Source: 0.2.2AylrL13DwoqmCT.exe.407e958.3.unpack, type: UNPACKEDPE | Matched rule: INDICATOR_SUSPICIOUS_EXE_VaultSchemaGUID author = ditekSHen, description = Detects executables referencing Windows vault credential objects. Observed in infostealers |
Source: 0.2.2AylrL13DwoqmCT.exe.407e958.3.unpack, type: UNPACKEDPE | Matched rule: MALWARE_Win_AgentTeslaV2 author = ditekSHen, description = AgenetTesla Type 2 Keylogger payload |
Source: 0.2.2AylrL13DwoqmCT.exe.8dc0000.6.unpack, type: UNPACKEDPE | Matched rule: INDICATOR_SUSPICIOUS_EXE_VaultSchemaGUID author = ditekSHen, description = Detects executables referencing Windows vault credential objects. Observed in infostealers |
Source: 0.2.2AylrL13DwoqmCT.exe.8dc0000.6.unpack, type: UNPACKEDPE | Matched rule: MALWARE_Win_AgentTeslaV2 author = ditekSHen, description = AgenetTesla Type 2 Keylogger payload |
Source: 0.2.2AylrL13DwoqmCT.exe.4042b38.4.unpack, type: UNPACKEDPE | Matched rule: INDICATOR_SUSPICIOUS_EXE_VaultSchemaGUID author = ditekSHen, description = Detects executables referencing Windows vault credential objects. Observed in infostealers |
Source: 0.2.2AylrL13DwoqmCT.exe.4042b38.4.unpack, type: UNPACKEDPE | Matched rule: MALWARE_Win_AgentTeslaV2 author = ditekSHen, description = AgenetTesla Type 2 Keylogger payload |
Source: 0.2.2AylrL13DwoqmCT.exe.8dc0000.6.raw.unpack, type: UNPACKEDPE | Matched rule: INDICATOR_SUSPICIOUS_EXE_VaultSchemaGUID author = ditekSHen, description = Detects executables referencing Windows vault credential objects. Observed in infostealers |
Source: 0.2.2AylrL13DwoqmCT.exe.8dc0000.6.raw.unpack, type: UNPACKEDPE | Matched rule: MALWARE_Win_AgentTeslaV2 author = ditekSHen, description = AgenetTesla Type 2 Keylogger payload |
Source: 0.2.2AylrL13DwoqmCT.exe.407e958.3.raw.unpack, type: UNPACKEDPE | Matched rule: INDICATOR_SUSPICIOUS_EXE_VaultSchemaGUID author = ditekSHen, description = Detects executables referencing Windows vault credential objects. Observed in infostealers |
Source: 0.2.2AylrL13DwoqmCT.exe.407e958.3.raw.unpack, type: UNPACKEDPE | Matched rule: MALWARE_Win_AgentTeslaV2 author = ditekSHen, description = AgenetTesla Type 2 Keylogger payload |
Source: 0.2.2AylrL13DwoqmCT.exe.4042b38.4.raw.unpack, type: UNPACKEDPE | Matched rule: INDICATOR_SUSPICIOUS_EXE_VaultSchemaGUID author = ditekSHen, description = Detects executables referencing Windows vault credential objects. Observed in infostealers |
Source: 0.2.2AylrL13DwoqmCT.exe.4042b38.4.raw.unpack, type: UNPACKEDPE | Matched rule: MALWARE_Win_AgentTeslaV2 author = ditekSHen, description = AgenetTesla Type 2 Keylogger payload |
Source: 0.2.2AylrL13DwoqmCT.exe.2d563cc.2.raw.unpack, type: UNPACKEDPE | Matched rule: INDICATOR_SUSPICIOUS_EXE_VaultSchemaGUID author = ditekSHen, description = Detects executables referencing Windows vault credential objects. Observed in infostealers |
Source: 0.2.2AylrL13DwoqmCT.exe.2d67474.0.raw.unpack, type: UNPACKEDPE | Matched rule: INDICATOR_SUSPICIOUS_EXE_VaultSchemaGUID author = ditekSHen, description = Detects executables referencing Windows vault credential objects. Observed in infostealers |
Source: 0.2.2AylrL13DwoqmCT.exe.2d23110.1.raw.unpack, type: UNPACKEDPE | Matched rule: INDICATOR_SUSPICIOUS_EXE_VaultSchemaGUID author = ditekSHen, description = Detects executables referencing Windows vault credential objects. Observed in infostealers |
Source: 00000000.00000002.3674919885.0000000008DC0000.00000004.08000000.00040000.00000000.sdmp, type: MEMORY | Matched rule: INDICATOR_SUSPICIOUS_EXE_VaultSchemaGUID author = ditekSHen, description = Detects executables referencing Windows vault credential objects. Observed in infostealers |
Source: 00000000.00000002.3674919885.0000000008DC0000.00000004.08000000.00040000.00000000.sdmp, type: MEMORY | Matched rule: MALWARE_Win_AgentTeslaV2 author = ditekSHen, description = AgenetTesla Type 2 Keylogger payload |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Section loaded: windowscodecs.dll | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Section loaded: edputil.dll | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Section loaded: windows.staterepositoryps.dll | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Section loaded: appresolver.dll | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Section loaded: bcp47langs.dll | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Section loaded: slc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Section loaded: sppc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Section loaded: onecorecommonproxystub.dll | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Section loaded: onecoreuapcommonproxystub.dll | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Section loaded: wbemcomn.dll | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Section loaded: rasapi32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Section loaded: rasman.dll | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Section loaded: rtutils.dll | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Section loaded: dhcpcsvc6.dll | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Section loaded: dhcpcsvc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Section loaded: dnsapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Section loaded: winnsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Section loaded: rasadhlp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Section loaded: fwpuclnt.dll | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Section loaded: vaultcli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: atl.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: msisip.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wshext.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: appxsip.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: opcservices.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: secur32.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: microsoft.management.infrastructure.native.unmanaged.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: mi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: miutils.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wmidcom.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: dpapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wbemcomn.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\schtasks.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\schtasks.exe | Section loaded: taskschd.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\schtasks.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\KrzbVJsCi.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\KrzbVJsCi.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\KrzbVJsCi.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\KrzbVJsCi.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\KrzbVJsCi.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\KrzbVJsCi.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\KrzbVJsCi.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\KrzbVJsCi.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\KrzbVJsCi.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\KrzbVJsCi.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\KrzbVJsCi.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\KrzbVJsCi.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\KrzbVJsCi.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\KrzbVJsCi.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\KrzbVJsCi.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\KrzbVJsCi.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\KrzbVJsCi.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\KrzbVJsCi.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\KrzbVJsCi.exe | Section loaded: windowscodecs.dll | Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: fastprox.dll | Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: ncobjapi.dll | Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: wbemcomn.dll | Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: mpclient.dll | Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: wmitomi.dll | Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: mi.dll | Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: miutils.dll | Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: 6.2.KrzbVJsCi.exe.2e57480.1.raw.unpack, XG.cs | High entropy of concatenated method names: 'S1d', 'RgtTUJcyZL', 'n1Q', 'M1r', 'Y1a', 'U1m', 'k2an4M', 'gt', 'kU', 'rK' |
Source: 6.2.KrzbVJsCi.exe.415c3a0.6.raw.unpack, cgiECCzxjFhWtfUWsx.cs | High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'aix0ZQqQ2A', 'RhN02G6g6O', 'qDa0EU0oFx', 'H9P0YynSRC', 'QgX0sthGiE', 'jsY0074L3y', 'UEj0PG3MXs' |
Source: 6.2.KrzbVJsCi.exe.415c3a0.6.raw.unpack, j32Z8eBlHNeoNY1wp3.cs | High entropy of concatenated method names: 'EditValue', 'GetEditStyle', 'bbDojKxar3', 'ykgownG2JI', 'htbozaXFR8', 'N5AUbbvNib', 'AbWU4DvxEC', 'BSFUoKl9lg', 'x1bUUfLKsf', 'xw31Xi4eI9fu5J8IU4k' |
Source: 6.2.KrzbVJsCi.exe.415c3a0.6.raw.unpack, KV2B7X8Z1o6fKyhy02.cs | High entropy of concatenated method names: 'pclUMS6Hxc', 'mb6UpM6AIi', 'LrgUaip1gi', 'eurUBA3fgn', 'kuwU9oxfHR', 'MiuUlk3Ksh', 'PLOUXlK5EN', 'endU8IF89O', 'dPyUgMMiwN', 'sutUOtQYkL' |
Source: 6.2.KrzbVJsCi.exe.415c3a0.6.raw.unpack, F23ZBO4bPTbFsYojED5.cs | High entropy of concatenated method names: 'fWH0tulCeC', 'DEx0RgtGW7', 'VBF0kWgeWm', 'zSb0NFI4V2', 'Vdr0vhRTPo', 'piD0FJ3Rtd', 'OS70doBdmG', 'SpL0SU3D7c', 'fBt0KryL3G', 'AHK0JYmelv' |
Source: 6.2.KrzbVJsCi.exe.415c3a0.6.raw.unpack, gkr2vS3VAweL2pqg1O.cs | High entropy of concatenated method names: 'wHcY6CyZmT', 'gTjYwcrOtr', 'qlIsb3jcdH', 'dQOs4gGUZM', 'HHsYfEXkto', 'FiKYhtAFa7', 'wDbY7pi2xD', 'jgfYWeD9ow', 'kwMYCyXvhk', 'alAYrgJNho' |
Source: 6.2.KrzbVJsCi.exe.415c3a0.6.raw.unpack, Qh2qfjj6p4RCYat27j.cs | High entropy of concatenated method names: 'YGZsekDPZA', 'ORNsmV0A18', 'ddgsLAPaT7', 'cLWsxkSkxf', 'nuUsWRWTDA', 'kZysckgtac', 'Next', 'Next', 'Next', 'NextBytes' |
Source: 6.2.KrzbVJsCi.exe.415c3a0.6.raw.unpack, oh3xttoD6pxO5MkmB2.cs | High entropy of concatenated method names: 'dcFkGmWhZ', 'gXJNL36ik', 'Ao8FCnAQh', 'ooMdcxpTc', 'clHKPfSl2', 'WGfJGWujO', 'Fnv76FVGwmMavFEkvM', 'AJWZ41qsgK6dhs1iEV', 'F2ZsshstA', 'X86PfATDy' |
Source: 6.2.KrzbVJsCi.exe.415c3a0.6.raw.unpack, KlaSVIS0ixltNPkyhS.cs | High entropy of concatenated method names: 'QqYaW3pw4U', 'tY8aCyKujs', 'o05araQY2y', 'tiIa1vogFB', 'bHRauYND21', 'eb0a3MN41V', 'U89aqMK6MC', 'F5qa6J2bXu', 'rDDajUgiRZ', 'ADCawFd3v7' |
Source: 6.2.KrzbVJsCi.exe.415c3a0.6.raw.unpack, zfQ0q26yIi94kDYsAg.cs | High entropy of concatenated method names: 'bALsp7gkUn', 'LO7saMg46q', 'zmrsB1R8F2', 'kc0s9ixIKc', 'dP2sl8wvx3', 'j7ssXJmfEv', 'Fsrs8gf2dK', 'Nmrsg0QkJa', 'ORysOTWdU5', 'tgJsyIIi9b' |
Source: 6.2.KrzbVJsCi.exe.415c3a0.6.raw.unpack, G6RyO84UyL1Dup5NFBb.cs | High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'K2PPWCxG6K', 'JptPCW0et8', 'Yu0PrTbL16', 'J9LP191Pw2', 'FuyPuMxR43', 'xO6P3qlD3P', 'XIvPqoZKjB' |
Source: 6.2.KrzbVJsCi.exe.415c3a0.6.raw.unpack, X37ECbJdXblq73DUeq.cs | High entropy of concatenated method names: 'r6m9vK9vZu', 'Bx09dwi8tu', 'SerBLTI0bW', 'WRDBxwZAxW', 'sUEBc8KR4f', 'NoLB5vFWYj', 'F2mBDfpmcN', 'FumBnXwuth', 'GRtBIrGdMC', 'H70BTIDbvN' |
Source: 6.2.KrzbVJsCi.exe.415c3a0.6.raw.unpack, PPIROl4oH3vaJoMkGQS.cs | High entropy of concatenated method names: 'TSZPtH9Xu9', 'MgGPRk4nsi', 'n5iPk7vjGi', 'x1kbSCM2COSvpojGgS5', 'Dse1ZXMCkXM7CVQQMOs', 'KPel2BMt3Wys35JyB8X', 'dfklv2MgK10X4qLRK3o', 'nvaLNUMw55NTfe91d3r', 'jQuZucM3SSx5ruUjJKA' |
Source: 6.2.KrzbVJsCi.exe.415c3a0.6.raw.unpack, GfKFgJa9v75DSJSlfo.cs | High entropy of concatenated method names: 'Dispose', 'UmH4jpPqrD', 'oflomwbDFp', 'PTwJJGsbmW', 'lkf4wQ0q2y', 'Mi94z4kDYs', 'ProcessDialogKey', 'vg7obh2qfj', 'Wp4o4RCYat', 'o7jooeAtBI' |
Source: 6.2.KrzbVJsCi.exe.415c3a0.6.raw.unpack, vDDDNp7TFjfAvOnxcL.cs | High entropy of concatenated method names: 'DHaZSSInQ7', 'NMyZKBsiEw', 'pFTZeEXGQa', 'ltmZmWWBOB', 'KVPZxCC0TW', 'SK2ZcFFWu1', 'kywZDFKbZS', 'ErBZn7Ix0o', 'kLGZTcLhoy', 'cSEZfJaYsv' |
Source: 6.2.KrzbVJsCi.exe.415c3a0.6.raw.unpack, W6g8h6e7tYR17jgKE1.cs | High entropy of concatenated method names: 'jU7lMx5MHe', 'nUllauXOxy', 'G5El9Y15Nt', 't2XlXeYwvj', 'Ybwl8k8MCw', 'iTI9uwMpNi', 'oTi93e4yJC', 'iHb9qjoi01', 'nZw96afgst', 'FKZ9jeADgU' |
Source: 6.2.KrzbVJsCi.exe.415c3a0.6.raw.unpack, qv9BRi1MoyBa0f8v1a.cs | High entropy of concatenated method names: 'ibvYOAWZaB', 'lFrYyLRjij', 'ToString', 'S2kYpribxJ', 'UGbYagAnhd', 'B4NYBVwDdZ', 'lr8Y9LEH7d', 'z0iYl26rI9', 'UeQYXmrqrR', 'BCBY8S8xS6' |
Source: 6.2.KrzbVJsCi.exe.415c3a0.6.raw.unpack, z641QkWfOUKw8fFaph.cs | High entropy of concatenated method names: 'kt32TOceRh', 'Src2hxgULA', 'eAh2WsCeEh', 'RTX2Cepcvi', 'kvY2m3Gno7', 'GkW2LhLe1L', 'wDP2xQn5xW', 'UKj2chMHSy', 'SxD25QSuPX', 'D7A2DgklPJ' |
Source: 6.2.KrzbVJsCi.exe.415c3a0.6.raw.unpack, tLAoC9IvMlWfvf9x8n.cs | High entropy of concatenated method names: 'emFXtn8Evh', 'RTHXRTDbqF', 'JODXkJo9N0', 'CxDXNy7oo5', 'miGXvogjD0', 'HwiXFvBfLO', 'NwuXdV1U8S', 'b4YXS8Mc7J', 'Sw9XK2Nc1q', 'dYXXJDKKjb' |
Source: 6.2.KrzbVJsCi.exe.415c3a0.6.raw.unpack, FAtBIfwcTLYyoirreW.cs | High entropy of concatenated method names: 'OkO04ikKPP', 'Ulx0U6WguU', 'i2P0VeJCuK', 'HOp0pYl8EB', 'Joc0apY2EV', 'cRh094yVoK', 'n410lnafFD', 'wROsqBZNnO', 'u1ts6HWK2q', 'kcEsj1B0wn' |
Source: 6.2.KrzbVJsCi.exe.415c3a0.6.raw.unpack, mfcsEMVoU8nCM8FYxr.cs | High entropy of concatenated method names: 'rf54XlaSVI', 'rix48ltNPk', 'j6j4OM3Wg1', 'fKM4ybj37E', 'VDU42eq66g', 'kh64E7tYR1', 'wH34XSA97wPWcWFAvp', 'wJlvqqSOPVkqeJ4fLi', 'khl44q9NqA', 'QIH4Usbjeb' |
Source: 6.2.KrzbVJsCi.exe.415c3a0.6.raw.unpack, fNMfXlK6jM3Wg1pKMb.cs | High entropy of concatenated method names: 'Q7UBNpBYbh', 'Ed8BFYvCgl', 'u5HBSCiZ5J', 'a6kBKoKhul', 'hNaB2wLUSb', 'y2kBEh7fIS', 'qGvBYycx6c', 'fv1Bs6JBr0', 'DtnB0TKCXs', 't0pBPI5Qpt' |
Source: 6.2.KrzbVJsCi.exe.5520000.9.raw.unpack, XG.cs | High entropy of concatenated method names: 'S1d', 'RgtTUJcyZL', 'n1Q', 'M1r', 'Y1a', 'U1m', 'k2an4M', 'gt', 'kU', 'rK' |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\KrzbVJsCi.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\KrzbVJsCi.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\KrzbVJsCi.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\KrzbVJsCi.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\KrzbVJsCi.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\KrzbVJsCi.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\KrzbVJsCi.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\KrzbVJsCi.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\KrzbVJsCi.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\KrzbVJsCi.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\KrzbVJsCi.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\KrzbVJsCi.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\KrzbVJsCi.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\KrzbVJsCi.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\KrzbVJsCi.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\KrzbVJsCi.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\KrzbVJsCi.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\KrzbVJsCi.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\KrzbVJsCi.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\KrzbVJsCi.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\KrzbVJsCi.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\KrzbVJsCi.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\KrzbVJsCi.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\KrzbVJsCi.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\KrzbVJsCi.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\KrzbVJsCi.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\KrzbVJsCi.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\KrzbVJsCi.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\KrzbVJsCi.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\KrzbVJsCi.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\KrzbVJsCi.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\KrzbVJsCi.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\KrzbVJsCi.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\KrzbVJsCi.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\KrzbVJsCi.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\KrzbVJsCi.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Thread delayed: delay time: 600000 | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Thread delayed: delay time: 599875 | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Thread delayed: delay time: 599754 | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Thread delayed: delay time: 599640 | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Thread delayed: delay time: 599531 | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Thread delayed: delay time: 599421 | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Thread delayed: delay time: 599312 | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Thread delayed: delay time: 599203 | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Thread delayed: delay time: 599093 | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Thread delayed: delay time: 598984 | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Thread delayed: delay time: 598875 | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Thread delayed: delay time: 598765 | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Thread delayed: delay time: 598656 | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Thread delayed: delay time: 598546 | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Thread delayed: delay time: 598424 | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Thread delayed: delay time: 598312 | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Thread delayed: delay time: 598202 | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Thread delayed: delay time: 598093 | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Thread delayed: delay time: 597984 | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Thread delayed: delay time: 597875 | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Thread delayed: delay time: 597764 | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Thread delayed: delay time: 597656 | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Thread delayed: delay time: 597546 | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Thread delayed: delay time: 597320 | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Thread delayed: delay time: 597202 | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Thread delayed: delay time: 597093 | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Thread delayed: delay time: 596984 | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Thread delayed: delay time: 596875 | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Thread delayed: delay time: 596765 | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Thread delayed: delay time: 596656 | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Thread delayed: delay time: 596546 | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Thread delayed: delay time: 596436 | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Thread delayed: delay time: 596327 | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Thread delayed: delay time: 596218 | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Thread delayed: delay time: 596109 | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Thread delayed: delay time: 595999 | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Thread delayed: delay time: 595890 | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Thread delayed: delay time: 595781 | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Thread delayed: delay time: 595671 | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Thread delayed: delay time: 595558 | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Thread delayed: delay time: 595453 | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Thread delayed: delay time: 595343 | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Thread delayed: delay time: 595234 | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Thread delayed: delay time: 595125 | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Thread delayed: delay time: 595015 | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Thread delayed: delay time: 594906 | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Thread delayed: delay time: 594796 | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Thread delayed: delay time: 594687 | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Thread delayed: delay time: 594578 | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Thread delayed: delay time: 594468 | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\KrzbVJsCi.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe TID: 6856 | Thread sleep time: -30437127721620741s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe TID: 6856 | Thread sleep time: -600000s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe TID: 6856 | Thread sleep time: -599875s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe TID: 6856 | Thread sleep time: -599754s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe TID: 6856 | Thread sleep time: -599640s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe TID: 6856 | Thread sleep time: -599531s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe TID: 6856 | Thread sleep time: -599421s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe TID: 6856 | Thread sleep time: -599312s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe TID: 6856 | Thread sleep time: -599203s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe TID: 6856 | Thread sleep time: -599093s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe TID: 6856 | Thread sleep time: -598984s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe TID: 6856 | Thread sleep time: -598875s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe TID: 6856 | Thread sleep time: -598765s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe TID: 6856 | Thread sleep time: -598656s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe TID: 6856 | Thread sleep time: -598546s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe TID: 6856 | Thread sleep time: -598424s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe TID: 6856 | Thread sleep time: -598312s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe TID: 6856 | Thread sleep time: -598202s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe TID: 6856 | Thread sleep time: -598093s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe TID: 6856 | Thread sleep time: -597984s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe TID: 6856 | Thread sleep time: -597875s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe TID: 6856 | Thread sleep time: -597764s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe TID: 6856 | Thread sleep time: -597656s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe TID: 6856 | Thread sleep time: -597546s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe TID: 6856 | Thread sleep time: -597320s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe TID: 6856 | Thread sleep time: -597202s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe TID: 6856 | Thread sleep time: -597093s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe TID: 6856 | Thread sleep time: -596984s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe TID: 6856 | Thread sleep time: -596875s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe TID: 6856 | Thread sleep time: -596765s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe TID: 6856 | Thread sleep time: -596656s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe TID: 6856 | Thread sleep time: -596546s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe TID: 6856 | Thread sleep time: -596436s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe TID: 6856 | Thread sleep time: -596327s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe TID: 6856 | Thread sleep time: -596218s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe TID: 6856 | Thread sleep time: -596109s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe TID: 6856 | Thread sleep time: -595999s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe TID: 6856 | Thread sleep time: -595890s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe TID: 6856 | Thread sleep time: -595781s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe TID: 6856 | Thread sleep time: -595671s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe TID: 6856 | Thread sleep time: -595558s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe TID: 6856 | Thread sleep time: -595453s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe TID: 6856 | Thread sleep time: -595343s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe TID: 6856 | Thread sleep time: -595234s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe TID: 6856 | Thread sleep time: -595125s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe TID: 6856 | Thread sleep time: -595015s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe TID: 6856 | Thread sleep time: -594906s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe TID: 6856 | Thread sleep time: -594796s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe TID: 6856 | Thread sleep time: -594687s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe TID: 6856 | Thread sleep time: -594578s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe TID: 6856 | Thread sleep time: -594468s >= -30000s | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe TID: 1000 | Thread sleep time: -3689348814741908s >= -30000s | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe TID: 3432 | Thread sleep time: -922337203685477s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\KrzbVJsCi.exe TID: 4544 | Thread sleep time: -922337203685477s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Thread delayed: delay time: 600000 | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Thread delayed: delay time: 599875 | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Thread delayed: delay time: 599754 | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Thread delayed: delay time: 599640 | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Thread delayed: delay time: 599531 | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Thread delayed: delay time: 599421 | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Thread delayed: delay time: 599312 | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Thread delayed: delay time: 599203 | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Thread delayed: delay time: 599093 | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Thread delayed: delay time: 598984 | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Thread delayed: delay time: 598875 | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Thread delayed: delay time: 598765 | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Thread delayed: delay time: 598656 | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Thread delayed: delay time: 598546 | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Thread delayed: delay time: 598424 | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Thread delayed: delay time: 598312 | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Thread delayed: delay time: 598202 | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Thread delayed: delay time: 598093 | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Thread delayed: delay time: 597984 | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Thread delayed: delay time: 597875 | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Thread delayed: delay time: 597764 | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Thread delayed: delay time: 597656 | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Thread delayed: delay time: 597546 | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Thread delayed: delay time: 597320 | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Thread delayed: delay time: 597202 | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Thread delayed: delay time: 597093 | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Thread delayed: delay time: 596984 | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Thread delayed: delay time: 596875 | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Thread delayed: delay time: 596765 | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Thread delayed: delay time: 596656 | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Thread delayed: delay time: 596546 | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Thread delayed: delay time: 596436 | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Thread delayed: delay time: 596327 | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Thread delayed: delay time: 596218 | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Thread delayed: delay time: 596109 | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Thread delayed: delay time: 595999 | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Thread delayed: delay time: 595890 | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Thread delayed: delay time: 595781 | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Thread delayed: delay time: 595671 | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Thread delayed: delay time: 595558 | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Thread delayed: delay time: 595453 | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Thread delayed: delay time: 595343 | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Thread delayed: delay time: 595234 | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Thread delayed: delay time: 595125 | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Thread delayed: delay time: 595015 | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Thread delayed: delay time: 594906 | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Thread delayed: delay time: 594796 | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Thread delayed: delay time: 594687 | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Thread delayed: delay time: 594578 | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Thread delayed: delay time: 594468 | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\KrzbVJsCi.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Queries volume information: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\2AylrL13DwoqmCT.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Security\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Security.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\ VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-GroupPolicy-ClientTools-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-AppManagement-AppV-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\Microsoft.Management.Infrastructure.Native\v4.0_1.0.0.0__31bf3856ad364e35\Microsoft.Management.Infrastructure.Native.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\AppvClient\Microsoft.AppV.AppVClientPowerShell.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1865.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-WOW64-Package~31bf3856ad364e35~amd64~en-GB~10.0.19041.1.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\BitLocker\Microsoft.BitLocker.Structures.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management\v4.0_3.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Management.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\KrzbVJsCi.exe | Queries volume information: C:\Users\user\AppData\Roaming\KrzbVJsCi.exe VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\KrzbVJsCi.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\KrzbVJsCi.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\KrzbVJsCi.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\KrzbVJsCi.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation | Jump to behavior |