Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Code function: 1_2_022883B0 | 1_2_022883B0 |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Code function: 1_2_022886D8 | 1_2_022886D8 |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Code function: 1_2_02287330 | 1_2_02287330 |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Code function: 1_2_02288451 | 1_2_02288451 |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Code function: 1_2_02287326 | 1_2_02287326 |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Code function: 1_2_0228736A | 1_2_0228736A |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Code function: 1_2_0228780B | 1_2_0228780B |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Code function: 1_2_067B5BE8 | 1_2_067B5BE8 |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Code function: 1_2_067B35E1 | 1_2_067B35E1 |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Code function: 1_2_067B15D0 | 1_2_067B15D0 |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Code function: 1_2_067B0040 | 1_2_067B0040 |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Code function: 1_2_067B1840 | 1_2_067B1840 |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Code function: 1_2_08780040 | 1_2_08780040 |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Code function: 1_2_08782220 | 1_2_08782220 |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Code function: 1_2_0878F858 | 1_2_0878F858 |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Code function: 1_2_0878F849 | 1_2_0878F849 |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Code function: 1_2_08787379 | 1_2_08787379 |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Code function: 1_2_08787388 | 1_2_08787388 |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Code function: 1_2_0878F420 | 1_2_0878F420 |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Code function: 3_2_015D9378 | 3_2_015D9378 |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Code function: 3_2_015D9B30 | 3_2_015D9B30 |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Code function: 3_2_015D4A98 | 3_2_015D4A98 |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Code function: 3_2_015DCDA8 | 3_2_015DCDA8 |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Code function: 3_2_015D3E80 | 3_2_015D3E80 |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Code function: 3_2_015D41C8 | 3_2_015D41C8 |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Code function: 3_2_066D56C8 | 3_2_066D56C8 |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Code function: 3_2_066D3F40 | 3_2_066D3F40 |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Code function: 3_2_066DDCF8 | 3_2_066DDCF8 |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Code function: 3_2_066DBCF0 | 3_2_066DBCF0 |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Code function: 3_2_066D2AF8 | 3_2_066D2AF8 |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Code function: 3_2_066D9AD0 | 3_2_066D9AD0 |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Code function: 3_2_066D8B80 | 3_2_066D8B80 |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Code function: 3_2_066D0040 | 3_2_066D0040 |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Code function: 3_2_066D4FE8 | 3_2_066D4FE8 |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Code function: 3_2_066D3248 | 3_2_066D3248 |
Source: Documents of shipment 3-2024.exe, 00000001.00000002.1245351308.00000000005FE000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: OriginalFilenameclr.dllT vs Documents of shipment 3-2024.exe |
Source: Documents of shipment 3-2024.exe, 00000001.00000002.1246801206.000000000251C000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: OriginalFilenameecf3ed1c-5c3b-4038-87a8-401c6c5075d4.exe4 vs Documents of shipment 3-2024.exe |
Source: Documents of shipment 3-2024.exe, 00000001.00000002.1249994593.0000000006AE0000.00000004.08000000.00040000.00000000.sdmp | Binary or memory string: OriginalFilenameTyrone.dll8 vs Documents of shipment 3-2024.exe |
Source: Documents of shipment 3-2024.exe, 00000001.00000002.1247364304.00000000036AE000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: OriginalFilenameecf3ed1c-5c3b-4038-87a8-401c6c5075d4.exe4 vs Documents of shipment 3-2024.exe |
Source: Documents of shipment 3-2024.exe, 00000001.00000002.1247364304.00000000036AE000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: OriginalFilenameTyrone.dll8 vs Documents of shipment 3-2024.exe |
Source: Documents of shipment 3-2024.exe, 00000003.00000002.2485139424.00000000012F9000.00000004.00000010.00020000.00000000.sdmp | Binary or memory string: OriginalFilenameUNKNOWN_FILET vs Documents of shipment 3-2024.exe |
Source: Documents of shipment 3-2024.exe, 00000003.00000002.2484776287.0000000000402000.00000040.00000400.00020000.00000000.sdmp | Binary or memory string: OriginalFilenameecf3ed1c-5c3b-4038-87a8-401c6c5075d4.exe4 vs Documents of shipment 3-2024.exe |
Source: Documents of shipment 3-2024.exe | Binary or memory string: OriginalFilenameZOtz.exe< vs Documents of shipment 3-2024.exe |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Section loaded: dwrite.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Section loaded: textshaping.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Section loaded: windowscodecs.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Section loaded: wbemcomn.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Section loaded: vaultcli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Section loaded: dnsapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Section loaded: dhcpcsvc6.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Section loaded: dhcpcsvc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Section loaded: winnsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Section loaded: rasadhlp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Section loaded: fwpuclnt.dll | Jump to behavior |
Source: 1.2.Documents of shipment 3-2024.exe.374f338.2.unpack, type: UNPACKEDPE | Matched rule: INDICATOR_SUSPICIOUS_EXE_VaultSchemaGUID author = ditekSHen, description = Detects executables referencing Windows vault credential objects. Observed in infostealers |
Source: 3.2.Documents of shipment 3-2024.exe.400000.0.unpack, type: UNPACKEDPE | Matched rule: INDICATOR_SUSPICIOUS_EXE_VaultSchemaGUID author = ditekSHen, description = Detects executables referencing Windows vault credential objects. Observed in infostealers |
Source: 1.2.Documents of shipment 3-2024.exe.3789d58.3.unpack, type: UNPACKEDPE | Matched rule: INDICATOR_SUSPICIOUS_EXE_VaultSchemaGUID author = ditekSHen, description = Detects executables referencing Windows vault credential objects. Observed in infostealers |
Source: 1.2.Documents of shipment 3-2024.exe.3789d58.3.raw.unpack, type: UNPACKEDPE | Matched rule: INDICATOR_SUSPICIOUS_EXE_VaultSchemaGUID author = ditekSHen, description = Detects executables referencing Windows vault credential objects. Observed in infostealers |
Source: 1.2.Documents of shipment 3-2024.exe.374f338.2.raw.unpack, type: UNPACKEDPE | Matched rule: INDICATOR_SUSPICIOUS_EXE_VaultSchemaGUID author = ditekSHen, description = Detects executables referencing Windows vault credential objects. Observed in infostealers |
Source: 1.2.Documents of shipment 3-2024.exe.3789d58.3.raw.unpack, ISZbPXDvPz.cs | Cryptographic APIs: 'TransformFinalBlock' |
Source: 1.2.Documents of shipment 3-2024.exe.3789d58.3.raw.unpack, ISZbPXDvPz.cs | Cryptographic APIs: 'TransformFinalBlock', 'CreateDecryptor' |
Source: 1.2.Documents of shipment 3-2024.exe.3789d58.3.raw.unpack, nAXAT51m.cs | Cryptographic APIs: 'TransformFinalBlock' |
Source: 1.2.Documents of shipment 3-2024.exe.3789d58.3.raw.unpack, nAXAT51m.cs | Cryptographic APIs: 'TransformFinalBlock' |
Source: 1.2.Documents of shipment 3-2024.exe.3789d58.3.raw.unpack, nAXAT51m.cs | Cryptographic APIs: 'TransformFinalBlock' |
Source: 1.2.Documents of shipment 3-2024.exe.3789d58.3.raw.unpack, nAXAT51m.cs | Cryptographic APIs: 'TransformFinalBlock' |
Source: 1.2.Documents of shipment 3-2024.exe.3789d58.3.raw.unpack, YpS.cs | Cryptographic APIs: 'TransformFinalBlock' |
Source: 1.2.Documents of shipment 3-2024.exe.3789d58.3.raw.unpack, YpS.cs | Cryptographic APIs: 'TransformFinalBlock' |
Source: 1.2.Documents of shipment 3-2024.exe.6ae0000.5.raw.unpack, LY9WGgoMp5W6Ls47W9.cs | High entropy of concatenated method names: 'LHi98FWZep', 'p4M9ixVqgj', 'SkT9bYCkfZ', 'm8ebUZW1xs', 'e4BbzQBeaS', 'A4D9ZrhblG', 'FQo92xQ1Pw', 'OI09IHN5Xy', 'RCR9gfoFMQ', 'zoJ9AVHb8u' |
Source: 1.2.Documents of shipment 3-2024.exe.6ae0000.5.raw.unpack, k3Hp3OrSCTWFTJ5OT9.cs | High entropy of concatenated method names: 'KhAMdUc7rt', 'j66MW5j9kH', 'fI2iSAgTgr', 'SVhiCC9uYT', 'jLEixAvbXP', 's2xiu26uwd', 'IP8ioMiZqC', 'acjiTwrbG0', 'ViFi3697NE', 'PV2iRqj6Ku' |
Source: 1.2.Documents of shipment 3-2024.exe.6ae0000.5.raw.unpack, l2N8Wpqy0LebEdWDSs.cs | High entropy of concatenated method names: 'HigjRkng4F', 'XmHjFrOeLy', 'wYijqA7v6x', 'Kuhj7ydvYO', 'D7sj5KI7eT', 'zBijSX88a7', 'Ts5jCiIPET', 'ynojxWaYSm', 'RLNjuRUofN', 'my3jo6wvy7' |
Source: 1.2.Documents of shipment 3-2024.exe.6ae0000.5.raw.unpack, CWfQjmDbvcXPECMA27.cs | High entropy of concatenated method names: 'PPiQsdfL3I', 'jqeQURYsGa', 'BLmeZI1JPr', 'iaue2kv6AB', 'CrpQHDGQDg', 'NNmQFpAbjG', 'zRhQNOscUC', 'mZXQqCrPP3', 'xBEQ7jmGos', 'OI3Qvjf5O7' |
Source: 1.2.Documents of shipment 3-2024.exe.6ae0000.5.raw.unpack, dCmF1Ssthw6NjSeCNU.cs | High entropy of concatenated method names: 'wuje8fgRjf', 'M8xe0m0Rq4', 'DT5ei8K45i', 'JOueMKXdTV', 'oZKeb1BRZk', 'h20e9WQQsq', 'iqdeB9cbtb', 'RsEecqn0GJ', 'mdue622MYu', 'BdHeaEm9SV' |
Source: 1.2.Documents of shipment 3-2024.exe.6ae0000.5.raw.unpack, VSDVbK3tUKZEx3nS90.cs | High entropy of concatenated method names: 'nBW9GJTyr7', 'BKR9mYNHEV', 'Gq49pU7KBU', 'MD29ty2aW5', 'Pr09daVdqJ', 'ooi9XTsLvS', 'O1b9WtTdpG', 'Hos9yGuoaV', 'y8n9JgYaPf', 'i8n9rNFDMq' |
Source: 1.2.Documents of shipment 3-2024.exe.6ae0000.5.raw.unpack, BylFJf2Zhp8SLOP8x1I.cs | High entropy of concatenated method names: 'MAofGHCIZ8', 'fqyfmGsBpO', 'x4qfptxY2q', 'GVKftRrYvL', 'fi0fdnE2Hq', 'Ii6fXNUtBO', 'CEGfWlTvLb', 'rRdfyoPAns', 'LT3fJMvY5C', 'KlcfrADW0I' |
Source: 1.2.Documents of shipment 3-2024.exe.6ae0000.5.raw.unpack, gM2G8n0AHJRGPmLJNN.cs | High entropy of concatenated method names: 'Dispose', 'Tbp2VSQVLP', 'u38I5I2Qcc', 'qNmYYxk13q', 'mAC2UmF1St', 'Uw62zNjSeC', 'ProcessDialogKey', 'QUIIZIvYPF', 'zyII2riUck', 'mokIIfQ7i8' |
Source: 1.2.Documents of shipment 3-2024.exe.6ae0000.5.raw.unpack, LsAxH0IgLQPGa9oup8.cs | High entropy of concatenated method names: 'QSgpuBq8s', 'N0It1JvFI', 'YLFXqZKLO', 'uayWQUmp8', 'GyJJkCFkD', 'sPkr00p24', 'sByXSnf0gWcUhmau8p', 'D67D7Utcg2umaDOtp2', 'xgieN7uPh', 'gktYXVHym' |
Source: 1.2.Documents of shipment 3-2024.exe.6ae0000.5.raw.unpack, bIvYPFVtyIriUck6ok.cs | High entropy of concatenated method names: 'Ua0eKnlxO3', 'o7re57rA7r', 'OBoeSljykt', 'USXeCiYnad', 'SLaeqh1cy2', 'tBEexj65Lw', 'Next', 'Next', 'Next', 'NextBytes' |
Source: 1.2.Documents of shipment 3-2024.exe.6ae0000.5.raw.unpack, rQ7i8GUFLJVmdv8p2Y.cs | High entropy of concatenated method names: 'yhnf2KlrHa', 'xTBfghTtSe', 'rpsfA98TDs', 'YjEf8mQbvV', 'slyf0O2c1m', 'Kb7fM6wFo3', 'ar9fbvUQUL', 'Adae49GATU', 'BN3es1eH8t', 'OUmeVWHRgb' |
Source: 1.2.Documents of shipment 3-2024.exe.6ae0000.5.raw.unpack, lpyWDZv40r0bWpUTjS.cs | High entropy of concatenated method names: 'ToString', 's1PkHhTaO1', 'O2qk5JBcYw', 'I4hkSk6ZHi', 'UBPkCXmZth', 'akckxPH9Jq', 'Q9Fkud5Xep', 'jJSkoKl03u', 'MVIkT1ZrCZ', 'pRtk3HsJgo' |
Source: 1.2.Documents of shipment 3-2024.exe.6ae0000.5.raw.unpack, XTPGhDA3dIlhb64mav.cs | High entropy of concatenated method names: 'k7N29VE6fv', 'sY62BnuXQ1', 'poZ26wYr1m', 'm0d2a2B3Hp', 'E5O2jT9g3W', 'PxX2koTBRF', 'wfMeKR9Xpo0AND7rgS', 'h4HUGaviZk02U9jVKF', 'Fsh222YUnb', 'mQB2gSbxk9' |
Source: 1.2.Documents of shipment 3-2024.exe.6ae0000.5.raw.unpack, QhXs1iicvmrsW3kO07.cs | High entropy of concatenated method names: 'EditValue', 'GetEditStyle', 'UQjIVXLqqY', 'vUaIUVaJ9Z', 'oL7Iz2k5FG', 'tFYgZohJg8', 'jCvg2cLl60', 'Xl7gIbujGe', 'qQXggF5ybB', 'UpqUDWorkCFlXcm46CV' |
Source: 1.2.Documents of shipment 3-2024.exe.6ae0000.5.raw.unpack, c3WFxXKoTBRFECotHe.cs | High entropy of concatenated method names: 'oq8bnJ3xJI', 'WBXb0cMr4W', 'xPIbMT0Xj5', 'kWyb99kilu', 'CWsbB0G9On', 'tkOMh4lxIa', 'lVfMDhWffe', 'dVOM4wNreg', 'y4mMsf3eLR', 'nNoMVqvNpW' |
Source: 1.2.Documents of shipment 3-2024.exe.6ae0000.5.raw.unpack, L1THh1BjLYfAt0yqQB.cs | High entropy of concatenated method names: 'm8vgnnwCwk', 'QrLg8xsWkL', 'w7cg01PvZL', 'YcggiEp5S6', 'BU7gM800X2', 've3gbAog5e', 'BsSg9CnGOh', 'lrrgBt4Ejt', 'LEggcLNXKu', 'IBMg6Qwjqg' |
Source: 1.2.Documents of shipment 3-2024.exe.6ae0000.5.raw.unpack, QVE6fvyfY6nuXQ1y2a.cs | High entropy of concatenated method names: 'bcN0qkV31Y', 'Bm307QToCk', 'dfZ0vIpE0Y', 'e940Ew7V1B', 'jFM0hFgYMI', 'efS0DabEU8', 'NM404rXAkH', 'JSI0sfCQjs', 'NsE0VbF6qI', 'j4H0UxMEi6' |
Source: 1.2.Documents of shipment 3-2024.exe.6ae0000.5.raw.unpack, RcwQHaEZy6735qurFY.cs | High entropy of concatenated method names: 'P96Q6ZaFsG', 'QZgQatDWSE', 'ToString', 'ukQQ8NnhUm', 'CODQ0tlI8o', 'kaAQiQvCBg', 'icDQMXiLrI', 'VjUQbHHPsF', 'x9JQ963RLi', 'oyVQBAqxqs' |
Source: 1.2.Documents of shipment 3-2024.exe.6ae0000.5.raw.unpack, bwxwKbNIvW51SAID7j.cs | High entropy of concatenated method names: 'qF4Py0fJ41', 'vXtPJpbDqK', 'ARjPKGvtBL', 'MyEP5fffaY', 'BWZPCPboR3', 'RGaPxAaydS', 'Mk7PoLi0hC', 'j9BPTKUrCk', 'cK0PRb2j0M', 'RA8PHmrY6V' |
Source: 1.2.Documents of shipment 3-2024.exe.6ae0000.5.raw.unpack, FRq2DkJoZwYr1m60d2.cs | High entropy of concatenated method names: 'LuQitvlipS', 'zJkiXX75u4', 't9FiyKOrMK', 'xF7iJD83OR', 'u6RijvPsJ0', 'DEPiklZZiv', 'QsDiQfe4Xr', 'TCmiePeUSv', 'eyrifNvMAU', 'QqfiYicV9C' |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Memory allocated: 2280000 memory reserve | memory write watch | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Memory allocated: 24D0000 memory reserve | memory write watch | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Memory allocated: 22F0000 memory reserve | memory write watch | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Memory allocated: 89E0000 memory reserve | memory write watch | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Memory allocated: 99E0000 memory reserve | memory write watch | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Memory allocated: 9BF0000 memory reserve | memory write watch | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Memory allocated: ABF0000 memory reserve | memory write watch | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Memory allocated: 15D0000 memory reserve | memory write watch | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Memory allocated: 31A0000 memory reserve | memory write watch | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Memory allocated: 30F0000 memory reserve | memory write watch | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe TID: 7524 | Thread sleep time: -922337203685477s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe TID: 7748 | Thread sleep time: -10145709240540247s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe TID: 7748 | Thread sleep time: -100000s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe TID: 7748 | Thread sleep time: -99875s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe TID: 7764 | Thread sleep count: 1291 > 30 | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe TID: 7748 | Thread sleep time: -99766s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe TID: 7764 | Thread sleep count: 2893 > 30 | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe TID: 7748 | Thread sleep time: -99641s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe TID: 7748 | Thread sleep time: -99500s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe TID: 7748 | Thread sleep time: -99391s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe TID: 7748 | Thread sleep time: -99266s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe TID: 7748 | Thread sleep time: -99153s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe TID: 7748 | Thread sleep time: -99047s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe TID: 7748 | Thread sleep time: -98937s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe TID: 7748 | Thread sleep time: -98828s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe TID: 7748 | Thread sleep time: -98719s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe TID: 7748 | Thread sleep time: -98609s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe TID: 7748 | Thread sleep time: -98500s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe TID: 7748 | Thread sleep time: -98391s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe TID: 7748 | Thread sleep time: -98281s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe TID: 7748 | Thread sleep time: -98172s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe TID: 7748 | Thread sleep time: -98062s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe TID: 7748 | Thread sleep time: -97953s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe TID: 7748 | Thread sleep time: -97844s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe TID: 7748 | Thread sleep time: -97734s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe TID: 7748 | Thread sleep time: -922337203685477s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Thread delayed: delay time: 100000 | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Thread delayed: delay time: 99875 | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Thread delayed: delay time: 99766 | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Thread delayed: delay time: 99641 | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Thread delayed: delay time: 99500 | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Thread delayed: delay time: 99391 | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Thread delayed: delay time: 99266 | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Thread delayed: delay time: 99153 | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Thread delayed: delay time: 99047 | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Thread delayed: delay time: 98937 | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Thread delayed: delay time: 98828 | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Thread delayed: delay time: 98719 | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Thread delayed: delay time: 98609 | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Thread delayed: delay time: 98500 | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Thread delayed: delay time: 98391 | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Thread delayed: delay time: 98281 | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Thread delayed: delay time: 98172 | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Thread delayed: delay time: 98062 | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Thread delayed: delay time: 97953 | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Thread delayed: delay time: 97844 | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Thread delayed: delay time: 97734 | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Queries volume information: C:\Users\user\Desktop\Documents of shipment 3-2024.exe VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Queries volume information: C:\Windows\Fonts\micross.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Queries volume information: C:\Users\user\Desktop\Documents of shipment 3-2024.exe VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Security\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Security.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Documents of shipment 3-2024.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation | Jump to behavior |
Source: Yara match | File source: dump.pcap, type: PCAP |
Source: Yara match | File source: 1.2.Documents of shipment 3-2024.exe.374f338.2.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 3.2.Documents of shipment 3-2024.exe.400000.0.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 1.2.Documents of shipment 3-2024.exe.3789d58.3.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 1.2.Documents of shipment 3-2024.exe.3789d58.3.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 1.2.Documents of shipment 3-2024.exe.374f338.2.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 00000003.00000002.2487661512.00000000031F6000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000003.00000002.2487661512.00000000031EE000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000003.00000002.2484776287.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000003.00000002.2487661512.00000000031A1000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000001.00000002.1247364304.00000000036AE000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: Process Memory Space: Documents of shipment 3-2024.exe PID: 7472, type: MEMORYSTR |
Source: Yara match | File source: Process Memory Space: Documents of shipment 3-2024.exe PID: 7644, type: MEMORYSTR |
Source: Yara match | File source: dump.pcap, type: PCAP |
Source: Yara match | File source: 1.2.Documents of shipment 3-2024.exe.374f338.2.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 3.2.Documents of shipment 3-2024.exe.400000.0.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 1.2.Documents of shipment 3-2024.exe.3789d58.3.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 1.2.Documents of shipment 3-2024.exe.3789d58.3.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 1.2.Documents of shipment 3-2024.exe.374f338.2.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 00000003.00000002.2487661512.00000000031F6000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000003.00000002.2487661512.00000000031EE000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000003.00000002.2484776287.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000003.00000002.2487661512.00000000031A1000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000001.00000002.1247364304.00000000036AE000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Source: Yara match | File source: Process Memory Space: Documents of shipment 3-2024.exe PID: 7472, type: MEMORYSTR |
Source: Yara match | File source: Process Memory Space: Documents of shipment 3-2024.exe PID: 7644, type: MEMORYSTR |