Source: C:\Users\user\Desktop\SOA-Al Daleel.exe |
Code function: 1_2_0136D364 |
1_2_0136D364 |
Source: C:\Users\user\Desktop\SOA-Al Daleel.exe |
Code function: 1_2_01601700 |
1_2_01601700 |
Source: C:\Users\user\Desktop\SOA-Al Daleel.exe |
Code function: 1_2_01601710 |
1_2_01601710 |
Source: C:\Users\user\Desktop\SOA-Al Daleel.exe |
Code function: 1_2_01607B48 |
1_2_01607B48 |
Source: C:\Users\user\Desktop\SOA-Al Daleel.exe |
Code function: 1_2_01608BE8 |
1_2_01608BE8 |
Source: C:\Users\user\Desktop\SOA-Al Daleel.exe |
Code function: 1_2_0313F718 |
1_2_0313F718 |
Source: C:\Users\user\Desktop\SOA-Al Daleel.exe |
Code function: 1_2_0313BB70 |
1_2_0313BB70 |
Source: C:\Users\user\Desktop\SOA-Al Daleel.exe |
Code function: 1_2_0313F6CE |
1_2_0313F6CE |
Source: C:\Users\user\Desktop\SOA-Al Daleel.exe |
Code function: 1_2_0313BB60 |
1_2_0313BB60 |
Source: C:\Users\user\Desktop\SOA-Al Daleel.exe |
Code function: 1_2_0313FBC8 |
1_2_0313FBC8 |
Source: C:\Users\user\Desktop\SOA-Al Daleel.exe |
Code function: 1_2_07481060 |
1_2_07481060 |
Source: C:\Users\user\Desktop\SOA-Al Daleel.exe |
Code function: 1_2_07487F28 |
1_2_07487F28 |
Source: C:\Users\user\Desktop\SOA-Al Daleel.exe |
Code function: 1_2_07483D50 |
1_2_07483D50 |
Source: C:\Users\user\Desktop\SOA-Al Daleel.exe |
Code function: 1_2_07488779 |
1_2_07488779 |
Source: C:\Users\user\Desktop\SOA-Al Daleel.exe |
Code function: 1_2_0748877B |
1_2_0748877B |
Source: C:\Users\user\Desktop\SOA-Al Daleel.exe |
Code function: 1_2_07488788 |
1_2_07488788 |
Source: C:\Users\user\Desktop\SOA-Al Daleel.exe |
Code function: 1_2_07482450 |
1_2_07482450 |
Source: C:\Users\user\Desktop\SOA-Al Daleel.exe |
Code function: 1_2_07482460 |
1_2_07482460 |
Source: C:\Users\user\Desktop\SOA-Al Daleel.exe |
Code function: 1_2_07486438 |
1_2_07486438 |
Source: C:\Users\user\Desktop\SOA-Al Daleel.exe |
Code function: 1_2_0748F4C8 |
1_2_0748F4C8 |
Source: C:\Users\user\Desktop\SOA-Al Daleel.exe |
Code function: 1_2_074872F0 |
1_2_074872F0 |
Source: C:\Users\user\Desktop\SOA-Al Daleel.exe |
Code function: 1_2_074882B1 |
1_2_074882B1 |
Source: C:\Users\user\Desktop\SOA-Al Daleel.exe |
Code function: 1_2_07481053 |
1_2_07481053 |
Source: C:\Users\user\Desktop\SOA-Al Daleel.exe |
Code function: 1_2_0748F090 |
1_2_0748F090 |
Source: C:\Users\user\Desktop\SOA-Al Daleel.exe |
Code function: 1_2_07487F18 |
1_2_07487F18 |
Source: C:\Users\user\Desktop\SOA-Al Daleel.exe |
Code function: 1_2_07483EE3 |
1_2_07483EE3 |
Source: C:\Users\user\Desktop\SOA-Al Daleel.exe |
Code function: 1_2_07483D43 |
1_2_07483D43 |
Source: C:\Users\user\Desktop\SOA-Al Daleel.exe |
Code function: 1_2_0748EC58 |
1_2_0748EC58 |
Source: C:\Users\user\Desktop\SOA-Al Daleel.exe |
Code function: 1_2_07487967 |
1_2_07487967 |
Source: C:\Users\user\Desktop\SOA-Al Daleel.exe |
Code function: 1_2_07487978 |
1_2_07487978 |
Source: C:\Users\user\Desktop\SOA-Al Daleel.exe |
Code function: 1_2_0748F900 |
1_2_0748F900 |
Source: C:\Users\user\Desktop\SOA-Al Daleel.exe |
Code function: 1_2_07481918 |
1_2_07481918 |
Source: C:\Users\user\Desktop\SOA-Al Daleel.exe |
Code function: 1_2_07481913 |
1_2_07481913 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 10_2_014ED025 |
10_2_014ED025 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 10_2_014E9378 |
10_2_014E9378 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 10_2_014E9B38 |
10_2_014E9B38 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 10_2_014E4A98 |
10_2_014E4A98 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 10_2_014E3E80 |
10_2_014E3E80 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 10_2_014ED168 |
10_2_014ED168 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 10_2_014E41C8 |
10_2_014E41C8 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 10_2_063A56A8 |
10_2_063A56A8 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 10_2_063A0040 |
10_2_063A0040 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 10_2_063A3F18 |
10_2_063A3F18 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 10_2_063ADCF0 |
10_2_063ADCF0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 10_2_063ABCD8 |
10_2_063ABCD8 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 10_2_063A9AB8 |
10_2_063A9AB8 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 10_2_063A2AF0 |
10_2_063A2AF0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 10_2_063A8B68 |
10_2_063A8B68 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 10_2_063A3210 |
10_2_063A3210 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 10_2_063A4FC8 |
10_2_063A4FC8 |
Source: C:\Users\user\AppData\Roaming\eeXxnIpy.exe |
Code function: 11_2_05466CD0 |
11_2_05466CD0 |
Source: C:\Users\user\AppData\Roaming\eeXxnIpy.exe |
Code function: 11_2_05461700 |
11_2_05461700 |
Source: C:\Users\user\AppData\Roaming\eeXxnIpy.exe |
Code function: 11_2_05461710 |
11_2_05461710 |
Source: C:\Users\user\AppData\Roaming\eeXxnIpy.exe |
Code function: 11_2_05467970 |
11_2_05467970 |
Source: C:\Users\user\AppData\Roaming\eeXxnIpy.exe |
Code function: 11_2_058E7D58 |
11_2_058E7D58 |
Source: C:\Users\user\AppData\Roaming\eeXxnIpy.exe |
Code function: 11_2_058E7FB0 |
11_2_058E7FB0 |
Source: C:\Users\user\AppData\Roaming\eeXxnIpy.exe |
Code function: 11_2_058E0006 |
11_2_058E0006 |
Source: C:\Users\user\AppData\Roaming\eeXxnIpy.exe |
Code function: 11_2_058E0040 |
11_2_058E0040 |
Source: C:\Users\user\AppData\Roaming\eeXxnIpy.exe |
Code function: 11_2_058EAEB0 |
11_2_058EAEB0 |
Source: C:\Users\user\AppData\Roaming\eeXxnIpy.exe |
Code function: 11_2_058E7FA1 |
11_2_058E7FA1 |
Source: C:\Users\user\AppData\Roaming\eeXxnIpy.exe |
Code function: 11_2_0592F718 |
11_2_0592F718 |
Source: C:\Users\user\AppData\Roaming\eeXxnIpy.exe |
Code function: 11_2_0592BB70 |
11_2_0592BB70 |
Source: C:\Users\user\AppData\Roaming\eeXxnIpy.exe |
Code function: 11_2_0592F6CE |
11_2_0592F6CE |
Source: C:\Users\user\AppData\Roaming\eeXxnIpy.exe |
Code function: 11_2_0592FBC8 |
11_2_0592FBC8 |
Source: C:\Users\user\AppData\Roaming\eeXxnIpy.exe |
Code function: 11_2_0592BB60 |
11_2_0592BB60 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 15_2_0122D021 |
15_2_0122D021 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 15_2_01229378 |
15_2_01229378 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 15_2_01229B38 |
15_2_01229B38 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 15_2_01224A98 |
15_2_01224A98 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 15_2_01223E80 |
15_2_01223E80 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 15_2_0122D168 |
15_2_0122D168 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 15_2_012241C8 |
15_2_012241C8 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 15_2_05F4DCF0 |
15_2_05F4DCF0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 15_2_05F4BCD8 |
15_2_05F4BCD8 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 15_2_05F43F18 |
15_2_05F43F18 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 15_2_05F456A8 |
15_2_05F456A8 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 15_2_05F40040 |
15_2_05F40040 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 15_2_05F48B68 |
15_2_05F48B68 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 15_2_05F42AF0 |
15_2_05F42AF0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 15_2_05F44FC8 |
15_2_05F44FC8 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Code function: 15_2_05F43210 |
15_2_05F43210 |
Source: C:\Users\user\Desktop\SOA-Al Daleel.exe |
Section loaded: mscoree.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\SOA-Al Daleel.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\SOA-Al Daleel.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\SOA-Al Daleel.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\SOA-Al Daleel.exe |
Section loaded: vcruntime140_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\SOA-Al Daleel.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\SOA-Al Daleel.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\SOA-Al Daleel.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\SOA-Al Daleel.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\SOA-Al Daleel.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\SOA-Al Daleel.exe |
Section loaded: cryptsp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\SOA-Al Daleel.exe |
Section loaded: rsaenh.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\SOA-Al Daleel.exe |
Section loaded: cryptbase.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\SOA-Al Daleel.exe |
Section loaded: dwrite.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\SOA-Al Daleel.exe |
Section loaded: amsi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\SOA-Al Daleel.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\SOA-Al Daleel.exe |
Section loaded: msasn1.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\SOA-Al Daleel.exe |
Section loaded: gpapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\SOA-Al Daleel.exe |
Section loaded: windowscodecs.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\SOA-Al Daleel.exe |
Section loaded: ntmarta.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\SOA-Al Daleel.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\SOA-Al Daleel.exe |
Section loaded: propsys.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\SOA-Al Daleel.exe |
Section loaded: edputil.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\SOA-Al Daleel.exe |
Section loaded: urlmon.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\SOA-Al Daleel.exe |
Section loaded: iertutil.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\SOA-Al Daleel.exe |
Section loaded: srvcli.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\SOA-Al Daleel.exe |
Section loaded: netutils.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\SOA-Al Daleel.exe |
Section loaded: windows.staterepositoryps.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\SOA-Al Daleel.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\SOA-Al Daleel.exe |
Section loaded: appresolver.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\SOA-Al Daleel.exe |
Section loaded: bcp47langs.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\SOA-Al Daleel.exe |
Section loaded: slc.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\SOA-Al Daleel.exe |
Section loaded: sppc.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\SOA-Al Daleel.exe |
Section loaded: onecorecommonproxystub.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\SOA-Al Daleel.exe |
Section loaded: onecoreuapcommonproxystub.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: atl.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: mscoree.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: vcruntime140_clr0400.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: cryptsp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: rsaenh.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: cryptbase.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: amsi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: msasn1.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: msisip.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: wshext.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: appxsip.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: opcservices.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: gpapi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: secur32.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: urlmon.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: iertutil.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: srvcli.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: netutils.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: propsys.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: wininet.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: microsoft.management.infrastructure.native.unmanaged.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: mi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: miutils.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: wmidcom.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: dpapi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: wbemcomn.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\schtasks.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\schtasks.exe |
Section loaded: taskschd.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\schtasks.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Section loaded: mscoree.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Section loaded: vcruntime140_clr0400.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Section loaded: cryptsp.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Section loaded: rsaenh.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Section loaded: cryptbase.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Section loaded: wbemcomn.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Section loaded: amsi.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Section loaded: vaultcli.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Section loaded: iphlpapi.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Section loaded: dnsapi.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Section loaded: dhcpcsvc6.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Section loaded: dhcpcsvc.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Section loaded: winnsi.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Section loaded: mswsock.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Section loaded: rasadhlp.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Section loaded: fwpuclnt.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Section loaded: secur32.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Section loaded: schannel.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Section loaded: mskeyprotect.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Section loaded: ntasn1.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Section loaded: ncrypt.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Section loaded: ncryptsslp.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Section loaded: msasn1.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eeXxnIpy.exe |
Section loaded: mscoree.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eeXxnIpy.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eeXxnIpy.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eeXxnIpy.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eeXxnIpy.exe |
Section loaded: vcruntime140_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eeXxnIpy.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eeXxnIpy.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eeXxnIpy.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eeXxnIpy.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eeXxnIpy.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eeXxnIpy.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eeXxnIpy.exe |
Section loaded: cryptsp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eeXxnIpy.exe |
Section loaded: rsaenh.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eeXxnIpy.exe |
Section loaded: cryptbase.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eeXxnIpy.exe |
Section loaded: dwrite.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eeXxnIpy.exe |
Section loaded: amsi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eeXxnIpy.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eeXxnIpy.exe |
Section loaded: msasn1.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eeXxnIpy.exe |
Section loaded: gpapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eeXxnIpy.exe |
Section loaded: windowscodecs.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eeXxnIpy.exe |
Section loaded: propsys.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eeXxnIpy.exe |
Section loaded: edputil.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eeXxnIpy.exe |
Section loaded: urlmon.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eeXxnIpy.exe |
Section loaded: iertutil.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eeXxnIpy.exe |
Section loaded: srvcli.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eeXxnIpy.exe |
Section loaded: netutils.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eeXxnIpy.exe |
Section loaded: windows.staterepositoryps.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eeXxnIpy.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eeXxnIpy.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eeXxnIpy.exe |
Section loaded: appresolver.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eeXxnIpy.exe |
Section loaded: bcp47langs.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eeXxnIpy.exe |
Section loaded: slc.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eeXxnIpy.exe |
Section loaded: sppc.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eeXxnIpy.exe |
Section loaded: onecorecommonproxystub.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eeXxnIpy.exe |
Section loaded: onecoreuapcommonproxystub.dll |
Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: fastprox.dll |
Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: ncobjapi.dll |
Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: wbemcomn.dll |
Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: wbemcomn.dll |
Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: mpclient.dll |
Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: msasn1.dll |
Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: wmitomi.dll |
Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: mi.dll |
Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: miutils.dll |
Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: gpapi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\schtasks.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\schtasks.exe |
Section loaded: taskschd.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\schtasks.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Section loaded: mscoree.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Section loaded: vcruntime140_clr0400.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Section loaded: cryptsp.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Section loaded: rsaenh.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Section loaded: cryptbase.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Section loaded: wbemcomn.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Section loaded: amsi.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Section loaded: vaultcli.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Section loaded: iphlpapi.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Section loaded: dnsapi.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Section loaded: dhcpcsvc6.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Section loaded: dhcpcsvc.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Section loaded: winnsi.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Section loaded: mswsock.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Section loaded: rasadhlp.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Section loaded: fwpuclnt.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Section loaded: secur32.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Section loaded: schannel.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Section loaded: mskeyprotect.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Section loaded: ntasn1.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Section loaded: ncrypt.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Section loaded: ncryptsslp.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Section loaded: msasn1.dll |
Jump to behavior |
Source: 1.2.SOA-Al Daleel.exe.7e00000.8.raw.unpack, FS4WZPMtGmHZsvtoqxr.cs |
High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'OpGs0t0u2p', 'EGMsc3hQGy', 'y1FsioBIwG', 'yGPs2vPoSy', 'jlKsED5VnD', 'Hh1sWwSddW', 'vEYsHiNQt6' |
Source: 1.2.SOA-Al Daleel.exe.7e00000.8.raw.unpack, xLnFXNr3HFxaLKS95p.cs |
High entropy of concatenated method names: 'H2tqPfQ5NC', 'ROfqj5oVNJ', 'kGXqVgnKSj', 'VQbVmawvla', 'TVZVzro6JV', 'bGuqKjlXm4', 'IJ6qMeWbdy', 'V6hqYMe6Wo', 'cbSqtgm584', 'vkHqn6OPDE' |
Source: 1.2.SOA-Al Daleel.exe.7e00000.8.raw.unpack, WpTrCDeRd6UKSRIBf0.cs |
High entropy of concatenated method names: 'KKw5NqH0jc', 'dF65x4J3D5', 'pmjj6Em8FG', 'a5Yj9PFkuV', 'FlIjU3pqOb', 'zywjT0EKX1', 'owgjrMyjRp', 'IWTjAVSa8C', 'idHjDx1akG', 'VqXjQImgBV' |
Source: 1.2.SOA-Al Daleel.exe.7e00000.8.raw.unpack, mRTYIxOiui1rh23kdo.cs |
High entropy of concatenated method names: 'UfxwPnjyMD', 'z6awIQMqKZ', 'BjHwjpqwOt', 'C46w5wZYqZ', 'WgcwVtCHZ8', 'MHtwqReAx0', 'roJwGrIOYm', 'ARDwScggQa', 'I7PwJ5vbSp', 'EynwgbV2i5' |
Source: 1.2.SOA-Al Daleel.exe.7e00000.8.raw.unpack, hYU3HGMKWv8bkPWU6ax.cs |
High entropy of concatenated method names: 'DqBC4bdBc1', 'G1HCosUVyR', 'PuEC1T1xbG', 'yCXC8DnlUO', 'vueCNkxMJS', 'gRnCZwqSxF', 'rdHCx1mcax', 'bptCp2CcLH', 'MDMCBduhj7', 'PgdCejNSg3' |
Source: 1.2.SOA-Al Daleel.exe.7e00000.8.raw.unpack, nmWwLFp6y3CsQoaaSm.cs |
High entropy of concatenated method names: 'HmII0Qj0iD', 'ysrIcIfavG', 'AMGIi6OSyM', 'UyaI2R4pQj', 'rmLIENfF5m', 'vBoIWq596Q', 'gPGIHjhlSi', 'c9cIOp0ebS', 'j8cIFjMiQS', 'OyiIm205qG' |
Source: 1.2.SOA-Al Daleel.exe.7e00000.8.raw.unpack, NOe3SomiFjQjwIKZ19.cs |
High entropy of concatenated method names: 'pwwCMMGNRl', 'QAPCtlSaJe', 'deDCnphy84', 'IgYCPnGkSu', 'liJCIERrnG', 'MqRC5Ixl2U', 'eACCVVKvC0', 'QdbwHapMg5', 'eaiwOiYppc', 'SyJwFLCUB8' |
Source: 1.2.SOA-Al Daleel.exe.7e00000.8.raw.unpack, bTT64qIAwoSlECeHGn.cs |
High entropy of concatenated method names: 'Dispose', 'arQMF4Qkw2', 'lQHYkem6Gi', 'VWCbbJBeIj', 'bJRMmTYIxi', 'ui1Mzrh23k', 'ProcessDialogKey', 'OoPYKX7iEk', 'MJyYMYRb1m', 'jPVYYQOe3S' |
Source: 1.2.SOA-Al Daleel.exe.7e00000.8.raw.unpack, WX1d9xMMPbCWFZFN1bJ.cs |
High entropy of concatenated method names: 'ToString', 'xE9stCbvrV', 'rKusnBNcM6', 'vaPs7PGZrX', 'vuOsP0vo1l', 'kljsIn6Kvk', 'CbQsjShd0o', 'Hhps5m2EVY', 'AW31hKWRkDBxue9ujjw', 'kyZA0SW6BjZLNha57Em' |
Source: 1.2.SOA-Al Daleel.exe.7e00000.8.raw.unpack, LuTWFhDqbyYGms4qGU.cs |
High entropy of concatenated method names: 'o2pq4HHOYF', 'RMsqonMdDi', 'dN1q1TOFsJ', 'Iu6q8XTHZG', 'dGpqNiW6Ny', 'iLxqZcUhyo', 'XtMqxNqAQP', 'bSOqpJ2ACZ', 'x68qBq1gyA', 'SOXqe0ryUd' |
Source: 1.2.SOA-Al Daleel.exe.7e00000.8.raw.unpack, BFcI26iDUMvT9J3TRi.cs |
High entropy of concatenated method names: 'ToString', 'E0GXdM9HRU', 'mAcXkJotsZ', 'VcaX6jy0HS', 'Ya9X9mf835', 'MCBXUb5s86', 'd2ZXTOkVNF', 'elFXr7AWpm', 'k8oXAXCnL1', 'x1JXDwmIcX' |
Source: 1.2.SOA-Al Daleel.exe.7e00000.8.raw.unpack, tFal2IWqM4KEuopdVU.cs |
High entropy of concatenated method names: 'LsgRObLiK0', 'BUfRmw0jrT', 'SaCwKLPviK', 'fKPwMfeCBM', 'BGFRdbNv2T', 'mAFRhkvjgl', 'CE2RLjkVGh', 'qnWR0QbHtN', 'EgcRcCDl8v', 'TOmRi2osne' |
Source: 1.2.SOA-Al Daleel.exe.7e00000.8.raw.unpack, Q7YLY1zjDKs4A9wNqQ.cs |
High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'yggClUrEYY', 'hMdCyLCJko', 'G2jCXh7A37', 'BHiCRKMxFX', 'rRKCwAi4Am', 'PXwCCP9MxL', 'sArCs13RcM' |
Source: 1.2.SOA-Al Daleel.exe.7e00000.8.raw.unpack, hkDdW7nnKXps9uafUV.cs |
High entropy of concatenated method names: 'X5lMqmWwLF', 'Iy3MGCsQoa', 'UO7MJj0XYh', 'lu4MgnHpTr', 'qIBMyf0dUv', 'GbpMXFjlmj', 'SZggXJ5LBlaVun6rde', 'UurvbqrwC453On0kGM', 'enqZqZhBMld2aa4SnV', 'oh3MMl6yxl' |
Source: 1.2.SOA-Al Daleel.exe.7e00000.8.raw.unpack, PvJ5GG095hCttXfFSn.cs |
High entropy of concatenated method names: 'Dk2yQkXhvJ', 'PnWyh8pcUW', 'bpJy0xxabw', 'bp5ycTMwKL', 'NeUykt14Mn', 'yEky6L9y8H', 'sZMy92wMDr', 'CA9yU2PKq8', 'Op3yTA58m1', 'Nlbyrg6p1t' |
Source: 1.2.SOA-Al Daleel.exe.7e00000.8.raw.unpack, KawfvEBO7j0XYhJu4n.cs |
High entropy of concatenated method names: 'MABj80TYh1', 'KEwjZKo9ZQ', 'p6fjpZuR9a', 'JJcjBdA0Sg', 'Og4jy7Q2tb', 'yCYjXt40TJ', 'cMXjRaLaGs', 'VFBjwa4Qx1', 'vlJjCNNCAy', 'rB9jsDIHHx' |
Source: 1.2.SOA-Al Daleel.exe.7e00000.8.raw.unpack, fX7iEkFDJyYRb1mqPV.cs |
High entropy of concatenated method names: 'xGqwaJtMUf', 'tQdwk3YJhV', 'Jfiw60dadM', 'iiiw9yCdJp', 'aABw0aNRZJ', 'fqCwUL79RX', 'Next', 'Next', 'Next', 'NextBytes' |
Source: 1.2.SOA-Al Daleel.exe.7e00000.8.raw.unpack, OUvkbpaFjlmjZtt3qe.cs |
High entropy of concatenated method names: 'n1bV7PsxsA', 'MxXVI9u9Tx', 'kgBV5aut62', 'ogmVqig8kr', 'xSLVGkkq7T', 'SxI5E5r5lw', 'Uqt5WARj8j', 'D6p5HIxtDO', 'OKp5Os5roF', 'h3D5Fmece7' |
Source: 1.2.SOA-Al Daleel.exe.7e00000.8.raw.unpack, JHelOmGX9xBk92vdl7.cs |
High entropy of concatenated method names: 'tYNt7gPTUp', 'wH2tPynM1X', 'F1xtIfmu2q', 'yFptjdVbZn', 'GLit5jEGVq', 'U4atVklNcI', 'H6dtqAlNFV', 'rsytGbqbgU', 'QYTtSnfiFU', 'ofetJdp4RK' |
Source: 1.2.SOA-Al Daleel.exe.7e00000.8.raw.unpack, zYcJRlYQUJlOxnn6is.cs |
High entropy of concatenated method names: 'N4q14g5iG', 'dB28oC7LP', 'a6qZb04mn', 'ihoxYgJmA', 'jgyBCCfCX', 'Seye1YUvV', 'rEkgBJ3ygkxoQR86pO', 'rAuQgYvKmUqvfnxo6p', 'iquw7GlW5', 'SuSs1Xevj' |
Source: 1.2.SOA-Al Daleel.exe.7e00000.8.raw.unpack, cLoPfEL4mIMos0teB9.cs |
High entropy of concatenated method names: 'sqJlp5mwrG', 'U8QlBXAKeb', 'luZlaOkHIa', 'KpIlk5st04', 'ERhl9ymdeT', 'tBylULSZZJ', 'L1Nlr8jTvL', 'TT9lAo2G3A', 'sbulQQnuhK', 'iBQldgbKWh' |
Source: 1.2.SOA-Al Daleel.exe.7e00000.8.raw.unpack, Ml3vWW25nwsS3efjZZ.cs |
High entropy of concatenated method names: 'STRRJwhDj0', 'UenRg0SYmG', 'ToString', 'LgYRPcYP3E', 'LxORIbiZll', 'sffRjxJRxt', 'MkoR5DA9gu', 'rUrRVdnW5f', 'rFhRq1NYIh', 'h4aRGd5qeC' |
Source: 1.2.SOA-Al Daleel.exe.4457ff0.3.raw.unpack, FS4WZPMtGmHZsvtoqxr.cs |
High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'OpGs0t0u2p', 'EGMsc3hQGy', 'y1FsioBIwG', 'yGPs2vPoSy', 'jlKsED5VnD', 'Hh1sWwSddW', 'vEYsHiNQt6' |
Source: 1.2.SOA-Al Daleel.exe.4457ff0.3.raw.unpack, xLnFXNr3HFxaLKS95p.cs |
High entropy of concatenated method names: 'H2tqPfQ5NC', 'ROfqj5oVNJ', 'kGXqVgnKSj', 'VQbVmawvla', 'TVZVzro6JV', 'bGuqKjlXm4', 'IJ6qMeWbdy', 'V6hqYMe6Wo', 'cbSqtgm584', 'vkHqn6OPDE' |
Source: 1.2.SOA-Al Daleel.exe.4457ff0.3.raw.unpack, WpTrCDeRd6UKSRIBf0.cs |
High entropy of concatenated method names: 'KKw5NqH0jc', 'dF65x4J3D5', 'pmjj6Em8FG', 'a5Yj9PFkuV', 'FlIjU3pqOb', 'zywjT0EKX1', 'owgjrMyjRp', 'IWTjAVSa8C', 'idHjDx1akG', 'VqXjQImgBV' |
Source: 1.2.SOA-Al Daleel.exe.4457ff0.3.raw.unpack, mRTYIxOiui1rh23kdo.cs |
High entropy of concatenated method names: 'UfxwPnjyMD', 'z6awIQMqKZ', 'BjHwjpqwOt', 'C46w5wZYqZ', 'WgcwVtCHZ8', 'MHtwqReAx0', 'roJwGrIOYm', 'ARDwScggQa', 'I7PwJ5vbSp', 'EynwgbV2i5' |
Source: 1.2.SOA-Al Daleel.exe.4457ff0.3.raw.unpack, hYU3HGMKWv8bkPWU6ax.cs |
High entropy of concatenated method names: 'DqBC4bdBc1', 'G1HCosUVyR', 'PuEC1T1xbG', 'yCXC8DnlUO', 'vueCNkxMJS', 'gRnCZwqSxF', 'rdHCx1mcax', 'bptCp2CcLH', 'MDMCBduhj7', 'PgdCejNSg3' |
Source: 1.2.SOA-Al Daleel.exe.4457ff0.3.raw.unpack, nmWwLFp6y3CsQoaaSm.cs |
High entropy of concatenated method names: 'HmII0Qj0iD', 'ysrIcIfavG', 'AMGIi6OSyM', 'UyaI2R4pQj', 'rmLIENfF5m', 'vBoIWq596Q', 'gPGIHjhlSi', 'c9cIOp0ebS', 'j8cIFjMiQS', 'OyiIm205qG' |
Source: 1.2.SOA-Al Daleel.exe.4457ff0.3.raw.unpack, NOe3SomiFjQjwIKZ19.cs |
High entropy of concatenated method names: 'pwwCMMGNRl', 'QAPCtlSaJe', 'deDCnphy84', 'IgYCPnGkSu', 'liJCIERrnG', 'MqRC5Ixl2U', 'eACCVVKvC0', 'QdbwHapMg5', 'eaiwOiYppc', 'SyJwFLCUB8' |
Source: 1.2.SOA-Al Daleel.exe.4457ff0.3.raw.unpack, bTT64qIAwoSlECeHGn.cs |
High entropy of concatenated method names: 'Dispose', 'arQMF4Qkw2', 'lQHYkem6Gi', 'VWCbbJBeIj', 'bJRMmTYIxi', 'ui1Mzrh23k', 'ProcessDialogKey', 'OoPYKX7iEk', 'MJyYMYRb1m', 'jPVYYQOe3S' |
Source: 1.2.SOA-Al Daleel.exe.4457ff0.3.raw.unpack, WX1d9xMMPbCWFZFN1bJ.cs |
High entropy of concatenated method names: 'ToString', 'xE9stCbvrV', 'rKusnBNcM6', 'vaPs7PGZrX', 'vuOsP0vo1l', 'kljsIn6Kvk', 'CbQsjShd0o', 'Hhps5m2EVY', 'AW31hKWRkDBxue9ujjw', 'kyZA0SW6BjZLNha57Em' |
Source: 1.2.SOA-Al Daleel.exe.4457ff0.3.raw.unpack, LuTWFhDqbyYGms4qGU.cs |
High entropy of concatenated method names: 'o2pq4HHOYF', 'RMsqonMdDi', 'dN1q1TOFsJ', 'Iu6q8XTHZG', 'dGpqNiW6Ny', 'iLxqZcUhyo', 'XtMqxNqAQP', 'bSOqpJ2ACZ', 'x68qBq1gyA', 'SOXqe0ryUd' |
Source: 1.2.SOA-Al Daleel.exe.4457ff0.3.raw.unpack, BFcI26iDUMvT9J3TRi.cs |
High entropy of concatenated method names: 'ToString', 'E0GXdM9HRU', 'mAcXkJotsZ', 'VcaX6jy0HS', 'Ya9X9mf835', 'MCBXUb5s86', 'd2ZXTOkVNF', 'elFXr7AWpm', 'k8oXAXCnL1', 'x1JXDwmIcX' |
Source: 1.2.SOA-Al Daleel.exe.4457ff0.3.raw.unpack, tFal2IWqM4KEuopdVU.cs |
High entropy of concatenated method names: 'LsgRObLiK0', 'BUfRmw0jrT', 'SaCwKLPviK', 'fKPwMfeCBM', 'BGFRdbNv2T', 'mAFRhkvjgl', 'CE2RLjkVGh', 'qnWR0QbHtN', 'EgcRcCDl8v', 'TOmRi2osne' |
Source: 1.2.SOA-Al Daleel.exe.4457ff0.3.raw.unpack, Q7YLY1zjDKs4A9wNqQ.cs |
High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'yggClUrEYY', 'hMdCyLCJko', 'G2jCXh7A37', 'BHiCRKMxFX', 'rRKCwAi4Am', 'PXwCCP9MxL', 'sArCs13RcM' |
Source: 1.2.SOA-Al Daleel.exe.4457ff0.3.raw.unpack, hkDdW7nnKXps9uafUV.cs |
High entropy of concatenated method names: 'X5lMqmWwLF', 'Iy3MGCsQoa', 'UO7MJj0XYh', 'lu4MgnHpTr', 'qIBMyf0dUv', 'GbpMXFjlmj', 'SZggXJ5LBlaVun6rde', 'UurvbqrwC453On0kGM', 'enqZqZhBMld2aa4SnV', 'oh3MMl6yxl' |
Source: 1.2.SOA-Al Daleel.exe.4457ff0.3.raw.unpack, PvJ5GG095hCttXfFSn.cs |
High entropy of concatenated method names: 'Dk2yQkXhvJ', 'PnWyh8pcUW', 'bpJy0xxabw', 'bp5ycTMwKL', 'NeUykt14Mn', 'yEky6L9y8H', 'sZMy92wMDr', 'CA9yU2PKq8', 'Op3yTA58m1', 'Nlbyrg6p1t' |
Source: 1.2.SOA-Al Daleel.exe.4457ff0.3.raw.unpack, KawfvEBO7j0XYhJu4n.cs |
High entropy of concatenated method names: 'MABj80TYh1', 'KEwjZKo9ZQ', 'p6fjpZuR9a', 'JJcjBdA0Sg', 'Og4jy7Q2tb', 'yCYjXt40TJ', 'cMXjRaLaGs', 'VFBjwa4Qx1', 'vlJjCNNCAy', 'rB9jsDIHHx' |
Source: 1.2.SOA-Al Daleel.exe.4457ff0.3.raw.unpack, fX7iEkFDJyYRb1mqPV.cs |
High entropy of concatenated method names: 'xGqwaJtMUf', 'tQdwk3YJhV', 'Jfiw60dadM', 'iiiw9yCdJp', 'aABw0aNRZJ', 'fqCwUL79RX', 'Next', 'Next', 'Next', 'NextBytes' |
Source: 1.2.SOA-Al Daleel.exe.4457ff0.3.raw.unpack, OUvkbpaFjlmjZtt3qe.cs |
High entropy of concatenated method names: 'n1bV7PsxsA', 'MxXVI9u9Tx', 'kgBV5aut62', 'ogmVqig8kr', 'xSLVGkkq7T', 'SxI5E5r5lw', 'Uqt5WARj8j', 'D6p5HIxtDO', 'OKp5Os5roF', 'h3D5Fmece7' |
Source: 1.2.SOA-Al Daleel.exe.4457ff0.3.raw.unpack, JHelOmGX9xBk92vdl7.cs |
High entropy of concatenated method names: 'tYNt7gPTUp', 'wH2tPynM1X', 'F1xtIfmu2q', 'yFptjdVbZn', 'GLit5jEGVq', 'U4atVklNcI', 'H6dtqAlNFV', 'rsytGbqbgU', 'QYTtSnfiFU', 'ofetJdp4RK' |
Source: 1.2.SOA-Al Daleel.exe.4457ff0.3.raw.unpack, zYcJRlYQUJlOxnn6is.cs |
High entropy of concatenated method names: 'N4q14g5iG', 'dB28oC7LP', 'a6qZb04mn', 'ihoxYgJmA', 'jgyBCCfCX', 'Seye1YUvV', 'rEkgBJ3ygkxoQR86pO', 'rAuQgYvKmUqvfnxo6p', 'iquw7GlW5', 'SuSs1Xevj' |
Source: 1.2.SOA-Al Daleel.exe.4457ff0.3.raw.unpack, cLoPfEL4mIMos0teB9.cs |
High entropy of concatenated method names: 'sqJlp5mwrG', 'U8QlBXAKeb', 'luZlaOkHIa', 'KpIlk5st04', 'ERhl9ymdeT', 'tBylULSZZJ', 'L1Nlr8jTvL', 'TT9lAo2G3A', 'sbulQQnuhK', 'iBQldgbKWh' |
Source: 1.2.SOA-Al Daleel.exe.4457ff0.3.raw.unpack, Ml3vWW25nwsS3efjZZ.cs |
High entropy of concatenated method names: 'STRRJwhDj0', 'UenRg0SYmG', 'ToString', 'LgYRPcYP3E', 'LxORIbiZll', 'sffRjxJRxt', 'MkoR5DA9gu', 'rUrRVdnW5f', 'rFhRq1NYIh', 'h4aRGd5qeC' |
Source: 1.2.SOA-Al Daleel.exe.4511010.5.raw.unpack, FS4WZPMtGmHZsvtoqxr.cs |
High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'OpGs0t0u2p', 'EGMsc3hQGy', 'y1FsioBIwG', 'yGPs2vPoSy', 'jlKsED5VnD', 'Hh1sWwSddW', 'vEYsHiNQt6' |
Source: 1.2.SOA-Al Daleel.exe.4511010.5.raw.unpack, xLnFXNr3HFxaLKS95p.cs |
High entropy of concatenated method names: 'H2tqPfQ5NC', 'ROfqj5oVNJ', 'kGXqVgnKSj', 'VQbVmawvla', 'TVZVzro6JV', 'bGuqKjlXm4', 'IJ6qMeWbdy', 'V6hqYMe6Wo', 'cbSqtgm584', 'vkHqn6OPDE' |
Source: 1.2.SOA-Al Daleel.exe.4511010.5.raw.unpack, WpTrCDeRd6UKSRIBf0.cs |
High entropy of concatenated method names: 'KKw5NqH0jc', 'dF65x4J3D5', 'pmjj6Em8FG', 'a5Yj9PFkuV', 'FlIjU3pqOb', 'zywjT0EKX1', 'owgjrMyjRp', 'IWTjAVSa8C', 'idHjDx1akG', 'VqXjQImgBV' |
Source: 1.2.SOA-Al Daleel.exe.4511010.5.raw.unpack, mRTYIxOiui1rh23kdo.cs |
High entropy of concatenated method names: 'UfxwPnjyMD', 'z6awIQMqKZ', 'BjHwjpqwOt', 'C46w5wZYqZ', 'WgcwVtCHZ8', 'MHtwqReAx0', 'roJwGrIOYm', 'ARDwScggQa', 'I7PwJ5vbSp', 'EynwgbV2i5' |
Source: 1.2.SOA-Al Daleel.exe.4511010.5.raw.unpack, hYU3HGMKWv8bkPWU6ax.cs |
High entropy of concatenated method names: 'DqBC4bdBc1', 'G1HCosUVyR', 'PuEC1T1xbG', 'yCXC8DnlUO', 'vueCNkxMJS', 'gRnCZwqSxF', 'rdHCx1mcax', 'bptCp2CcLH', 'MDMCBduhj7', 'PgdCejNSg3' |
Source: 1.2.SOA-Al Daleel.exe.4511010.5.raw.unpack, nmWwLFp6y3CsQoaaSm.cs |
High entropy of concatenated method names: 'HmII0Qj0iD', 'ysrIcIfavG', 'AMGIi6OSyM', 'UyaI2R4pQj', 'rmLIENfF5m', 'vBoIWq596Q', 'gPGIHjhlSi', 'c9cIOp0ebS', 'j8cIFjMiQS', 'OyiIm205qG' |
Source: 1.2.SOA-Al Daleel.exe.4511010.5.raw.unpack, NOe3SomiFjQjwIKZ19.cs |
High entropy of concatenated method names: 'pwwCMMGNRl', 'QAPCtlSaJe', 'deDCnphy84', 'IgYCPnGkSu', 'liJCIERrnG', 'MqRC5Ixl2U', 'eACCVVKvC0', 'QdbwHapMg5', 'eaiwOiYppc', 'SyJwFLCUB8' |
Source: 1.2.SOA-Al Daleel.exe.4511010.5.raw.unpack, bTT64qIAwoSlECeHGn.cs |
High entropy of concatenated method names: 'Dispose', 'arQMF4Qkw2', 'lQHYkem6Gi', 'VWCbbJBeIj', 'bJRMmTYIxi', 'ui1Mzrh23k', 'ProcessDialogKey', 'OoPYKX7iEk', 'MJyYMYRb1m', 'jPVYYQOe3S' |
Source: 1.2.SOA-Al Daleel.exe.4511010.5.raw.unpack, WX1d9xMMPbCWFZFN1bJ.cs |
High entropy of concatenated method names: 'ToString', 'xE9stCbvrV', 'rKusnBNcM6', 'vaPs7PGZrX', 'vuOsP0vo1l', 'kljsIn6Kvk', 'CbQsjShd0o', 'Hhps5m2EVY', 'AW31hKWRkDBxue9ujjw', 'kyZA0SW6BjZLNha57Em' |
Source: 1.2.SOA-Al Daleel.exe.4511010.5.raw.unpack, LuTWFhDqbyYGms4qGU.cs |
High entropy of concatenated method names: 'o2pq4HHOYF', 'RMsqonMdDi', 'dN1q1TOFsJ', 'Iu6q8XTHZG', 'dGpqNiW6Ny', 'iLxqZcUhyo', 'XtMqxNqAQP', 'bSOqpJ2ACZ', 'x68qBq1gyA', 'SOXqe0ryUd' |
Source: 1.2.SOA-Al Daleel.exe.4511010.5.raw.unpack, BFcI26iDUMvT9J3TRi.cs |
High entropy of concatenated method names: 'ToString', 'E0GXdM9HRU', 'mAcXkJotsZ', 'VcaX6jy0HS', 'Ya9X9mf835', 'MCBXUb5s86', 'd2ZXTOkVNF', 'elFXr7AWpm', 'k8oXAXCnL1', 'x1JXDwmIcX' |
Source: 1.2.SOA-Al Daleel.exe.4511010.5.raw.unpack, tFal2IWqM4KEuopdVU.cs |
High entropy of concatenated method names: 'LsgRObLiK0', 'BUfRmw0jrT', 'SaCwKLPviK', 'fKPwMfeCBM', 'BGFRdbNv2T', 'mAFRhkvjgl', 'CE2RLjkVGh', 'qnWR0QbHtN', 'EgcRcCDl8v', 'TOmRi2osne' |
Source: 1.2.SOA-Al Daleel.exe.4511010.5.raw.unpack, Q7YLY1zjDKs4A9wNqQ.cs |
High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'yggClUrEYY', 'hMdCyLCJko', 'G2jCXh7A37', 'BHiCRKMxFX', 'rRKCwAi4Am', 'PXwCCP9MxL', 'sArCs13RcM' |
Source: 1.2.SOA-Al Daleel.exe.4511010.5.raw.unpack, hkDdW7nnKXps9uafUV.cs |
High entropy of concatenated method names: 'X5lMqmWwLF', 'Iy3MGCsQoa', 'UO7MJj0XYh', 'lu4MgnHpTr', 'qIBMyf0dUv', 'GbpMXFjlmj', 'SZggXJ5LBlaVun6rde', 'UurvbqrwC453On0kGM', 'enqZqZhBMld2aa4SnV', 'oh3MMl6yxl' |
Source: 1.2.SOA-Al Daleel.exe.4511010.5.raw.unpack, PvJ5GG095hCttXfFSn.cs |
High entropy of concatenated method names: 'Dk2yQkXhvJ', 'PnWyh8pcUW', 'bpJy0xxabw', 'bp5ycTMwKL', 'NeUykt14Mn', 'yEky6L9y8H', 'sZMy92wMDr', 'CA9yU2PKq8', 'Op3yTA58m1', 'Nlbyrg6p1t' |
Source: 1.2.SOA-Al Daleel.exe.4511010.5.raw.unpack, KawfvEBO7j0XYhJu4n.cs |
High entropy of concatenated method names: 'MABj80TYh1', 'KEwjZKo9ZQ', 'p6fjpZuR9a', 'JJcjBdA0Sg', 'Og4jy7Q2tb', 'yCYjXt40TJ', 'cMXjRaLaGs', 'VFBjwa4Qx1', 'vlJjCNNCAy', 'rB9jsDIHHx' |
Source: 1.2.SOA-Al Daleel.exe.4511010.5.raw.unpack, fX7iEkFDJyYRb1mqPV.cs |
High entropy of concatenated method names: 'xGqwaJtMUf', 'tQdwk3YJhV', 'Jfiw60dadM', 'iiiw9yCdJp', 'aABw0aNRZJ', 'fqCwUL79RX', 'Next', 'Next', 'Next', 'NextBytes' |
Source: 1.2.SOA-Al Daleel.exe.4511010.5.raw.unpack, OUvkbpaFjlmjZtt3qe.cs |
High entropy of concatenated method names: 'n1bV7PsxsA', 'MxXVI9u9Tx', 'kgBV5aut62', 'ogmVqig8kr', 'xSLVGkkq7T', 'SxI5E5r5lw', 'Uqt5WARj8j', 'D6p5HIxtDO', 'OKp5Os5roF', 'h3D5Fmece7' |
Source: 1.2.SOA-Al Daleel.exe.4511010.5.raw.unpack, JHelOmGX9xBk92vdl7.cs |
High entropy of concatenated method names: 'tYNt7gPTUp', 'wH2tPynM1X', 'F1xtIfmu2q', 'yFptjdVbZn', 'GLit5jEGVq', 'U4atVklNcI', 'H6dtqAlNFV', 'rsytGbqbgU', 'QYTtSnfiFU', 'ofetJdp4RK' |
Source: 1.2.SOA-Al Daleel.exe.4511010.5.raw.unpack, zYcJRlYQUJlOxnn6is.cs |
High entropy of concatenated method names: 'N4q14g5iG', 'dB28oC7LP', 'a6qZb04mn', 'ihoxYgJmA', 'jgyBCCfCX', 'Seye1YUvV', 'rEkgBJ3ygkxoQR86pO', 'rAuQgYvKmUqvfnxo6p', 'iquw7GlW5', 'SuSs1Xevj' |
Source: 1.2.SOA-Al Daleel.exe.4511010.5.raw.unpack, cLoPfEL4mIMos0teB9.cs |
High entropy of concatenated method names: 'sqJlp5mwrG', 'U8QlBXAKeb', 'luZlaOkHIa', 'KpIlk5st04', 'ERhl9ymdeT', 'tBylULSZZJ', 'L1Nlr8jTvL', 'TT9lAo2G3A', 'sbulQQnuhK', 'iBQldgbKWh' |
Source: 1.2.SOA-Al Daleel.exe.4511010.5.raw.unpack, Ml3vWW25nwsS3efjZZ.cs |
High entropy of concatenated method names: 'STRRJwhDj0', 'UenRg0SYmG', 'ToString', 'LgYRPcYP3E', 'LxORIbiZll', 'sffRjxJRxt', 'MkoR5DA9gu', 'rUrRVdnW5f', 'rFhRq1NYIh', 'h4aRGd5qeC' |
Source: C:\Users\user\Desktop\SOA-Al Daleel.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\SOA-Al Daleel.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\SOA-Al Daleel.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\SOA-Al Daleel.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\SOA-Al Daleel.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\SOA-Al Daleel.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\SOA-Al Daleel.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\SOA-Al Daleel.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\SOA-Al Daleel.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\SOA-Al Daleel.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\SOA-Al Daleel.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\SOA-Al Daleel.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\SOA-Al Daleel.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\SOA-Al Daleel.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\SOA-Al Daleel.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\SOA-Al Daleel.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\SOA-Al Daleel.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\SOA-Al Daleel.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\SOA-Al Daleel.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\SOA-Al Daleel.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\SOA-Al Daleel.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\SOA-Al Daleel.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\SOA-Al Daleel.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\SOA-Al Daleel.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\SOA-Al Daleel.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\SOA-Al Daleel.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\SOA-Al Daleel.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\SOA-Al Daleel.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\SOA-Al Daleel.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\SOA-Al Daleel.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\SOA-Al Daleel.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\SOA-Al Daleel.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\SOA-Al Daleel.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\SOA-Al Daleel.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\SOA-Al Daleel.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\SOA-Al Daleel.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\SOA-Al Daleel.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\SOA-Al Daleel.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\SOA-Al Daleel.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\SOA-Al Daleel.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\SOA-Al Daleel.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\SOA-Al Daleel.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\SOA-Al Daleel.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\SOA-Al Daleel.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\SOA-Al Daleel.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\SOA-Al Daleel.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eeXxnIpy.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eeXxnIpy.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eeXxnIpy.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eeXxnIpy.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eeXxnIpy.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eeXxnIpy.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eeXxnIpy.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eeXxnIpy.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eeXxnIpy.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eeXxnIpy.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eeXxnIpy.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eeXxnIpy.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eeXxnIpy.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eeXxnIpy.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eeXxnIpy.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eeXxnIpy.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eeXxnIpy.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eeXxnIpy.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eeXxnIpy.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eeXxnIpy.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eeXxnIpy.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eeXxnIpy.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eeXxnIpy.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eeXxnIpy.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eeXxnIpy.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eeXxnIpy.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eeXxnIpy.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eeXxnIpy.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eeXxnIpy.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eeXxnIpy.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eeXxnIpy.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eeXxnIpy.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eeXxnIpy.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eeXxnIpy.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eeXxnIpy.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eeXxnIpy.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eeXxnIpy.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eeXxnIpy.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eeXxnIpy.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eeXxnIpy.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eeXxnIpy.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eeXxnIpy.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eeXxnIpy.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\SOA-Al Daleel.exe TID: 7560 |
Thread sleep time: -922337203685477s >= -30000s |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe TID: 7968 |
Thread sleep time: -4611686018427385s >= -30000s |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 8008 |
Thread sleep time: -14757395258967632s >= -30000s |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 8008 |
Thread sleep time: -100000s >= -30000s |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 8008 |
Thread sleep time: -99858s >= -30000s |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 8024 |
Thread sleep count: 1480 > 30 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 8024 |
Thread sleep count: 2701 > 30 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 8008 |
Thread sleep time: -99749s >= -30000s |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 8008 |
Thread sleep time: -99638s >= -30000s |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 8008 |
Thread sleep time: -99529s >= -30000s |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 8008 |
Thread sleep time: -99419s >= -30000s |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 8008 |
Thread sleep time: -99312s >= -30000s |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 8008 |
Thread sleep time: -99203s >= -30000s |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 8008 |
Thread sleep time: -99094s >= -30000s |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 8008 |
Thread sleep time: -98984s >= -30000s |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 8008 |
Thread sleep time: -98875s >= -30000s |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 8008 |
Thread sleep time: -98765s >= -30000s |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 8008 |
Thread sleep time: -98656s >= -30000s |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 8008 |
Thread sleep time: -98544s >= -30000s |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 8008 |
Thread sleep time: -98437s >= -30000s |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 8008 |
Thread sleep time: -98328s >= -30000s |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 8008 |
Thread sleep time: -98219s >= -30000s |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 8008 |
Thread sleep time: -98094s >= -30000s |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 8008 |
Thread sleep time: -97984s >= -30000s |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 8008 |
Thread sleep time: -97874s >= -30000s |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 8008 |
Thread sleep time: -97765s >= -30000s |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 8008 |
Thread sleep time: -97656s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eeXxnIpy.exe TID: 8088 |
Thread sleep time: -922337203685477s >= -30000s |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 6820 |
Thread sleep time: -17524406870024063s >= -30000s |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 6820 |
Thread sleep time: -100000s >= -30000s |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 6608 |
Thread sleep count: 1761 > 30 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 6820 |
Thread sleep time: -99844s >= -30000s |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 6608 |
Thread sleep count: 2515 > 30 |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 6820 |
Thread sleep time: -99734s >= -30000s |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 6820 |
Thread sleep time: -99625s >= -30000s |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 6820 |
Thread sleep time: -99495s >= -30000s |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 6820 |
Thread sleep time: -99389s >= -30000s |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 6820 |
Thread sleep time: -99281s >= -30000s |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 6820 |
Thread sleep time: -99135s >= -30000s |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 6820 |
Thread sleep time: -99025s >= -30000s |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 6820 |
Thread sleep time: -98916s >= -30000s |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 6820 |
Thread sleep time: -98800s >= -30000s |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 6820 |
Thread sleep time: -98594s >= -30000s |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 6820 |
Thread sleep time: -98457s >= -30000s |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 6820 |
Thread sleep time: -98132s >= -30000s |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 6820 |
Thread sleep time: -97737s >= -30000s |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 6820 |
Thread sleep time: -97609s >= -30000s |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 6820 |
Thread sleep time: -97498s >= -30000s |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 6820 |
Thread sleep time: -97391s >= -30000s |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 6820 |
Thread sleep time: -97281s >= -30000s |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 6820 |
Thread sleep time: -97170s >= -30000s |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 6820 |
Thread sleep time: -97044s >= -30000s |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 6820 |
Thread sleep time: -96937s >= -30000s |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 6820 |
Thread sleep time: -922337203685477s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\SOA-Al Daleel.exe |
Queries volume information: C:\Users\user\Desktop\SOA-Al Daleel.exe VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\SOA-Al Daleel.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\SOA-Al Daleel.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\SOA-Al Daleel.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\SOA-Al Daleel.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\ VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-GroupPolicy-ClientTools-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-AppManagement-AppV-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\Microsoft.Management.Infrastructure.Native\v4.0_1.0.0.0__31bf3856ad364e35\Microsoft.Management.Infrastructure.Native.dll VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\AppvClient\Microsoft.AppV.AppVClientPowerShell.dll VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1865.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-WOW64-Package~31bf3856ad364e35~amd64~en-GB~10.0.19041.1.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\BitLocker\Microsoft.BitLocker.Structures.dll VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management\v4.0_3.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Management.dll VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Queries volume information: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe VolumeInformation |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Security\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Security.dll VolumeInformation |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eeXxnIpy.exe |
Queries volume information: C:\Users\user\AppData\Roaming\eeXxnIpy.exe VolumeInformation |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eeXxnIpy.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eeXxnIpy.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eeXxnIpy.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\eeXxnIpy.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Queries volume information: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe VolumeInformation |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Security\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Security.dll VolumeInformation |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation |
Jump to behavior |