Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 4x nop then jmp 0015FA39h |
6_2_0015F778 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 4x nop then mov dword ptr [ebp-14h], 00000000h |
6_2_0015E005 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 4x nop then jmp 0015E61Fh |
6_2_0015E431 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 4x nop then jmp 0015EFA9h |
6_2_0015E431 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 4x nop then mov dword ptr [ebp-14h], 00000000h |
6_2_0015D7F0 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 4x nop then mov dword ptr [ebp-14h], 00000000h |
6_2_0015DE23 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 4x nop then jmp 20CB15D8h |
6_2_20CB11C0 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 4x nop then jmp 20CB1011h |
6_2_20CB0D60 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 4x nop then jmp 20CBFB81h |
6_2_20CBF8D8 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 4x nop then jmp 20CBF729h |
6_2_20CBF480 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 4x nop then jmp 20CB0751h |
6_2_20CB04A0 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 4x nop then jmp 20CBC761h |
6_2_20CBC4B8 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 4x nop then jmp 20CB02F1h |
6_2_20CB0040 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 4x nop then jmp 20CBC309h |
6_2_20CBC060 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 4x nop then jmp 20CBBEB1h |
6_2_20CBBC08 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 4x nop then jmp 20CBF2D1h |
6_2_20CBF028 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 4x nop then jmp 20CBD469h |
6_2_20CBD1C0 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 4x nop then jmp 20CB15D8h |
6_2_20CB11B0 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 4x nop then jmp 20CBD011h |
6_2_20CBCD68 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 4x nop then jmp 20CB0BB1h |
6_2_20CB0900 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 4x nop then jmp 20CB15D8h |
6_2_20CB1506 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 4x nop then jmp 20CBCBB9h |
6_2_20CBC910 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 4x nop then jmp 20CBE171h |
6_2_20CBDEC8 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 4x nop then jmp 20CBDD19h |
6_2_20CBDA70 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 4x nop then jmp 20CBD8C1h |
6_2_20CBD618 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 4x nop then jmp 20CBEE79h |
6_2_20CBEBD0 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 4x nop then jmp 20CBBA59h |
6_2_20CBB7B0 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 4x nop then jmp 20CBB601h |
6_2_20CBB358 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 4x nop then jmp 20CBEA21h |
6_2_20CBE778 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 4x nop then jmp 20CBB1A9h |
6_2_20CBAF00 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 4x nop then jmp 20CBE5C9h |
6_2_20CBE320 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 4x nop then jmp 238288EDh |
6_2_238285B0 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 4x nop then jmp 23820741h |
6_2_23820498 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 4x nop then jmp 238272A2h |
6_2_23826FF8 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 4x nop then jmp 238269C9h |
6_2_23826720 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 4x nop then lea esp, dword ptr [ebp-04h] |
6_2_23823350 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 4x nop then lea esp, dword ptr [ebp-04h] |
6_2_23823360 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 4x nop then jmp 23826E21h |
6_2_23826B78 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 4x nop then jmp 23826571h |
6_2_238262C8 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 4x nop then jmp 23825CC1h |
6_2_23825A18 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 4x nop then jmp 23826119h |
6_2_23825E70 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 4x nop then jmp 23825869h |
6_2_238255C0 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 4x nop then jmp 23827FA9h |
6_2_23827D00 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 4x nop then jmp 238253E9h |
6_2_23825140 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 4x nop then jmp 23828401h |
6_2_23828158 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 4x nop then jmp 23827B51h |
6_2_238278A8 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 4x nop then jmp 23820B99h |
6_2_238208F0 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 4x nop then jmp 238202E9h |
6_2_23820040 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 4x nop then jmp 238276F9h |
6_2_23827450 |
Source: Contentious.exe, 00000006.00000002.2944378842.0000000021067000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://api.telegram.org |
Source: Contentious.exe, 00000006.00000002.2944378842.0000000020F9C000.00000004.00000800.00020000.00000000.sdmp, Contentious.exe, 00000006.00000002.2944378842.0000000020F53000.00000004.00000800.00020000.00000000.sdmp, Contentious.exe, 00000006.00000002.2944378842.0000000020F45000.00000004.00000800.00020000.00000000.sdmp, Contentious.exe, 00000006.00000002.2944378842.0000000020F38000.00000004.00000800.00020000.00000000.sdmp, Contentious.exe, 00000006.00000002.2944378842.0000000020EA5000.00000004.00000800.00020000.00000000.sdmp, Contentious.exe, 00000006.00000002.2944378842.0000000020F60000.00000004.00000800.00020000.00000000.sdmp, Contentious.exe, 00000006.00000002.2944378842.0000000020F8D000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://checkip.dyndns.com |
Source: Contentious.exe, 00000006.00000002.2944378842.0000000020F9C000.00000004.00000800.00020000.00000000.sdmp, Contentious.exe, 00000006.00000002.2944378842.0000000020EE8000.00000004.00000800.00020000.00000000.sdmp, Contentious.exe, 00000006.00000002.2944378842.0000000020F6E000.00000004.00000800.00020000.00000000.sdmp, Contentious.exe, 00000006.00000002.2944378842.0000000020F53000.00000004.00000800.00020000.00000000.sdmp, Contentious.exe, 00000006.00000002.2944378842.0000000020F45000.00000004.00000800.00020000.00000000.sdmp, Contentious.exe, 00000006.00000002.2944378842.0000000020F38000.00000004.00000800.00020000.00000000.sdmp, Contentious.exe, 00000006.00000002.2944378842.0000000020E99000.00000004.00000800.00020000.00000000.sdmp, Contentious.exe, 00000006.00000002.2944378842.0000000020EA5000.00000004.00000800.00020000.00000000.sdmp, Contentious.exe, 00000006.00000002.2944378842.0000000020F60000.00000004.00000800.00020000.00000000.sdmp, Contentious.exe, 00000006.00000002.2944378842.0000000020F8D000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://checkip.dyndns.org |
Source: Contentious.exe, 00000006.00000002.2944378842.0000000020DE1000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://checkip.dyndns.org/ |
Source: powershell.exe, 00000001.00000002.2177929958.0000000006E21000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://crl.m |
Source: Torpernes.exe, Contentious.exe.1.dr |
String found in binary or memory: http://nsis.sf.net/NSIS_ErrorError |
Source: powershell.exe, 00000001.00000002.2173904529.000000000568D000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://nuget.org/NuGet.exe |
Source: powershell.exe, 00000001.00000002.2171178295.0000000004776000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://pesterbdd.com/images/Pester.png |
Source: Contentious.exe, 00000006.00000002.2944378842.0000000020EBD000.00000004.00000800.00020000.00000000.sdmp, Contentious.exe, 00000006.00000002.2944378842.0000000020F9C000.00000004.00000800.00020000.00000000.sdmp, Contentious.exe, 00000006.00000002.2944378842.0000000020F53000.00000004.00000800.00020000.00000000.sdmp, Contentious.exe, 00000006.00000002.2944378842.0000000020F45000.00000004.00000800.00020000.00000000.sdmp, Contentious.exe, 00000006.00000002.2944378842.0000000020F38000.00000004.00000800.00020000.00000000.sdmp, Contentious.exe, 00000006.00000002.2944378842.0000000020F60000.00000004.00000800.00020000.00000000.sdmp, Contentious.exe, 00000006.00000002.2944378842.0000000020F8D000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://reallyfreegeoip.org |
Source: powershell.exe, 00000001.00000002.2171178295.0000000004621000.00000004.00000800.00020000.00000000.sdmp, Contentious.exe, 00000006.00000002.2944378842.0000000020DE1000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name |
Source: powershell.exe, 00000001.00000002.2171178295.0000000004776000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://www.apache.org/licenses/LICENSE-2.0.html |
Source: powershell.exe, 00000001.00000002.2171178295.0000000004621000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://aka.ms/pscore6lB |
Source: Contentious.exe, 00000006.00000002.2944378842.0000000021067000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://api.telegram.org |
Source: Contentious.exe, 00000006.00000002.2944378842.0000000021067000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://api.telegram.org/bot |
Source: Contentious.exe, 00000006.00000002.2944378842.0000000021067000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://api.telegram.org/bot7233802065:AAGhMGPQ0nLoLP2hx7_EW3TbcrrzChgxpJA/sendDocument?chat_id=5811 |
Source: powershell.exe, 00000001.00000002.2173904529.000000000568D000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://contoso.com/ |
Source: powershell.exe, 00000001.00000002.2173904529.000000000568D000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://contoso.com/Icon |
Source: powershell.exe, 00000001.00000002.2173904529.000000000568D000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://contoso.com/License |
Source: Contentious.exe, 00000006.00000002.2928735040.0000000004A54000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://domzeleni.kz/ |
Source: Contentious.exe, 00000006.00000002.2943257213.00000000205A0000.00000004.00001000.00020000.00000000.sdmp, Contentious.exe, 00000006.00000002.2928735040.0000000004A54000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://domzeleni.kz/image/bwSNbczRiJIuD15.bin |
Source: Contentious.exe, 00000006.00000002.2928735040.0000000004A19000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://domzeleni.kz/image/bwSNbczRiJIuD15.binB |
Source: powershell.exe, 00000001.00000002.2171178295.0000000004776000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://github.com/Pester/Pester |
Source: powershell.exe, 00000001.00000002.2173904529.000000000568D000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://nuget.org/nuget.exe |
Source: Contentious.exe, 00000006.00000002.2944378842.0000000020F9C000.00000004.00000800.00020000.00000000.sdmp, Contentious.exe, 00000006.00000002.2944378842.0000000020EE8000.00000004.00000800.00020000.00000000.sdmp, Contentious.exe, 00000006.00000002.2944378842.0000000020F53000.00000004.00000800.00020000.00000000.sdmp, Contentious.exe, 00000006.00000002.2944378842.0000000020F45000.00000004.00000800.00020000.00000000.sdmp, Contentious.exe, 00000006.00000002.2944378842.0000000020F38000.00000004.00000800.00020000.00000000.sdmp, Contentious.exe, 00000006.00000002.2944378842.0000000020EA5000.00000004.00000800.00020000.00000000.sdmp, Contentious.exe, 00000006.00000002.2944378842.0000000020F60000.00000004.00000800.00020000.00000000.sdmp, Contentious.exe, 00000006.00000002.2944378842.0000000020F8D000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://reallyfreegeoip.org |
Source: Contentious.exe, 00000006.00000002.2944378842.0000000020EA5000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://reallyfreegeoip.org/xml/ |
Source: Contentious.exe, 00000006.00000002.2944378842.0000000020F8D000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://reallyfreegeoip.org/xml/8.46.123.33 |
Source: Contentious.exe, 00000006.00000002.2944378842.0000000020F9C000.00000004.00000800.00020000.00000000.sdmp, Contentious.exe, 00000006.00000002.2944378842.0000000020EE8000.00000004.00000800.00020000.00000000.sdmp, Contentious.exe, 00000006.00000002.2944378842.0000000020F53000.00000004.00000800.00020000.00000000.sdmp, Contentious.exe, 00000006.00000002.2944378842.0000000020F45000.00000004.00000800.00020000.00000000.sdmp, Contentious.exe, 00000006.00000002.2944378842.0000000020F38000.00000004.00000800.00020000.00000000.sdmp, Contentious.exe, 00000006.00000002.2944378842.0000000020F60000.00000004.00000800.00020000.00000000.sdmp, Contentious.exe, 00000006.00000002.2944378842.0000000020F8D000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://reallyfreegeoip.org/xml/8.46.123.33$ |
Source: C:\Users\user\Desktop\Torpernes.exe |
Code function: 0_2_0040646E |
0_2_0040646E |
Source: C:\Users\user\Desktop\Torpernes.exe |
Code function: 0_2_00404A3D |
0_2_00404A3D |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Code function: 1_2_0457EAD8 |
1_2_0457EAD8 |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Code function: 1_2_0457F3A8 |
1_2_0457F3A8 |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Code function: 1_2_0457E790 |
1_2_0457E790 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_0040646E |
6_2_0040646E |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_00404A3D |
6_2_00404A3D |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_00156108 |
6_2_00156108 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_0015C190 |
6_2_0015C190 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_0015B328 |
6_2_0015B328 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_0015C473 |
6_2_0015C473 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_00156730 |
6_2_00156730 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_0015C754 |
6_2_0015C754 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_0015F778 |
6_2_0015F778 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_00159858 |
6_2_00159858 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_0015CA34 |
6_2_0015CA34 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_00154AD9 |
6_2_00154AD9 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_0015BBBA |
6_2_0015BBBA |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_0015BEB7 |
6_2_0015BEB7 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_0015E431 |
6_2_0015E431 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_00153578 |
6_2_00153578 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_0015D7F0 |
6_2_0015D7F0 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_0015D7E0 |
6_2_0015D7E0 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_2042B0E0 |
6_2_2042B0E0 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_2042C3EC |
6_2_2042C3EC |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_20514F11 |
6_2_20514F11 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_20CB7588 |
6_2_20CB7588 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_20CB0D60 |
6_2_20CB0D60 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_20CB3288 |
6_2_20CB3288 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_20CBF8C9 |
6_2_20CBF8C9 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_20CBF8D8 |
6_2_20CBF8D8 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_20CB08F0 |
6_2_20CB08F0 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_20CBF480 |
6_2_20CBF480 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_20CB0491 |
6_2_20CB0491 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_20CBC4A8 |
6_2_20CBC4A8 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_20CB04A0 |
6_2_20CB04A0 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_20CBC4B8 |
6_2_20CBC4B8 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_20CB0040 |
6_2_20CB0040 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_20CBC050 |
6_2_20CBC050 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_20CBC060 |
6_2_20CBC060 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_20CBF471 |
6_2_20CBF471 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_20CBBC08 |
6_2_20CBBC08 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_20CBF018 |
6_2_20CBF018 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_20CBF028 |
6_2_20CBF028 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_20CB0023 |
6_2_20CB0023 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_20CBD1C0 |
6_2_20CBD1C0 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_20CB6DF7 |
6_2_20CB6DF7 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_20CBD1B0 |
6_2_20CBD1B0 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_20CBCD58 |
6_2_20CBCD58 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_20CB0D50 |
6_2_20CB0D50 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_20CBCD68 |
6_2_20CBCD68 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_20CBC901 |
6_2_20CBC901 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_20CB0900 |
6_2_20CB0900 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_20CBC910 |
6_2_20CBC910 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_20CB4924 |
6_2_20CB4924 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_20CBDEC8 |
6_2_20CBDEC8 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_20CBAEEF |
6_2_20CBAEEF |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_20CB3284 |
6_2_20CB3284 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_20CBDEB8 |
6_2_20CBDEB8 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_20CBDA61 |
6_2_20CBDA61 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_20CB7E78 |
6_2_20CB7E78 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_20CBDA70 |
6_2_20CBDA70 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_20CBD609 |
6_2_20CBD609 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_20CB6E00 |
6_2_20CB6E00 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_20CBD618 |
6_2_20CBD618 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_20CBEBC1 |
6_2_20CBEBC1 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_20CBEBD0 |
6_2_20CBEBD0 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_20CBBBF8 |
6_2_20CBBBF8 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_20CB77A8 |
6_2_20CB77A8 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_20CBB7A0 |
6_2_20CBB7A0 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_20CBB7B0 |
6_2_20CBB7B0 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_20CBB348 |
6_2_20CBB348 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_20CBB358 |
6_2_20CBB358 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_20CBE768 |
6_2_20CBE768 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_20CBE778 |
6_2_20CBE778 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_20CBAF00 |
6_2_20CBAF00 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_20CBE310 |
6_2_20CBE310 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_20CBE320 |
6_2_20CBE320 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_23829FB0 |
6_2_23829FB0 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_2382CBD0 |
6_2_2382CBD0 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_23828B00 |
6_2_23828B00 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_2382BF30 |
6_2_2382BF30 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_2382B290 |
6_2_2382B290 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_238236D8 |
6_2_238236D8 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_2382A600 |
6_2_2382A600 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_2382D218 |
6_2_2382D218 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_2382DA48 |
6_2_2382DA48 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_2382C580 |
6_2_2382C580 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_238285B0 |
6_2_238285B0 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_23820D48 |
6_2_23820D48 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_23820498 |
6_2_23820498 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_2382B8E0 |
6_2_2382B8E0 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_2382AC48 |
6_2_2382AC48 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_23829FA0 |
6_2_23829FA0 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_2382CBC0 |
6_2_2382CBC0 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_238243D8 |
6_2_238243D8 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_23826FE8 |
6_2_23826FE8 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_23826FF8 |
6_2_23826FF8 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_23826713 |
6_2_23826713 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_23826720 |
6_2_23826720 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_2382BF20 |
6_2_2382BF20 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_23823350 |
6_2_23823350 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_23823360 |
6_2_23823360 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_23826B69 |
6_2_23826B69 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_23826B78 |
6_2_23826B78 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_2382B281 |
6_2_2382B281 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_238262B8 |
6_2_238262B8 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_238262C8 |
6_2_238262C8 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_2382D20A |
6_2_2382D20A |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_23825A08 |
6_2_23825A08 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_23825A18 |
6_2_23825A18 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_23825E60 |
6_2_23825E60 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_23825E70 |
6_2_23825E70 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_238285A0 |
6_2_238285A0 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_238255B1 |
6_2_238255B1 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_238255C0 |
6_2_238255C0 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_2382A5F0 |
6_2_2382A5F0 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_23827D00 |
6_2_23827D00 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_23825138 |
6_2_23825138 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_23825140 |
6_2_23825140 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_23828148 |
6_2_23828148 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_23828158 |
6_2_23828158 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_2382C570 |
6_2_2382C570 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_23820488 |
6_2_23820488 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_23827898 |
6_2_23827898 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_238278A8 |
6_2_238278A8 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_2382B8D0 |
6_2_2382B8D0 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_238208E1 |
6_2_238208E1 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_238208F0 |
6_2_238208F0 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_23827CF0 |
6_2_23827CF0 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_23820007 |
6_2_23820007 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_2382AC37 |
6_2_2382AC37 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_2382743F |
6_2_2382743F |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_23820040 |
6_2_23820040 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_23822848 |
6_2_23822848 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_23827450 |
6_2_23827450 |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Code function: 6_2_23822858 |
6_2_23822858 |
Source: C:\Users\user\Desktop\Torpernes.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Torpernes.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Torpernes.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Torpernes.exe |
Section loaded: shfolder.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Torpernes.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Torpernes.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Torpernes.exe |
Section loaded: propsys.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Torpernes.exe |
Section loaded: riched20.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Torpernes.exe |
Section loaded: usp10.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Torpernes.exe |
Section loaded: msls31.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Torpernes.exe |
Section loaded: textinputframework.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Torpernes.exe |
Section loaded: coreuicomponents.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Torpernes.exe |
Section loaded: coremessaging.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Torpernes.exe |
Section loaded: ntmarta.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Torpernes.exe |
Section loaded: coremessaging.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Torpernes.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Torpernes.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Torpernes.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Torpernes.exe |
Section loaded: textshaping.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Torpernes.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: atl.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: mscoree.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: vcruntime140_clr0400.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: cryptsp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: rsaenh.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: cryptbase.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: msasn1.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: gpapi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: amsi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: msisip.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: wshext.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: appxsip.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: opcservices.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: secur32.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: wbemcomn.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: napinsp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: pnrpnsp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: wshbth.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: nlaapi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: iphlpapi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: mswsock.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: dnsapi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: winrnr.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: fwpuclnt.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: rasadhlp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: ntmarta.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Section loaded: propsys.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Section loaded: edputil.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Section loaded: urlmon.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Section loaded: iertutil.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Section loaded: srvcli.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Section loaded: netutils.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Section loaded: windows.staterepositoryps.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Section loaded: appresolver.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Section loaded: bcp47langs.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Section loaded: slc.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Section loaded: sppc.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Section loaded: onecorecommonproxystub.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Section loaded: onecoreuapcommonproxystub.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Section loaded: wininet.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Section loaded: ondemandconnroutehelper.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Section loaded: winhttp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Section loaded: mswsock.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Section loaded: iphlpapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Section loaded: winnsi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Section loaded: dnsapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Section loaded: rasadhlp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Section loaded: fwpuclnt.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Section loaded: schannel.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Section loaded: mskeyprotect.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Section loaded: ntasn1.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Section loaded: msasn1.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Section loaded: dpapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Section loaded: cryptsp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Section loaded: rsaenh.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Section loaded: cryptbase.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Section loaded: gpapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Section loaded: ncrypt.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Section loaded: ncryptsslp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Section loaded: mscoree.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Section loaded: vcruntime140_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Section loaded: rasapi32.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Section loaded: rasman.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Section loaded: rtutils.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Section loaded: dhcpcsvc6.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Section loaded: dhcpcsvc.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Section loaded: secur32.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\Torpernes.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Thread delayed: delay time: 922337203685477 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Thread delayed: delay time: 922337203685477 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Thread delayed: delay time: 600000 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Thread delayed: delay time: 599890 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Thread delayed: delay time: 599771 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Thread delayed: delay time: 599652 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Thread delayed: delay time: 599534 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Thread delayed: delay time: 599401 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Thread delayed: delay time: 599281 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Thread delayed: delay time: 599172 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Thread delayed: delay time: 599062 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Thread delayed: delay time: 598947 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Thread delayed: delay time: 598837 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Thread delayed: delay time: 598680 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Thread delayed: delay time: 598562 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Thread delayed: delay time: 598453 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Thread delayed: delay time: 598343 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Thread delayed: delay time: 598234 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Thread delayed: delay time: 598117 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Thread delayed: delay time: 598000 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Thread delayed: delay time: 597890 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Thread delayed: delay time: 597774 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Thread delayed: delay time: 597656 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Thread delayed: delay time: 597546 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Thread delayed: delay time: 597434 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Thread delayed: delay time: 597328 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Thread delayed: delay time: 597219 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Thread delayed: delay time: 597101 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Thread delayed: delay time: 596984 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Thread delayed: delay time: 596875 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Thread delayed: delay time: 596765 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Thread delayed: delay time: 596656 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Thread delayed: delay time: 596546 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Thread delayed: delay time: 596437 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Thread delayed: delay time: 596327 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Thread delayed: delay time: 596219 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Thread delayed: delay time: 596102 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Thread delayed: delay time: 595984 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Thread delayed: delay time: 595872 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Thread delayed: delay time: 595764 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Thread delayed: delay time: 595655 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Thread delayed: delay time: 595522 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Thread delayed: delay time: 595348 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Thread delayed: delay time: 595219 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Thread delayed: delay time: 595075 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Thread delayed: delay time: 594968 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Thread delayed: delay time: 594859 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Thread delayed: delay time: 594750 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Thread delayed: delay time: 594640 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Thread delayed: delay time: 594531 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Thread delayed: delay time: 594421 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Thread delayed: delay time: 594233 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Thread delayed: delay time: 594125 |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe TID: 7604 |
Thread sleep time: -3689348814741908s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe TID: 7180 |
Thread sleep time: -25825441703193356s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe TID: 7180 |
Thread sleep time: -600000s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe TID: 7192 |
Thread sleep count: 3788 > 30 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe TID: 7180 |
Thread sleep time: -599890s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe TID: 7192 |
Thread sleep count: 6044 > 30 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe TID: 7180 |
Thread sleep time: -599771s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe TID: 7180 |
Thread sleep time: -599652s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe TID: 7180 |
Thread sleep time: -599534s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe TID: 7180 |
Thread sleep time: -599401s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe TID: 7180 |
Thread sleep time: -599281s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe TID: 7180 |
Thread sleep time: -599172s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe TID: 7180 |
Thread sleep time: -599062s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe TID: 7180 |
Thread sleep time: -598947s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe TID: 7180 |
Thread sleep time: -598837s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe TID: 7180 |
Thread sleep time: -598680s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe TID: 7180 |
Thread sleep time: -598562s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe TID: 7180 |
Thread sleep time: -598453s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe TID: 7180 |
Thread sleep time: -598343s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe TID: 7180 |
Thread sleep time: -598234s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe TID: 7180 |
Thread sleep time: -598117s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe TID: 7180 |
Thread sleep time: -598000s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe TID: 7180 |
Thread sleep time: -597890s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe TID: 7180 |
Thread sleep time: -597774s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe TID: 7180 |
Thread sleep time: -597656s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe TID: 7180 |
Thread sleep time: -597546s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe TID: 7180 |
Thread sleep time: -597434s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe TID: 7180 |
Thread sleep time: -597328s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe TID: 7180 |
Thread sleep time: -597219s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe TID: 7180 |
Thread sleep time: -597101s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe TID: 7180 |
Thread sleep time: -596984s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe TID: 7180 |
Thread sleep time: -596875s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe TID: 7180 |
Thread sleep time: -596765s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe TID: 7180 |
Thread sleep time: -596656s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe TID: 7180 |
Thread sleep time: -596546s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe TID: 7180 |
Thread sleep time: -596437s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe TID: 7180 |
Thread sleep time: -596327s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe TID: 7180 |
Thread sleep time: -596219s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe TID: 7180 |
Thread sleep time: -596102s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe TID: 7180 |
Thread sleep time: -595984s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe TID: 7180 |
Thread sleep time: -595872s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe TID: 7180 |
Thread sleep time: -595764s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe TID: 7180 |
Thread sleep time: -595655s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe TID: 7180 |
Thread sleep time: -595522s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe TID: 7180 |
Thread sleep time: -595348s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe TID: 7180 |
Thread sleep time: -595219s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe TID: 7180 |
Thread sleep time: -595075s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe TID: 7180 |
Thread sleep time: -594968s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe TID: 7180 |
Thread sleep time: -594859s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe TID: 7180 |
Thread sleep time: -594750s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe TID: 7180 |
Thread sleep time: -594640s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe TID: 7180 |
Thread sleep time: -594531s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe TID: 7180 |
Thread sleep time: -594421s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe TID: 7180 |
Thread sleep time: -594233s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe TID: 7180 |
Thread sleep time: -594125s >= -30000s |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Thread delayed: delay time: 922337203685477 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Thread delayed: delay time: 922337203685477 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Thread delayed: delay time: 600000 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Thread delayed: delay time: 599890 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Thread delayed: delay time: 599771 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Thread delayed: delay time: 599652 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Thread delayed: delay time: 599534 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Thread delayed: delay time: 599401 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Thread delayed: delay time: 599281 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Thread delayed: delay time: 599172 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Thread delayed: delay time: 599062 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Thread delayed: delay time: 598947 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Thread delayed: delay time: 598837 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Thread delayed: delay time: 598680 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Thread delayed: delay time: 598562 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Thread delayed: delay time: 598453 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Thread delayed: delay time: 598343 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Thread delayed: delay time: 598234 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Thread delayed: delay time: 598117 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Thread delayed: delay time: 598000 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Thread delayed: delay time: 597890 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Thread delayed: delay time: 597774 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Thread delayed: delay time: 597656 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Thread delayed: delay time: 597546 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Thread delayed: delay time: 597434 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Thread delayed: delay time: 597328 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Thread delayed: delay time: 597219 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Thread delayed: delay time: 597101 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Thread delayed: delay time: 596984 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Thread delayed: delay time: 596875 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Thread delayed: delay time: 596765 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Thread delayed: delay time: 596656 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Thread delayed: delay time: 596546 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Thread delayed: delay time: 596437 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Thread delayed: delay time: 596327 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Thread delayed: delay time: 596219 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Thread delayed: delay time: 596102 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Thread delayed: delay time: 595984 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Thread delayed: delay time: 595872 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Thread delayed: delay time: 595764 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Thread delayed: delay time: 595655 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Thread delayed: delay time: 595522 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Thread delayed: delay time: 595348 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Thread delayed: delay time: 595219 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Thread delayed: delay time: 595075 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Thread delayed: delay time: 594968 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Thread delayed: delay time: 594859 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Thread delayed: delay time: 594750 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Thread delayed: delay time: 594640 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Thread delayed: delay time: 594531 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Thread delayed: delay time: 594421 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Thread delayed: delay time: 594233 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Thread delayed: delay time: 594125 |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\ VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management\v4.0_3.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Management.dll VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceProcess\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Queries volume information: C:\Users\user\AppData\Local\Temp\Contentious.exe VolumeInformation |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Security\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Security.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.Extensions\v4.0_4.0.0.0__31bf3856ad364e35\System.Web.Extensions.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Contentious.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation |
Jump to behavior |