Source: Forbundsstater.exe, 00000006.00000002.2674791850.00000000215C3000.00000004.00000800.00020000.00000000.sdmp, Forbundsstater.exe, 00000006.00000002.2674791850.000000002160C000.00000004.00000800.00020000.00000000.sdmp, Forbundsstater.exe, 00000006.00000002.2674791850.00000000215B6000.00000004.00000800.00020000.00000000.sdmp, Forbundsstater.exe, 00000006.00000002.2674791850.000000002161A000.00000004.00000800.00020000.00000000.sdmp, Forbundsstater.exe, 00000006.00000002.2674791850.0000000021523000.00000004.00000800.00020000.00000000.sdmp, Forbundsstater.exe, 00000006.00000002.2674791850.00000000215D1000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://checkip.dyndns.com |
Source: Forbundsstater.exe, 00000006.00000002.2674791850.00000000215C3000.00000004.00000800.00020000.00000000.sdmp, Forbundsstater.exe, 00000006.00000002.2674791850.000000002160C000.00000004.00000800.00020000.00000000.sdmp, Forbundsstater.exe, 00000006.00000002.2674791850.0000000021566000.00000004.00000800.00020000.00000000.sdmp, Forbundsstater.exe, 00000006.00000002.2674791850.00000000215B6000.00000004.00000800.00020000.00000000.sdmp, Forbundsstater.exe, 00000006.00000002.2674791850.00000000215EC000.00000004.00000800.00020000.00000000.sdmp, Forbundsstater.exe, 00000006.00000002.2674791850.000000002161A000.00000004.00000800.00020000.00000000.sdmp, Forbundsstater.exe, 00000006.00000002.2674791850.0000000021517000.00000004.00000800.00020000.00000000.sdmp, Forbundsstater.exe, 00000006.00000002.2674791850.0000000021523000.00000004.00000800.00020000.00000000.sdmp, Forbundsstater.exe, 00000006.00000002.2674791850.00000000215D1000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://checkip.dyndns.org |
Source: Forbundsstater.exe, 00000006.00000002.2674791850.0000000021461000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://checkip.dyndns.org/ |
Source: LPO-9180155-PDF.exe, Forbundsstater.exe.2.dr |
String found in binary or memory: http://nsis.sf.net/NSIS_ErrorError |
Source: powershell.exe, 00000002.00000002.2542661803.0000000005B28000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://nuget.org/NuGet.exe |
Source: powershell.exe, 00000002.00000002.2539524436.0000000004C16000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://pesterbdd.com/images/Pester.png |
Source: Forbundsstater.exe, 00000006.00000002.2674791850.00000000215C3000.00000004.00000800.00020000.00000000.sdmp, Forbundsstater.exe, 00000006.00000002.2674791850.000000002160C000.00000004.00000800.00020000.00000000.sdmp, Forbundsstater.exe, 00000006.00000002.2674791850.000000002153B000.00000004.00000800.00020000.00000000.sdmp, Forbundsstater.exe, 00000006.00000002.2674791850.00000000215B6000.00000004.00000800.00020000.00000000.sdmp, Forbundsstater.exe, 00000006.00000002.2674791850.000000002161A000.00000004.00000800.00020000.00000000.sdmp, Forbundsstater.exe, 00000006.00000002.2674791850.00000000215D1000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://reallyfreegeoip.org |
Source: LPO-9180155-PDF.exe, Forbundsstater.exe.2.dr |
String found in binary or memory: http://s.symcb.com/universal-root.crl0 |
Source: LPO-9180155-PDF.exe, Forbundsstater.exe.2.dr |
String found in binary or memory: http://s.symcd.com06 |
Source: powershell.exe, 00000002.00000002.2539524436.0000000004AC1000.00000004.00000800.00020000.00000000.sdmp, Forbundsstater.exe, 00000006.00000002.2674791850.0000000021461000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name |
Source: LPO-9180155-PDF.exe, Forbundsstater.exe.2.dr |
String found in binary or memory: http://ts-aia.ws.symantec.com/sha256-tss-ca.cer0( |
Source: LPO-9180155-PDF.exe, Forbundsstater.exe.2.dr |
String found in binary or memory: http://ts-crl.ws.symantec.com/sha256-tss-ca.crl0 |
Source: LPO-9180155-PDF.exe, Forbundsstater.exe.2.dr |
String found in binary or memory: http://ts-ocsp.ws.symantec.com0; |
Source: powershell.exe, 00000002.00000002.2539524436.0000000004C16000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://www.apache.org/licenses/LICENSE-2.0.html |
Source: powershell.exe, 00000002.00000002.2539524436.0000000004AC1000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://aka.ms/pscore6lBeq |
Source: powershell.exe, 00000002.00000002.2542661803.0000000005B28000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://contoso.com/ |
Source: powershell.exe, 00000002.00000002.2542661803.0000000005B28000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://contoso.com/Icon |
Source: powershell.exe, 00000002.00000002.2542661803.0000000005B28000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://contoso.com/License |
Source: LPO-9180155-PDF.exe, Forbundsstater.exe.2.dr |
String found in binary or memory: https://d.symcb.com/cps0% |
Source: LPO-9180155-PDF.exe, Forbundsstater.exe.2.dr |
String found in binary or memory: https://d.symcb.com/rpa0 |
Source: LPO-9180155-PDF.exe, Forbundsstater.exe.2.dr |
String found in binary or memory: https://d.symcb.com/rpa0. |
Source: powershell.exe, 00000002.00000002.2539524436.0000000004C16000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://github.com/Pester/Pester |
Source: powershell.exe, 00000002.00000002.2542661803.0000000005B28000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://nuget.org/nuget.exe |
Source: Forbundsstater.exe, 00000006.00000002.2674791850.00000000215C3000.00000004.00000800.00020000.00000000.sdmp, Forbundsstater.exe, 00000006.00000002.2674791850.000000002160C000.00000004.00000800.00020000.00000000.sdmp, Forbundsstater.exe, 00000006.00000002.2674791850.0000000021566000.00000004.00000800.00020000.00000000.sdmp, Forbundsstater.exe, 00000006.00000002.2674791850.00000000215B6000.00000004.00000800.00020000.00000000.sdmp, Forbundsstater.exe, 00000006.00000002.2674791850.000000002161A000.00000004.00000800.00020000.00000000.sdmp, Forbundsstater.exe, 00000006.00000002.2674791850.0000000021523000.00000004.00000800.00020000.00000000.sdmp, Forbundsstater.exe, 00000006.00000002.2674791850.00000000215D1000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://reallyfreegeoip.org |
Source: Forbundsstater.exe, 00000006.00000002.2674791850.0000000021523000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://reallyfreegeoip.org/xml/ |
Source: Forbundsstater.exe, 00000006.00000002.2674791850.00000000215D1000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://reallyfreegeoip.org/xml/8.46.123.33 |
Source: Forbundsstater.exe, 00000006.00000002.2674791850.00000000215C3000.00000004.00000800.00020000.00000000.sdmp, Forbundsstater.exe, 00000006.00000002.2674791850.000000002160C000.00000004.00000800.00020000.00000000.sdmp, Forbundsstater.exe, 00000006.00000002.2674791850.0000000021566000.00000004.00000800.00020000.00000000.sdmp, Forbundsstater.exe, 00000006.00000002.2674791850.00000000215B6000.00000004.00000800.00020000.00000000.sdmp, Forbundsstater.exe, 00000006.00000002.2674791850.000000002161A000.00000004.00000800.00020000.00000000.sdmp, Forbundsstater.exe, 00000006.00000002.2674791850.00000000215D1000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://reallyfreegeoip.org/xml/8.46.123.33$ |
Source: Forbundsstater.exe, 00000006.00000002.2662544799.0000000005589000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://www.reap.skyestates.com.mt/ |
Source: Forbundsstater.exe, 00000006.00000002.2662544799.0000000005589000.00000004.00000020.00020000.00000000.sdmp, Forbundsstater.exe, 00000006.00000002.2662922690.0000000006F20000.00000004.00001000.00020000.00000000.sdmp |
String found in binary or memory: https://www.reap.skyestates.com.mt/wp-includes/IoNHObzRr183.bin |
Source: Forbundsstater.exe, 00000006.00000002.2662544799.0000000005589000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://www.reap.skyestates.com.mt/wp-includes/IoNHObzRr183.bino |
Source: C:\Users\user\Desktop\LPO-9180155-PDF.exe |
Code function: 0_2_00403358 EntryPoint,#17,SetErrorMode,OleInitialize,SHGetFileInfoW,GetCommandLineW,GetModuleHandleW,CharNextW,GetTempPathW,GetTempPathW,GetWindowsDirectoryW,lstrcatW,GetTempPathW,lstrcatW,SetEnvironmentVariableW,SetEnvironmentVariableW,SetEnvironmentVariableW,DeleteFileW,OleUninitialize,ExitProcess,lstrcatW,lstrcmpiW,CreateDirectoryW,SetCurrentDirectoryW,DeleteFileW,CopyFileW,CloseHandle,GetCurrentProcess,ExitWindowsEx,ExitProcess, |
0_2_00403358 |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Code function: 6_2_00403358 EntryPoint,#17,SetErrorMode,OleInitialize,SHGetFileInfoW,GetCommandLineW,GetModuleHandleW,CharNextW,GetTempPathW,GetTempPathW,GetWindowsDirectoryW,lstrcatW,GetTempPathW,lstrcatW,SetEnvironmentVariableW,SetEnvironmentVariableW,SetEnvironmentVariableW,DeleteFileW,OleUninitialize,ExitProcess,lstrcatW,lstrcmpiW,CreateDirectoryW,SetCurrentDirectoryW,DeleteFileW,CopyFileW,CloseHandle,GetCurrentProcess,ExitWindowsEx,ExitProcess, |
6_2_00403358 |
Source: C:\Users\user\Desktop\LPO-9180155-PDF.exe |
Code function: 0_2_00404B0E |
0_2_00404B0E |
Source: C:\Users\user\Desktop\LPO-9180155-PDF.exe |
Code function: 0_2_0040653D |
0_2_0040653D |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Code function: 2_2_02FBEAD8 |
2_2_02FBEAD8 |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Code function: 2_2_02FBF3A8 |
2_2_02FBF3A8 |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Code function: 2_2_02FBE790 |
2_2_02FBE790 |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Code function: 2_2_0754C17E |
2_2_0754C17E |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Code function: 6_2_00404B0E |
6_2_00404B0E |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Code function: 6_2_0040653D |
6_2_0040653D |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Code function: 6_2_00156108 |
6_2_00156108 |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Code function: 6_2_0015C190 |
6_2_0015C190 |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Code function: 6_2_0015B328 |
6_2_0015B328 |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Code function: 6_2_0015C470 |
6_2_0015C470 |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Code function: 6_2_00156730 |
6_2_00156730 |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Code function: 6_2_0015C752 |
6_2_0015C752 |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Code function: 6_2_00159858 |
6_2_00159858 |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Code function: 6_2_0015CA32 |
6_2_0015CA32 |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Code function: 6_2_00154AD9 |
6_2_00154AD9 |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Code function: 6_2_0015BBD2 |
6_2_0015BBD2 |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Code function: 6_2_0015BEB0 |
6_2_0015BEB0 |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Code function: 6_2_0015B4F2 |
6_2_0015B4F2 |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Code function: 6_2_00153572 |
6_2_00153572 |
Source: C:\Users\user\Desktop\LPO-9180155-PDF.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LPO-9180155-PDF.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LPO-9180155-PDF.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LPO-9180155-PDF.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LPO-9180155-PDF.exe |
Section loaded: shfolder.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LPO-9180155-PDF.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LPO-9180155-PDF.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LPO-9180155-PDF.exe |
Section loaded: propsys.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LPO-9180155-PDF.exe |
Section loaded: riched20.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LPO-9180155-PDF.exe |
Section loaded: usp10.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LPO-9180155-PDF.exe |
Section loaded: msls31.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LPO-9180155-PDF.exe |
Section loaded: textinputframework.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LPO-9180155-PDF.exe |
Section loaded: coreuicomponents.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LPO-9180155-PDF.exe |
Section loaded: coremessaging.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LPO-9180155-PDF.exe |
Section loaded: ntmarta.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LPO-9180155-PDF.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LPO-9180155-PDF.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LPO-9180155-PDF.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LPO-9180155-PDF.exe |
Section loaded: textshaping.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: atl.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: mscoree.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: vcruntime140_clr0400.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: cryptsp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: rsaenh.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: cryptbase.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: amsi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: msasn1.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: msisip.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: gpapi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: wshext.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: appxsip.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: opcservices.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: secur32.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: wbemcomn.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: napinsp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: pnrpnsp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: wshbth.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: nlaapi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: iphlpapi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: mswsock.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: dnsapi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: winrnr.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: fwpuclnt.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: rasadhlp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: ntmarta.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Section loaded: wininet.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Section loaded: iertutil.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Section loaded: ondemandconnroutehelper.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Section loaded: winhttp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Section loaded: iphlpapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Section loaded: mswsock.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Section loaded: winnsi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Section loaded: urlmon.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Section loaded: srvcli.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Section loaded: netutils.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Section loaded: dnsapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Section loaded: rasadhlp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Section loaded: fwpuclnt.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Section loaded: schannel.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Section loaded: mskeyprotect.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Section loaded: ntasn1.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Section loaded: msasn1.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Section loaded: dpapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Section loaded: cryptsp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Section loaded: rsaenh.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Section loaded: cryptbase.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Section loaded: gpapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Section loaded: ncrypt.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Section loaded: ncryptsslp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Section loaded: mscoree.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Section loaded: vcruntime140_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Section loaded: rasapi32.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Section loaded: rasman.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Section loaded: rtutils.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Section loaded: dhcpcsvc6.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Section loaded: dhcpcsvc.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Section loaded: secur32.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Section loaded: propsys.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Section loaded: edputil.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Section loaded: windows.staterepositoryps.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Section loaded: appresolver.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Section loaded: bcp47langs.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Section loaded: slc.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Section loaded: sppc.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Section loaded: onecorecommonproxystub.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Section loaded: onecoreuapcommonproxystub.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\choice.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Code function: 2_2_02FB0B5D push edi; retf |
2_2_02FB0B62 |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Code function: 2_2_02FB12D8 push esp; retf |
2_2_02FB12E1 |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Code function: 2_2_02FB9307 pushfd ; iretd |
2_2_02FB9476 |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Code function: 2_2_07540757 push cs; iretd |
2_2_0754075A |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Code function: 2_2_0754E767 push cs; iretd |
2_2_0754E76A |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Code function: 2_2_0754A7ED push cs; iretd |
2_2_0754A7EE |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Code function: 2_2_0754E7BF push cs; iretd |
2_2_0754E7C2 |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Code function: 2_2_075437AE push cs; iretd |
2_2_075437B2 |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Code function: 2_2_07540677 push cs; iretd |
2_2_0754067A |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Code function: 2_2_0754E6C1 push cs; iretd |
2_2_0754E6C2 |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Code function: 2_2_075406FF push cs; iretd |
2_2_07540702 |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Code function: 2_2_0754A6FB push cs; iretd |
2_2_0754A6FE |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Code function: 2_2_07548518 push cs; iretd |
2_2_07548652 |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Code function: 2_2_0754A518 push cs; iretd |
2_2_0754A67A |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Code function: 2_2_075465F8 push cs; iretd |
2_2_0754678A |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Code function: 2_2_0754044F push cs; iretd |
2_2_07540452 |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Code function: 2_2_07540470 push cs; iretd |
2_2_0754062E |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Code function: 2_2_0754946D push cs; iretd |
2_2_0754946E |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Code function: 2_2_0754E418 push cs; iretd |
2_2_0754E5EA |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Code function: 2_2_0754A419 push cs; iretd |
2_2_0754A41A |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Code function: 2_2_0754A4FB push cs; iretd |
2_2_0754A4FE |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Code function: 2_2_0754B360 push cs; iretd |
2_2_0754B59A |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Code function: 2_2_07540309 push cs; iretd |
2_2_0754030A |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Code function: 2_2_075403DF push cs; iretd |
2_2_075403E2 |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Code function: 2_2_07540391 push cs; iretd |
2_2_07540392 |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Code function: 2_2_0754625D push cs; iretd |
2_2_0754625E |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Code function: 2_2_07547273 push cs; iretd |
2_2_07547276 |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Code function: 2_2_07549210 push cs; iretd |
2_2_0754937A |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Code function: 2_2_075472DF push cs; iretd |
2_2_075472E2 |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Code function: 2_2_0754E2C0 push cs; iretd |
2_2_0754E3FE |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Code function: 2_2_07540283 push cs; iretd |
2_2_07540286 |
Source: C:\Users\user\Desktop\LPO-9180155-PDF.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\conhost.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Thread delayed: delay time: 922337203685477 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Thread delayed: delay time: 922337203685477 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Thread delayed: delay time: 600000 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Thread delayed: delay time: 599874 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Thread delayed: delay time: 599765 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Thread delayed: delay time: 599656 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Thread delayed: delay time: 599546 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Thread delayed: delay time: 599437 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Thread delayed: delay time: 599313 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Thread delayed: delay time: 599199 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Thread delayed: delay time: 599093 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Thread delayed: delay time: 598984 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Thread delayed: delay time: 598874 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Thread delayed: delay time: 598765 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Thread delayed: delay time: 598653 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Thread delayed: delay time: 598530 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Thread delayed: delay time: 598421 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Thread delayed: delay time: 598303 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Thread delayed: delay time: 598187 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Thread delayed: delay time: 598078 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Thread delayed: delay time: 597959 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Thread delayed: delay time: 597843 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Thread delayed: delay time: 597734 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Thread delayed: delay time: 597624 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Thread delayed: delay time: 597515 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Thread delayed: delay time: 597406 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Thread delayed: delay time: 597294 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Thread delayed: delay time: 597184 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Thread delayed: delay time: 597077 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Thread delayed: delay time: 596965 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Thread delayed: delay time: 596859 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Thread delayed: delay time: 596749 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Thread delayed: delay time: 596639 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Thread delayed: delay time: 596531 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Thread delayed: delay time: 596421 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Thread delayed: delay time: 596312 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Thread delayed: delay time: 596201 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Thread delayed: delay time: 596093 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Thread delayed: delay time: 595984 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Thread delayed: delay time: 595874 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Thread delayed: delay time: 595765 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Thread delayed: delay time: 595656 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Thread delayed: delay time: 595537 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Thread delayed: delay time: 595421 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Thread delayed: delay time: 595312 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Thread delayed: delay time: 595193 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Thread delayed: delay time: 595068 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Thread delayed: delay time: 594828 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Thread delayed: delay time: 594703 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Thread delayed: delay time: 594578 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Thread delayed: delay time: 594468 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Thread delayed: delay time: 594359 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Thread delayed: delay time: 594249 |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe TID: 6136 |
Thread sleep time: -5534023222112862s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe TID: 2968 |
Thread sleep time: -22136092888451448s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe TID: 2968 |
Thread sleep time: -600000s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe TID: 5352 |
Thread sleep count: 3522 > 30 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe TID: 2968 |
Thread sleep time: -599874s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe TID: 5352 |
Thread sleep count: 6315 > 30 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe TID: 2968 |
Thread sleep time: -599765s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe TID: 2968 |
Thread sleep time: -599656s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe TID: 2968 |
Thread sleep time: -599546s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe TID: 2968 |
Thread sleep time: -599437s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe TID: 2968 |
Thread sleep time: -599313s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe TID: 2968 |
Thread sleep time: -599199s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe TID: 2968 |
Thread sleep time: -599093s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe TID: 2968 |
Thread sleep time: -598984s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe TID: 2968 |
Thread sleep time: -598874s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe TID: 2968 |
Thread sleep time: -598765s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe TID: 2968 |
Thread sleep time: -598653s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe TID: 2968 |
Thread sleep time: -598530s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe TID: 2968 |
Thread sleep time: -598421s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe TID: 2968 |
Thread sleep time: -598303s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe TID: 2968 |
Thread sleep time: -598187s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe TID: 2968 |
Thread sleep time: -598078s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe TID: 2968 |
Thread sleep time: -597959s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe TID: 2968 |
Thread sleep time: -597843s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe TID: 2968 |
Thread sleep time: -597734s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe TID: 2968 |
Thread sleep time: -597624s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe TID: 2968 |
Thread sleep time: -597515s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe TID: 2968 |
Thread sleep time: -597406s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe TID: 2968 |
Thread sleep time: -597294s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe TID: 2968 |
Thread sleep time: -597184s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe TID: 2968 |
Thread sleep time: -597077s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe TID: 2968 |
Thread sleep time: -596965s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe TID: 2968 |
Thread sleep time: -596859s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe TID: 2968 |
Thread sleep time: -596749s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe TID: 2968 |
Thread sleep time: -596639s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe TID: 2968 |
Thread sleep time: -596531s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe TID: 2968 |
Thread sleep time: -596421s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe TID: 2968 |
Thread sleep time: -596312s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe TID: 2968 |
Thread sleep time: -596201s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe TID: 2968 |
Thread sleep time: -596093s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe TID: 2968 |
Thread sleep time: -595984s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe TID: 2968 |
Thread sleep time: -595874s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe TID: 2968 |
Thread sleep time: -595765s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe TID: 2968 |
Thread sleep time: -595656s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe TID: 2968 |
Thread sleep time: -595537s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe TID: 2968 |
Thread sleep time: -595421s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe TID: 2968 |
Thread sleep time: -595312s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe TID: 2968 |
Thread sleep time: -595193s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe TID: 2968 |
Thread sleep time: -595068s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe TID: 2968 |
Thread sleep time: -594828s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe TID: 2968 |
Thread sleep time: -594703s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe TID: 2968 |
Thread sleep time: -594578s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe TID: 2968 |
Thread sleep time: -594468s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe TID: 2968 |
Thread sleep time: -594359s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe TID: 2968 |
Thread sleep time: -594249s >= -30000s |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Thread delayed: delay time: 922337203685477 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Thread delayed: delay time: 922337203685477 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Thread delayed: delay time: 600000 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Thread delayed: delay time: 599874 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Thread delayed: delay time: 599765 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Thread delayed: delay time: 599656 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Thread delayed: delay time: 599546 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Thread delayed: delay time: 599437 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Thread delayed: delay time: 599313 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Thread delayed: delay time: 599199 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Thread delayed: delay time: 599093 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Thread delayed: delay time: 598984 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Thread delayed: delay time: 598874 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Thread delayed: delay time: 598765 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Thread delayed: delay time: 598653 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Thread delayed: delay time: 598530 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Thread delayed: delay time: 598421 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Thread delayed: delay time: 598303 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Thread delayed: delay time: 598187 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Thread delayed: delay time: 598078 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Thread delayed: delay time: 597959 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Thread delayed: delay time: 597843 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Thread delayed: delay time: 597734 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Thread delayed: delay time: 597624 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Thread delayed: delay time: 597515 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Thread delayed: delay time: 597406 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Thread delayed: delay time: 597294 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Thread delayed: delay time: 597184 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Thread delayed: delay time: 597077 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Thread delayed: delay time: 596965 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Thread delayed: delay time: 596859 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Thread delayed: delay time: 596749 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Thread delayed: delay time: 596639 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Thread delayed: delay time: 596531 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Thread delayed: delay time: 596421 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Thread delayed: delay time: 596312 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Thread delayed: delay time: 596201 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Thread delayed: delay time: 596093 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Thread delayed: delay time: 595984 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Thread delayed: delay time: 595874 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Thread delayed: delay time: 595765 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Thread delayed: delay time: 595656 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Thread delayed: delay time: 595537 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Thread delayed: delay time: 595421 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Thread delayed: delay time: 595312 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Thread delayed: delay time: 595193 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Thread delayed: delay time: 595068 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Thread delayed: delay time: 594828 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Thread delayed: delay time: 594703 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Thread delayed: delay time: 594578 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Thread delayed: delay time: 594468 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Thread delayed: delay time: 594359 |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Thread delayed: delay time: 594249 |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\ VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management\v4.0_3.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Management.dll VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceProcess\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Queries volume information: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe VolumeInformation |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Forbundsstater.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation |
Jump to behavior |