Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Section loaded: windowscodecs.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Section loaded: wbemcomn.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Section loaded: vaultcli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Section loaded: dnsapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Section loaded: dhcpcsvc6.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Section loaded: dhcpcsvc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Section loaded: winnsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Section loaded: rasadhlp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Section loaded: fwpuclnt.dll | Jump to behavior |
Source: 1.2.SHIPPING DOC.exe.60a0000.7.raw.unpack, GKfjiIuHtil7qtynYQ.cs | High entropy of concatenated method names: 'USEP6CJvDp', 'fLyPSw0Odi', 'g3UPEGjULU', 'G9pPcuMhDZ', 'jpxP89pYi6', 'hSyPZVL9mb', 'kjtP5Xd7Cx', 'IniHrne6PU', 'BTTHJeiKKE', 'E9ZHC8elbP' |
Source: 1.2.SHIPPING DOC.exe.60a0000.7.raw.unpack, LQtP5syIaTgvMBcXxt.cs | High entropy of concatenated method names: 'ToString', 'tXydbuKFnl', 'g7sdjTBpsq', 'kqodkKPQIW', 'mj6dKEr3MD', 'L8WdWj9ZlN', 'oRHdimD89Z', 'M13dhnluAJ', 'I2DdUTviHc', 'zIbdA92wZa' |
Source: 1.2.SHIPPING DOC.exe.60a0000.7.raw.unpack, LNfkdJ1F0jiCp795oc.cs | High entropy of concatenated method names: 'iXFROeeJa5', 'T12ResZe39', 'RlfRxAgBN6', 'TVCRjuaFLx', 'ycJRKtI2LZ', 'unPRWF4ytp', 'znyRhdVptF', 'gpfRUHPVFM', 'dBrRGaO0Wm', 'OeHRbsnXxQ' |
Source: 1.2.SHIPPING DOC.exe.60a0000.7.raw.unpack, bydEhqz6QADfbfEnlJ.cs | High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'uOBPRUpSXt', 'CdVPvpTrax', 'dRIPd1FL6M', 'fT1P4v8W5h', 'QvtPHJV3Q0', 'QjPPPCc0tW', 'K7aPNnZiFB' |
Source: 1.2.SHIPPING DOC.exe.60a0000.7.raw.unpack, suOfnC7BrQp7je2mxQ.cs | High entropy of concatenated method names: 'gjBvGuuVSD', 'mEdvw2EaeJ', 'O8tv75oUIk', 'IHavBi80Ue', 'xsivjTwgQv', 'yH6vkIgs7N', 'Q9DvK1hkfS', 'mTBvWM1oqJ', 'iGXvin2GdZ', 'CGHvhJVXoX' |
Source: 1.2.SHIPPING DOC.exe.60a0000.7.raw.unpack, CReg2gfqxm9UgsNpFV.cs | High entropy of concatenated method names: 'doj4JGP2Is', 'AaQ4uQvtDA', 'VtTHacarVa', 'BFJH615njL', 'WFu4bcBXXC', 'JDs4whCAP6', 'iy441F8WtK', 'joO47x6uLx', 'cDC4BSOsh8', 'rnr4yf4n26' |
Source: 1.2.SHIPPING DOC.exe.60a0000.7.raw.unpack, cP0ZAVEaVGCcLG4ZcV.cs | High entropy of concatenated method names: 'DCb6YEMNn1', 'VrV6qjtqpx', 'zy26MUy3Ua', 'yOM6nku5RI', 'uGD6vrOQtm', 'ok16docMpZ', 'AgcctojZtkbjSTjdFr', 'RamjPa5YjVe9Y5XQRH', 'nWG66scqNP', 'Q3J6STA7F8' |
Source: 1.2.SHIPPING DOC.exe.60a0000.7.raw.unpack, YVWt3oKxm4mmSrrdWp.cs | High entropy of concatenated method names: 'ecc53RWyKh', 'Cbh5V4myaK', 'gYs5IH7Caq', 'wLs5D7F4SY', 'QNJ5myI3t7', 'iFo52N4JuB', 'QuI5eJVJOe', 'cvW5o4nMYn', 'aEEytZAZl0LbNJGDv1v', 'PScgfbALyUQTe6k0WZ9' |
Source: 1.2.SHIPPING DOC.exe.60a0000.7.raw.unpack, hgxNb8JhgwL7S767rW.cs | High entropy of concatenated method names: 'uRWHcJxWZu', 'MNpH8Yregr', 'adnHtvHw63', 'rI7HZ1WLmh', 'YVgH5iBt5k', 'DmlHYamYed', 'AbJHqcaFHE', 'SmyHXanl0w', 'zfRHMI2C9X', 'dcbHnWnA9o' |
Source: 1.2.SHIPPING DOC.exe.60a0000.7.raw.unpack, DL8PZIey2Uy3UagOMk.cs | High entropy of concatenated method names: 'j0AtDMa5nr', 'KBqtmZZP4T', 'kaQtOB4ahh', 'BJ2teAmptd', 'c7Itv4GBPR', 'z3JtdEwVnP', 'GIpt44VvFU', 'vFotHA6vnF', 'l3ttPcicpJ', 'ugNtNdm7E8' |
Source: 1.2.SHIPPING DOC.exe.60a0000.7.raw.unpack, deejC06anDeniGPsCo9.cs | High entropy of concatenated method names: 'oBMPVtWU8N', 'zR3Pg3waxU', 'VPsPIpRJRV', 'i77PDmOq1E', 'vLvP0bncpV', 'S0cPmKdcVm', 'NQYP2QoEbq', 'dp8POG2Cum', 'bIBPejpT5V', 'TnFPovhRL9' |
Source: 1.2.SHIPPING DOC.exe.60a0000.7.raw.unpack, QqyL2AC9kbkvyVoG46.cs | High entropy of concatenated method names: 'YFjHxotlG2', 'rLrHjSv30T', 'ipGHkfVvoR', 'WYrHKMT9pD', 'DRIH7tFvTc', 'UBhHWIqcYm', 'Next', 'Next', 'Next', 'NextBytes' |
Source: 1.2.SHIPPING DOC.exe.60a0000.7.raw.unpack, OEMNn1OrrVjtqpxfs0.cs | High entropy of concatenated method names: 'tso87V8CF4', 'esk8BokL2c', 'VrJ8yOZbcI', 'pRC8TPxVY8', 'NnA8stUoeH', 'ICi8ftuBZn', 'EWW8r6QG5D', 'lj98Jo7YrY', 'Jjc8C9YyQi', 'rTj8u5gBDh' |
Source: 1.2.SHIPPING DOC.exe.60a0000.7.raw.unpack, JAEHVZpOLNuB6f9cdN.cs | High entropy of concatenated method names: 'spuIA1M5g', 'Q3nDE0CAw', 'LKXm8Uugr', 'PoS2XYLop', 'qQUeCYV2H', 'P2Dof0eDP', 'M167Pk8Bh8ICUK8XR1', 'xF9FcTylsugKumfXyf', 'sbrHGI8wx', 'A0dNf4CsO' |
Source: 1.2.SHIPPING DOC.exe.60a0000.7.raw.unpack, zdmNlA6SLcRJtZwB1Cl.cs | High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'RuGN7IU4Cw', 'oHgNBMiWgk', 'bJZNyIFddF', 'YR2NT57Dl7', 'nLkNsaXerG', 'jq7NffRxKn', 'wqONraJJL8' |
Source: 1.2.SHIPPING DOC.exe.60a0000.7.raw.unpack, DePoAHAYb2BjY7tG6U.cs | High entropy of concatenated method names: 'kpgYVigSHS', 'djKYgRrVpi', 'dNgYI84hGy', 'DfLYDpVBBg', 'pBDY0SA3N2', 'Fp9YmsApHM', 'zK2Y2ZOSSv', 'JjPYOWqEnl', 'twkYefIL6g', 'Jk7YoaFJpJ' |
Source: 1.2.SHIPPING DOC.exe.60a0000.7.raw.unpack, Y5RI06ovnXHdiFGDrO.cs | High entropy of concatenated method names: 'TAhZ0IQVpX', 'W9OZ2LsRfA', 'hYQtkh05XM', 'sd2tKDFQkK', 'akAtW7juUb', 'YcxtiJL0mL', 'k1Uth1n1Pr', 'IRLtUCvZxq', 'CiCtAxNpWZ', 'NSttGgflTa' |
Source: 1.2.SHIPPING DOC.exe.60a0000.7.raw.unpack, hx522Aq0eW2kUhCv5G.cs | High entropy of concatenated method names: 'VY5SLYPpsb', 'B3XSc0a1gJ', 'sSJS8WNJtV', 'vHLStjj4Xy', 'VtQSZggpMR', 'c8VS5GHbyO', 'Mj1SYLPmKi', 'UQ5SqQH8oV', 'LtnSXfkoZt', 'hZ9SMJuZ6L' |
Source: 1.2.SHIPPING DOC.exe.60a0000.7.raw.unpack, mwQMCLhqNK2tMo69ZO.cs | High entropy of concatenated method names: 'kJAYc76LSS', 'sJ2YtI3xfd', 'j7vY5WGCnv', 'EU85uMavWx', 'huq5z7GId2', 'HmvYaKSDiQ', 'CiOY6LbvhX', 'YIrYp5OCvj', 'rMEYSkFmet', 'wFLYEt1ecV' |
Source: 1.2.SHIPPING DOC.exe.60a0000.7.raw.unpack, OMqLGv8DtSqKrN8qLP.cs | High entropy of concatenated method names: 'Dispose', 'Ffp6COt5VS', 'd6npjDbcnR', 'VAfEE1nZDi', 'Ftg6uxNb8h', 'ywL6z7S767', 'ProcessDialogKey', 'VW7paqyL2A', 'ukbp6kvyVo', 'N46ppxKfji' |
Source: 1.2.SHIPPING DOC.exe.60a0000.7.raw.unpack, vtmRk1xocMpZ7lVNsT.cs | High entropy of concatenated method names: 'NmE5LRLOha', 'Dw258GapOs', 'KGL5ZQUuuF', 'Ir75YmhKYm', 'VgB5qrHmn1', 'H0xZswnvmW', 'pkmZfrlr4B', 'm05ZrTl1E7', 'M59ZJgsxdq', 'mqcZCDxius' |
Source: 1.2.SHIPPING DOC.exe.3f2f0b8.2.raw.unpack, GKfjiIuHtil7qtynYQ.cs | High entropy of concatenated method names: 'USEP6CJvDp', 'fLyPSw0Odi', 'g3UPEGjULU', 'G9pPcuMhDZ', 'jpxP89pYi6', 'hSyPZVL9mb', 'kjtP5Xd7Cx', 'IniHrne6PU', 'BTTHJeiKKE', 'E9ZHC8elbP' |
Source: 1.2.SHIPPING DOC.exe.3f2f0b8.2.raw.unpack, LQtP5syIaTgvMBcXxt.cs | High entropy of concatenated method names: 'ToString', 'tXydbuKFnl', 'g7sdjTBpsq', 'kqodkKPQIW', 'mj6dKEr3MD', 'L8WdWj9ZlN', 'oRHdimD89Z', 'M13dhnluAJ', 'I2DdUTviHc', 'zIbdA92wZa' |
Source: 1.2.SHIPPING DOC.exe.3f2f0b8.2.raw.unpack, LNfkdJ1F0jiCp795oc.cs | High entropy of concatenated method names: 'iXFROeeJa5', 'T12ResZe39', 'RlfRxAgBN6', 'TVCRjuaFLx', 'ycJRKtI2LZ', 'unPRWF4ytp', 'znyRhdVptF', 'gpfRUHPVFM', 'dBrRGaO0Wm', 'OeHRbsnXxQ' |
Source: 1.2.SHIPPING DOC.exe.3f2f0b8.2.raw.unpack, bydEhqz6QADfbfEnlJ.cs | High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'uOBPRUpSXt', 'CdVPvpTrax', 'dRIPd1FL6M', 'fT1P4v8W5h', 'QvtPHJV3Q0', 'QjPPPCc0tW', 'K7aPNnZiFB' |
Source: 1.2.SHIPPING DOC.exe.3f2f0b8.2.raw.unpack, suOfnC7BrQp7je2mxQ.cs | High entropy of concatenated method names: 'gjBvGuuVSD', 'mEdvw2EaeJ', 'O8tv75oUIk', 'IHavBi80Ue', 'xsivjTwgQv', 'yH6vkIgs7N', 'Q9DvK1hkfS', 'mTBvWM1oqJ', 'iGXvin2GdZ', 'CGHvhJVXoX' |
Source: 1.2.SHIPPING DOC.exe.3f2f0b8.2.raw.unpack, CReg2gfqxm9UgsNpFV.cs | High entropy of concatenated method names: 'doj4JGP2Is', 'AaQ4uQvtDA', 'VtTHacarVa', 'BFJH615njL', 'WFu4bcBXXC', 'JDs4whCAP6', 'iy441F8WtK', 'joO47x6uLx', 'cDC4BSOsh8', 'rnr4yf4n26' |
Source: 1.2.SHIPPING DOC.exe.3f2f0b8.2.raw.unpack, cP0ZAVEaVGCcLG4ZcV.cs | High entropy of concatenated method names: 'DCb6YEMNn1', 'VrV6qjtqpx', 'zy26MUy3Ua', 'yOM6nku5RI', 'uGD6vrOQtm', 'ok16docMpZ', 'AgcctojZtkbjSTjdFr', 'RamjPa5YjVe9Y5XQRH', 'nWG66scqNP', 'Q3J6STA7F8' |
Source: 1.2.SHIPPING DOC.exe.3f2f0b8.2.raw.unpack, YVWt3oKxm4mmSrrdWp.cs | High entropy of concatenated method names: 'ecc53RWyKh', 'Cbh5V4myaK', 'gYs5IH7Caq', 'wLs5D7F4SY', 'QNJ5myI3t7', 'iFo52N4JuB', 'QuI5eJVJOe', 'cvW5o4nMYn', 'aEEytZAZl0LbNJGDv1v', 'PScgfbALyUQTe6k0WZ9' |
Source: 1.2.SHIPPING DOC.exe.3f2f0b8.2.raw.unpack, hgxNb8JhgwL7S767rW.cs | High entropy of concatenated method names: 'uRWHcJxWZu', 'MNpH8Yregr', 'adnHtvHw63', 'rI7HZ1WLmh', 'YVgH5iBt5k', 'DmlHYamYed', 'AbJHqcaFHE', 'SmyHXanl0w', 'zfRHMI2C9X', 'dcbHnWnA9o' |
Source: 1.2.SHIPPING DOC.exe.3f2f0b8.2.raw.unpack, DL8PZIey2Uy3UagOMk.cs | High entropy of concatenated method names: 'j0AtDMa5nr', 'KBqtmZZP4T', 'kaQtOB4ahh', 'BJ2teAmptd', 'c7Itv4GBPR', 'z3JtdEwVnP', 'GIpt44VvFU', 'vFotHA6vnF', 'l3ttPcicpJ', 'ugNtNdm7E8' |
Source: 1.2.SHIPPING DOC.exe.3f2f0b8.2.raw.unpack, deejC06anDeniGPsCo9.cs | High entropy of concatenated method names: 'oBMPVtWU8N', 'zR3Pg3waxU', 'VPsPIpRJRV', 'i77PDmOq1E', 'vLvP0bncpV', 'S0cPmKdcVm', 'NQYP2QoEbq', 'dp8POG2Cum', 'bIBPejpT5V', 'TnFPovhRL9' |
Source: 1.2.SHIPPING DOC.exe.3f2f0b8.2.raw.unpack, QqyL2AC9kbkvyVoG46.cs | High entropy of concatenated method names: 'YFjHxotlG2', 'rLrHjSv30T', 'ipGHkfVvoR', 'WYrHKMT9pD', 'DRIH7tFvTc', 'UBhHWIqcYm', 'Next', 'Next', 'Next', 'NextBytes' |
Source: 1.2.SHIPPING DOC.exe.3f2f0b8.2.raw.unpack, OEMNn1OrrVjtqpxfs0.cs | High entropy of concatenated method names: 'tso87V8CF4', 'esk8BokL2c', 'VrJ8yOZbcI', 'pRC8TPxVY8', 'NnA8stUoeH', 'ICi8ftuBZn', 'EWW8r6QG5D', 'lj98Jo7YrY', 'Jjc8C9YyQi', 'rTj8u5gBDh' |
Source: 1.2.SHIPPING DOC.exe.3f2f0b8.2.raw.unpack, JAEHVZpOLNuB6f9cdN.cs | High entropy of concatenated method names: 'spuIA1M5g', 'Q3nDE0CAw', 'LKXm8Uugr', 'PoS2XYLop', 'qQUeCYV2H', 'P2Dof0eDP', 'M167Pk8Bh8ICUK8XR1', 'xF9FcTylsugKumfXyf', 'sbrHGI8wx', 'A0dNf4CsO' |
Source: 1.2.SHIPPING DOC.exe.3f2f0b8.2.raw.unpack, zdmNlA6SLcRJtZwB1Cl.cs | High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'RuGN7IU4Cw', 'oHgNBMiWgk', 'bJZNyIFddF', 'YR2NT57Dl7', 'nLkNsaXerG', 'jq7NffRxKn', 'wqONraJJL8' |
Source: 1.2.SHIPPING DOC.exe.3f2f0b8.2.raw.unpack, DePoAHAYb2BjY7tG6U.cs | High entropy of concatenated method names: 'kpgYVigSHS', 'djKYgRrVpi', 'dNgYI84hGy', 'DfLYDpVBBg', 'pBDY0SA3N2', 'Fp9YmsApHM', 'zK2Y2ZOSSv', 'JjPYOWqEnl', 'twkYefIL6g', 'Jk7YoaFJpJ' |
Source: 1.2.SHIPPING DOC.exe.3f2f0b8.2.raw.unpack, Y5RI06ovnXHdiFGDrO.cs | High entropy of concatenated method names: 'TAhZ0IQVpX', 'W9OZ2LsRfA', 'hYQtkh05XM', 'sd2tKDFQkK', 'akAtW7juUb', 'YcxtiJL0mL', 'k1Uth1n1Pr', 'IRLtUCvZxq', 'CiCtAxNpWZ', 'NSttGgflTa' |
Source: 1.2.SHIPPING DOC.exe.3f2f0b8.2.raw.unpack, hx522Aq0eW2kUhCv5G.cs | High entropy of concatenated method names: 'VY5SLYPpsb', 'B3XSc0a1gJ', 'sSJS8WNJtV', 'vHLStjj4Xy', 'VtQSZggpMR', 'c8VS5GHbyO', 'Mj1SYLPmKi', 'UQ5SqQH8oV', 'LtnSXfkoZt', 'hZ9SMJuZ6L' |
Source: 1.2.SHIPPING DOC.exe.3f2f0b8.2.raw.unpack, mwQMCLhqNK2tMo69ZO.cs | High entropy of concatenated method names: 'kJAYc76LSS', 'sJ2YtI3xfd', 'j7vY5WGCnv', 'EU85uMavWx', 'huq5z7GId2', 'HmvYaKSDiQ', 'CiOY6LbvhX', 'YIrYp5OCvj', 'rMEYSkFmet', 'wFLYEt1ecV' |
Source: 1.2.SHIPPING DOC.exe.3f2f0b8.2.raw.unpack, OMqLGv8DtSqKrN8qLP.cs | High entropy of concatenated method names: 'Dispose', 'Ffp6COt5VS', 'd6npjDbcnR', 'VAfEE1nZDi', 'Ftg6uxNb8h', 'ywL6z7S767', 'ProcessDialogKey', 'VW7paqyL2A', 'ukbp6kvyVo', 'N46ppxKfji' |
Source: 1.2.SHIPPING DOC.exe.3f2f0b8.2.raw.unpack, vtmRk1xocMpZ7lVNsT.cs | High entropy of concatenated method names: 'NmE5LRLOha', 'Dw258GapOs', 'KGL5ZQUuuF', 'Ir75YmhKYm', 'VgB5qrHmn1', 'H0xZswnvmW', 'pkmZfrlr4B', 'm05ZrTl1E7', 'M59ZJgsxdq', 'mqcZCDxius' |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe TID: 7720 | Thread sleep time: -922337203685477s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe TID: 7868 | Thread sleep time: -10145709240540247s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe TID: 7868 | Thread sleep time: -100000s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe TID: 7876 | Thread sleep count: 3591 > 30 | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe TID: 7868 | Thread sleep time: -99890s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe TID: 7876 | Thread sleep count: 883 > 30 | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe TID: 7868 | Thread sleep time: -99781s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe TID: 7868 | Thread sleep time: -99671s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe TID: 7868 | Thread sleep time: -99562s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe TID: 7868 | Thread sleep time: -99453s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe TID: 7868 | Thread sleep time: -99343s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe TID: 7868 | Thread sleep time: -99234s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe TID: 7868 | Thread sleep time: -99125s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe TID: 7868 | Thread sleep time: -99015s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe TID: 7868 | Thread sleep time: -98906s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe TID: 7868 | Thread sleep time: -98797s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe TID: 7868 | Thread sleep time: -98687s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe TID: 7868 | Thread sleep time: -98578s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe TID: 7868 | Thread sleep time: -98468s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe TID: 7868 | Thread sleep time: -98359s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe TID: 7868 | Thread sleep time: -98250s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe TID: 7868 | Thread sleep time: -98140s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe TID: 7868 | Thread sleep time: -98031s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe TID: 7868 | Thread sleep time: -97921s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe TID: 7868 | Thread sleep time: -97812s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe TID: 7868 | Thread sleep time: -97702s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\SHIPPING DOC.exe TID: 7868 | Thread sleep time: -922337203685477s >= -30000s | Jump to behavior |