread sleep time: -96437s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe TID: 7284 |
Thread sleep time: -96328s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe TID: 7284 |
Thread sleep time: -96219s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe TID: 7284 |
Thread sleep time: -96109s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe TID: 7284 |
Thread sleep time: -96000s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe TID: 7284 |
Thread sleep time: -922337203685477s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Thread delayed: delay time: 922337203685477 |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Thread delayed: delay time: 922337203685477 |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Thread delayed: delay time: 922337203685477 |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Thread delayed: delay time: 100000 |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Thread delayed: delay time: 99875 |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Thread delayed: delay time: 99739 |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Thread delayed: delay time: 99609 |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Thread delayed: delay time: 99500 |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Thread delayed: delay time: 99390 |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Thread delayed: delay time: 99281 |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Thread delayed: delay time: 99170 |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Thread delayed: delay time: 99057 |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Thread delayed: delay time: 98953 |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Thread delayed: delay time: 98843 |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Thread delayed: delay time: 98734 |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Thread delayed: delay time: 98625 |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Thread delayed: delay time: 98515 |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Thread delayed: delay time: 98405 |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Thread delayed: delay time: 98296 |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Thread delayed: delay time: 98187 |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Thread delayed: delay time: 98078 |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Thread delayed: delay time: 97968 |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Thread delayed: delay time: 97859 |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Thread delayed: delay time: 97750 |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Thread delayed: delay time: 97640 |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Thread delayed: delay time: 97531 |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Thread delayed: delay time: 97422 |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Thread delayed: delay time: 97312 |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Thread delayed: delay time: 97203 |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Thread delayed: delay time: 97093 |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Thread delayed: delay time: 96984 |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Thread delayed: delay time: 96875 |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Thread delayed: delay time: 96765 |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Thread delayed: delay time: 96656 |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Thread delayed: delay time: 96546 |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Thread delayed: delay time: 96437 |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Thread delayed: delay time: 96328 |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Thread delayed: delay time: 96219 |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Thread delayed: delay time: 96109 |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Thread delayed: delay time: 96000 |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Thread delayed: delay time: 922337203685477 |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Queries volume information: C:\Users\user\Desktop\DHL_734825514200.exe VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\ VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-GroupPolicy-ClientTools-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-AppManagement-AppV-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\Microsoft.Management.Infrastructure.Native\v4.0_1.0.0.0__31bf3856ad364e35\Microsoft.Management.Infrastructure.Native.dll VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\AppvClient\Microsoft.AppV.AppVClientPowerShell.dll VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1865.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-WOW64-Package~31bf3856ad364e35~amd64~en-GB~10.0.19041.1.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\BitLocker\Microsoft.BitLocker.Structures.dll VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management\v4.0_3.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Management.dll VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Queries volume information: C:\Users\user\Desktop\DHL_734825514200.exe VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Security\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Security.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\DHL_734825514200.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation |
Jump to behavior |