Source: 0.2.LisectAVT_2403002A_134.exe.3dbb680.9.unpack, type: UNPACKEDPE | Matched rule: Detects executables referencing Windows vault credential objects. Observed in infostealers Author: ditekSHen |
Source: 0.2.LisectAVT_2403002A_134.exe.3dbb680.9.unpack, type: UNPACKEDPE | Matched rule: AgenetTesla Type 2 Keylogger payload Author: ditekSHen |
Source: 0.2.LisectAVT_2403002A_134.exe.3d81060.7.unpack, type: UNPACKEDPE | Matched rule: Detects executables referencing Windows vault credential objects. Observed in infostealers Author: ditekSHen |
Source: 0.2.LisectAVT_2403002A_134.exe.3d81060.7.unpack, type: UNPACKEDPE | Matched rule: AgenetTesla Type 2 Keylogger payload Author: ditekSHen |
Source: 3.2.LisectAVT_2403002A_134.exe.400000.0.unpack, type: UNPACKEDPE | Matched rule: Detects executables referencing Windows vault credential objects. Observed in infostealers Author: ditekSHen |
Source: 3.2.LisectAVT_2403002A_134.exe.400000.0.unpack, type: UNPACKEDPE | Matched rule: AgenetTesla Type 2 Keylogger payload Author: ditekSHen |
Source: 0.2.LisectAVT_2403002A_134.exe.3dbb680.9.raw.unpack, type: UNPACKEDPE | Matched rule: Detects executables referencing Windows vault credential objects. Observed in infostealers Author: ditekSHen |
Source: 0.2.LisectAVT_2403002A_134.exe.3dbb680.9.raw.unpack, type: UNPACKEDPE | Matched rule: AgenetTesla Type 2 Keylogger payload Author: ditekSHen |
Source: 0.2.LisectAVT_2403002A_134.exe.3d81060.7.raw.unpack, type: UNPACKEDPE | Matched rule: Detects executables referencing Windows vault credential objects. Observed in infostealers Author: ditekSHen |
Source: 0.2.LisectAVT_2403002A_134.exe.3d81060.7.raw.unpack, type: UNPACKEDPE | Matched rule: AgenetTesla Type 2 Keylogger payload Author: ditekSHen |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Code function: 0_2_00F9D364 | 0_2_00F9D364 |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Code function: 0_2_02912D28 | 0_2_02912D28 |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Code function: 0_2_04FBBF68 | 0_2_04FBBF68 |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Code function: 0_2_04FBEAEE | 0_2_04FBEAEE |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Code function: 3_2_013593F8 | 3_2_013593F8 |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Code function: 3_2_01359BB0 | 3_2_01359BB0 |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Code function: 3_2_01354A58 | 3_2_01354A58 |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Code function: 3_2_0135CFD0 | 3_2_0135CFD0 |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Code function: 3_2_01353E40 | 3_2_01353E40 |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Code function: 3_2_01354188 | 3_2_01354188 |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Code function: 3_2_062656B8 | 3_2_062656B8 |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Code function: 3_2_06262EF0 | 3_2_06262EF0 |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Code function: 3_2_06263F28 | 3_2_06263F28 |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Code function: 3_2_0626BCC8 | 3_2_0626BCC8 |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Code function: 3_2_06268B68 | 3_2_06268B68 |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Code function: 3_2_0626DBF0 | 3_2_0626DBF0 |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Code function: 3_2_06260040 | 3_2_06260040 |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Code function: 3_2_06263630 | 3_2_06263630 |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Code function: 3_2_06264FD8 | 3_2_06264FD8 |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Code function: 3_2_06A24738 | 3_2_06A24738 |
Source: LisectAVT_2403002A_134.exe, 00000000.00000002.2048277325.0000000000A5E000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: OriginalFilenameclr.dllT vs LisectAVT_2403002A_134.exe |
Source: LisectAVT_2403002A_134.exe, 00000000.00000002.2053351805.0000000007010000.00000004.08000000.00040000.00000000.sdmp | Binary or memory string: OriginalFilenameTyrone.dll8 vs LisectAVT_2403002A_134.exe |
Source: LisectAVT_2403002A_134.exe, 00000000.00000002.2050611192.0000000003C7E000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: OriginalFilename3819dde1-5cc3-425a-99b4-feee310e8d7d.exe4 vs LisectAVT_2403002A_134.exe |
Source: LisectAVT_2403002A_134.exe, 00000000.00000002.2050611192.0000000003C7E000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: OriginalFilenameTyrone.dll8 vs LisectAVT_2403002A_134.exe |
Source: LisectAVT_2403002A_134.exe, 00000000.00000002.2050004526.0000000002AA1000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: OriginalFilename vs LisectAVT_2403002A_134.exe |
Source: LisectAVT_2403002A_134.exe, 00000000.00000002.2050004526.0000000002B01000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: OriginalFilename3819dde1-5cc3-425a-99b4-feee310e8d7d.exe4 vs LisectAVT_2403002A_134.exe |
Source: LisectAVT_2403002A_134.exe, 00000003.00000002.4486742312.0000000000BB8000.00000004.00000010.00020000.00000000.sdmp | Binary or memory string: OriginalFilenameUNKNOWN_FILET vs LisectAVT_2403002A_134.exe |
Source: LisectAVT_2403002A_134.exe, 00000003.00000002.4486327299.0000000000402000.00000040.00000400.00020000.00000000.sdmp | Binary or memory string: OriginalFilename3819dde1-5cc3-425a-99b4-feee310e8d7d.exe4 vs LisectAVT_2403002A_134.exe |
Source: LisectAVT_2403002A_134.exe | Binary or memory string: OriginalFilenamemVmj.exe4 vs LisectAVT_2403002A_134.exe |
Source: 0.2.LisectAVT_2403002A_134.exe.3dbb680.9.unpack, type: UNPACKEDPE | Matched rule: INDICATOR_SUSPICIOUS_EXE_VaultSchemaGUID author = ditekSHen, description = Detects executables referencing Windows vault credential objects. Observed in infostealers |
Source: 0.2.LisectAVT_2403002A_134.exe.3dbb680.9.unpack, type: UNPACKEDPE | Matched rule: MALWARE_Win_AgentTeslaV2 author = ditekSHen, description = AgenetTesla Type 2 Keylogger payload |
Source: 0.2.LisectAVT_2403002A_134.exe.3d81060.7.unpack, type: UNPACKEDPE | Matched rule: INDICATOR_SUSPICIOUS_EXE_VaultSchemaGUID author = ditekSHen, description = Detects executables referencing Windows vault credential objects. Observed in infostealers |
Source: 0.2.LisectAVT_2403002A_134.exe.3d81060.7.unpack, type: UNPACKEDPE | Matched rule: MALWARE_Win_AgentTeslaV2 author = ditekSHen, description = AgenetTesla Type 2 Keylogger payload |
Source: 3.2.LisectAVT_2403002A_134.exe.400000.0.unpack, type: UNPACKEDPE | Matched rule: INDICATOR_SUSPICIOUS_EXE_VaultSchemaGUID author = ditekSHen, description = Detects executables referencing Windows vault credential objects. Observed in infostealers |
Source: 3.2.LisectAVT_2403002A_134.exe.400000.0.unpack, type: UNPACKEDPE | Matched rule: MALWARE_Win_AgentTeslaV2 author = ditekSHen, description = AgenetTesla Type 2 Keylogger payload |
Source: 0.2.LisectAVT_2403002A_134.exe.3dbb680.9.raw.unpack, type: UNPACKEDPE | Matched rule: INDICATOR_SUSPICIOUS_EXE_VaultSchemaGUID author = ditekSHen, description = Detects executables referencing Windows vault credential objects. Observed in infostealers |
Source: 0.2.LisectAVT_2403002A_134.exe.3dbb680.9.raw.unpack, type: UNPACKEDPE | Matched rule: MALWARE_Win_AgentTeslaV2 author = ditekSHen, description = AgenetTesla Type 2 Keylogger payload |
Source: 0.2.LisectAVT_2403002A_134.exe.3d81060.7.raw.unpack, type: UNPACKEDPE | Matched rule: INDICATOR_SUSPICIOUS_EXE_VaultSchemaGUID author = ditekSHen, description = Detects executables referencing Windows vault credential objects. Observed in infostealers |
Source: 0.2.LisectAVT_2403002A_134.exe.3d81060.7.raw.unpack, type: UNPACKEDPE | Matched rule: MALWARE_Win_AgentTeslaV2 author = ditekSHen, description = AgenetTesla Type 2 Keylogger payload |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Section loaded: dwrite.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Section loaded: riched20.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Section loaded: usp10.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Section loaded: msls31.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Section loaded: windowscodecs.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Section loaded: wbemcomn.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Section loaded: vaultcli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Section loaded: rasapi32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Section loaded: rasman.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Section loaded: rtutils.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Section loaded: dhcpcsvc6.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Section loaded: dhcpcsvc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Section loaded: dnsapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Section loaded: winnsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Section loaded: rasadhlp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Section loaded: fwpuclnt.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Section loaded: edputil.dll | Jump to behavior |
Source: 0.2.LisectAVT_2403002A_134.exe.5260000.10.raw.unpack, kdFvaMFVPKs73pA7Ae.cs | High entropy of concatenated method names: 'jlLbsIppcp4pe', 'HUDVafGQx3A5lYPXEbC', 'bWxlDPGFKtjOUjq8ME9', 'J13JY7Gs9VegMR0Usdn', 'gjnvHYGCPTFBSN5sXDA', 'UXn9pRGVr5JYGFjuCRJ', 'g8bQ3yGYPoLwrRusK3E', 'KwwAwLG5jtFVjgr5V0l', 'lJyLiGG0wAjthymuVo5', 'KrHGd2G9wj507LdZGDe' |
Source: 0.2.LisectAVT_2403002A_134.exe.5260000.10.raw.unpack, DD.cs | High entropy of concatenated method names: 'wgRxinKHcbWANUbFNm', 'dwveif1E9jqp4XTbTA', 'iYTXHL2SDoNZBJVsGw', 'hFySdn3keDBvJSvKal', 'PVIytPpWpuEYQLk40u' |
Source: 0.2.LisectAVT_2403002A_134.exe.5260000.10.raw.unpack, ihWImL1h2qjtIkVYDh.cs | High entropy of concatenated method names: 'qJUttacKFT', 'djwp7oGHZ8xfNf3m5ut', 'AZqALCG67UykKuowXP2', 'dkLCJpGlCfFdqtD7Epf', 'iHWSkAGjDuGN31hXJsT', 'u4UYnDGE5xCOMnt15QR', 'jhES7Va4c', 'jWmROKkjL', 'Dispose', 'BJj7gBhfp' |
Source: 0.2.LisectAVT_2403002A_134.exe.5260000.10.raw.unpack, oImfMJtvGUo8fMQNBQ.cs | High entropy of concatenated method names: 'cxsORewNJ', 'VvrninWuk', 'ustvIxt9o', 'QtXoY7g0N', 'cMKlMbnQu', 'w2KLAB5Xx', 'hNkF6TG2YCh7xU8s3hJ', 'hs4l1PGKtLhAeRnm1c4', 'Dispose', 'MoveNext' |
Source: 0.2.LisectAVT_2403002A_134.exe.5260000.10.raw.unpack, wehuuoKhMKMbnQu72K.cs | High entropy of concatenated method names: 'NXMyxc8eI', 'GTZadPHeP', 'DEVNaDCj9', 'cflmBNqev', 'VFQ0OImLC', 'PbYVMxZvt', 'UPdFjbLed', 'AeEi93ui9', 'oM66buTLn', 'nxFUIfcfn' |
Source: 0.2.LisectAVT_2403002A_134.exe.2ac5dc4.6.raw.unpack, kdFvaMFVPKs73pA7Ae.cs | High entropy of concatenated method names: 'jlLbsIppcp4pe', 'HUDVafGQx3A5lYPXEbC', 'bWxlDPGFKtjOUjq8ME9', 'J13JY7Gs9VegMR0Usdn', 'gjnvHYGCPTFBSN5sXDA', 'UXn9pRGVr5JYGFjuCRJ', 'g8bQ3yGYPoLwrRusK3E', 'KwwAwLG5jtFVjgr5V0l', 'lJyLiGG0wAjthymuVo5', 'KrHGd2G9wj507LdZGDe' |
Source: 0.2.LisectAVT_2403002A_134.exe.2ac5dc4.6.raw.unpack, DD.cs | High entropy of concatenated method names: 'wgRxinKHcbWANUbFNm', 'dwveif1E9jqp4XTbTA', 'iYTXHL2SDoNZBJVsGw', 'hFySdn3keDBvJSvKal', 'PVIytPpWpuEYQLk40u' |
Source: 0.2.LisectAVT_2403002A_134.exe.2ac5dc4.6.raw.unpack, ihWImL1h2qjtIkVYDh.cs | High entropy of concatenated method names: 'qJUttacKFT', 'djwp7oGHZ8xfNf3m5ut', 'AZqALCG67UykKuowXP2', 'dkLCJpGlCfFdqtD7Epf', 'iHWSkAGjDuGN31hXJsT', 'u4UYnDGE5xCOMnt15QR', 'jhES7Va4c', 'jWmROKkjL', 'Dispose', 'BJj7gBhfp' |
Source: 0.2.LisectAVT_2403002A_134.exe.2ac5dc4.6.raw.unpack, oImfMJtvGUo8fMQNBQ.cs | High entropy of concatenated method names: 'cxsORewNJ', 'VvrninWuk', 'ustvIxt9o', 'QtXoY7g0N', 'cMKlMbnQu', 'w2KLAB5Xx', 'hNkF6TG2YCh7xU8s3hJ', 'hs4l1PGKtLhAeRnm1c4', 'Dispose', 'MoveNext' |
Source: 0.2.LisectAVT_2403002A_134.exe.2ac5dc4.6.raw.unpack, wehuuoKhMKMbnQu72K.cs | High entropy of concatenated method names: 'NXMyxc8eI', 'GTZadPHeP', 'DEVNaDCj9', 'cflmBNqev', 'VFQ0OImLC', 'PbYVMxZvt', 'UPdFjbLed', 'AeEi93ui9', 'oM66buTLn', 'nxFUIfcfn' |
Source: 0.2.LisectAVT_2403002A_134.exe.3e84b70.8.raw.unpack, OdlSfjpuRUCNlQDYU5.cs | High entropy of concatenated method names: 'GZgVNGovtD', 'AM5Vx9Mjm9', 'S1nVcNPRVK', 'jXTV76p3Y6', 'd4xVApI8Yk', 'juJVub1Huh', 'teMVUCNgmo', 'QAqVM23EOR', 'ujQVKPQlcD', 'iQrVZ6XIpd' |
Source: 0.2.LisectAVT_2403002A_134.exe.3e84b70.8.raw.unpack, hJaVIUGkr0yoYGlVdP.cs | High entropy of concatenated method names: 'RCXeF0MYW', 'gjVOU50n3', 'u3a9SFKKQ', 'qIXLyg9Mk', 'WGIrOwdHY', 'laEX5NSjg', 'JyGTvbJmBXP112lT3h', 'TOcXPIAB28eHe8matj', 'gSInQt1Cq', 'zj1IbdSgU' |
Source: 0.2.LisectAVT_2403002A_134.exe.3e84b70.8.raw.unpack, DHiZVFPce8G67eHKnh.cs | High entropy of concatenated method names: 'wNSDtJi6Xv', 'YxcDlQRurL', 'mRvnaZjcNx', 'agVn53AFg2', 'utoDH9uCVt', 'UkcDo9tqPf', 'gsmD2niEJl', 'NrKDBewYvV', 'RbwD4fyKD5', 'iRRDbIEkIH' |
Source: 0.2.LisectAVT_2403002A_134.exe.3e84b70.8.raw.unpack, KHtFJk2DfQEoIV6f0f.cs | High entropy of concatenated method names: 'yAC7Obmq37', 'C9p79Y316q', 'Jvp7G4orFA', 'kdA7rrXa2F', 'XUN70Hw2Gm', 'HT97Qaj923', 'wTJ7DvkEeO', 'pan7nHhFnb', 'Two7fAs6TD', 'lB67IeSloE' |
Source: 0.2.LisectAVT_2403002A_134.exe.3e84b70.8.raw.unpack, BkKOPxWtPTDOl1lhxy.cs | High entropy of concatenated method names: 'h7DcBNXZAr', 'Q8Ic4i7xlN', 'lPDcbAinS3', 'V57cJkUgUX', 'EwXc69htkK', 'itQch1CqVd', 'K5ecFBdfJP', 'bxyct5vWC8', 'gBJc3nfBiT', 'i0CclvoVSm' |
Source: 0.2.LisectAVT_2403002A_134.exe.3e84b70.8.raw.unpack, GLuYQQYlAqor1TAQew.cs | High entropy of concatenated method names: 'fMv5UMaJuy', 'HcV5MeeBWg', 'nXI5ZaMp1Z', 'I925vt49IZ', 'cjV50NyuI6', 'ECM5QF9dxB', 'B1PPWQ8aR8CrdHMG9V', 'o4uqPgBvhnS1cWY2c3', 'sw555xs2Ku', 'mNf5VXO4M6' |
Source: 0.2.LisectAVT_2403002A_134.exe.3e84b70.8.raw.unpack, c7BtRQRUhKYwfA1Vwm6.cs | High entropy of concatenated method names: 'YdifT0ybbs', 'I5AfjbSjQt', 'mgvfe6VeRT', 'HhsfOfM0Sw', 'l7TfkCigZm', 'oEqf9fS1Js', 'LcDfLZ7ONK', 'klHfGf2FRe', 'NRlfrVPsfI', 'XqCfXoxwUP' |
Source: 0.2.LisectAVT_2403002A_134.exe.3e84b70.8.raw.unpack, mlnM4sOQIi70wBrNLb.cs | High entropy of concatenated method names: 'vAiSGPbw0T', 'LE4SryTooE', 'JJ8SYq8RcO', 'MNJSmQcPnG', 'qGMSgCRxJx', 'NADSWZSNid', 'Dl7SiT0Dm3', 'q4ySRgAENI', 'HTXSPaJRqR', 'YIxSHnuqLT' |
Source: 0.2.LisectAVT_2403002A_134.exe.3e84b70.8.raw.unpack, kk4Jd0fsfydXFWFdRc.cs | High entropy of concatenated method names: 'oTDnxy7a3N', 'o1EncfVDVw', 'k8En7ViVsH', 'NajnAJ6WPu', 'iKjnuboTxV', 'kDInUKK1jH', 'hltnM17SSP', 'JWCnKeRKu0', 'Dm8nZCUBTx', 'V4TnvI00cV' |
Source: 0.2.LisectAVT_2403002A_134.exe.3e84b70.8.raw.unpack, CBBlg6xa5rjXqJCcfN.cs | High entropy of concatenated method names: 'UeKuN2blB8', 'AKZucpA7Jm', 'XFiuApha5i', 'VqfuURpWXP', 'LjXuM9VcKd', 'NgYA64xyut', 'GQfAhqmCRj', 'nyGAFVtLiE', 'n3cAtoSseR', 'UrJA3w4NLT' |
Source: 0.2.LisectAVT_2403002A_134.exe.3e84b70.8.raw.unpack, dE9S1ktrxwWL2invdR.cs | High entropy of concatenated method names: 'ToString', 'WSHQHiQ2xs', 'L6dQmrK3xa', 'P5EQCB1Lhy', 'C0lQge6cQr', 'SiVQW50Vp7', 'P9LQqLRCyn', 'rvZQiiYSkT', 'ksfQRjPCc9', 'JdBQ8RwaNP' |
Source: 0.2.LisectAVT_2403002A_134.exe.3e84b70.8.raw.unpack, Oq7iU74OEBZ4I6vJvi.cs | High entropy of concatenated method names: 'JMyf5csVRE', 'BDnfV2vEUJ', 'nh0f1JYR9B', 'TGifxy5wCf', 'SAxfcVuFAe', 'WT9fAyTWGr', 'wwNfuDMcoL', 'RZnnFwYRQR', 'EexntVxOw9', 'hhYn3Mctio' |
Source: 0.2.LisectAVT_2403002A_134.exe.3e84b70.8.raw.unpack, KN3gSMS3NX11JJnl2T.cs | High entropy of concatenated method names: 'Dispose', 'vro53GYX6O', 'euppmMENQH', 'aLjyypcZfu', 'AEi5lN9rct', 'pO45zjk2X4', 'ProcessDialogKey', 'TUNpaB2ni2', 'LWTp5MophK', 'xyKppmKvnE' |
Source: 0.2.LisectAVT_2403002A_134.exe.3e84b70.8.raw.unpack, L6HRkmR90kOLBOfAGVr.cs | High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'qK1IBlHmKu', 'n9gI4Zkvts', 'ragIboXnC3', 'qvsIJfOome', 'TX7I6aXTCG', 'DnuIhPTCv4', 'nAOIFOYBlM' |
Source: 0.2.LisectAVT_2403002A_134.exe.3e84b70.8.raw.unpack, Oi5P6nhrwYbHF07Al8.cs | High entropy of concatenated method names: 'pYyubMtMq1', 'kZ4uJIELU4', 'kj5u6gFf5p', 'ToString', 'WFPuhRpCbj', 'lZ9uFKsSbH', 'mLGkwxYdaKw92CQrB1v', 'ILxAGnYwM3OehumEZ7V' |
Source: 0.2.LisectAVT_2403002A_134.exe.3e84b70.8.raw.unpack, DUlB6y1pOYQEFoGhR8.cs | High entropy of concatenated method names: 'IcoAk1XUBG', 'O4PALu6eHP', 'D2F7CMfPpD', 'n2y7g1dTEA', 'xAm7WWg5MF', 'n297qcHCq4', 'aCR7i3xMhW', 'RhS7RWkOXZ', 'EmI78WlVQo', 'oc37P5sdmr' |
Source: 0.2.LisectAVT_2403002A_134.exe.3e84b70.8.raw.unpack, qrDYACbEieiDK3cZUr.cs | High entropy of concatenated method names: 'L8fUTdTaSF', 'RZfUjVrBjJ', 'v5SUepjZLJ', 'mGMUOU6Zkd', 'OadUkKgh5h', 'yhyU9OGLWQ', 'b5oUL6LN3Y', 'V3uUGHdpVg', 'V93Ur4RxeH', 'Y3jUXxCqpv' |
Source: 0.2.LisectAVT_2403002A_134.exe.3e84b70.8.raw.unpack, weTgMsNRAZGaNR7pex.cs | High entropy of concatenated method names: 'f8inYA54HW', 'kgInmEnLVi', 'ohlnCVIQSR', 'ukKngDTs5H', 'vxpnB6L0gg', 'wZSnWyU7s2', 'Next', 'Next', 'Next', 'NextBytes' |
Source: 0.2.LisectAVT_2403002A_134.exe.3e84b70.8.raw.unpack, ip8Do4X07L2EjDlR2S.cs | High entropy of concatenated method names: 'cFGUxroKB7', 'O2kU7Z3y0j', 'aZtUuMRFPp', 'CUpulw5oni', 'JvNuzJGIyP', 'SG8Uao0KIQ', 'qyXU588v16', 'GNwUpe8uvY', 'JLSUV4v3lB', 'AniU1HZ2Xn' |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Thread delayed: delay time: 1200000 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Thread delayed: delay time: 1199891 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Thread delayed: delay time: 1199766 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Thread delayed: delay time: 1199641 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Thread delayed: delay time: 1199531 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Thread delayed: delay time: 1199422 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Thread delayed: delay time: 1199313 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Thread delayed: delay time: 1199188 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Thread delayed: delay time: 1199063 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Thread delayed: delay time: 1198953 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Thread delayed: delay time: 1198844 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Thread delayed: delay time: 1198719 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Thread delayed: delay time: 1198610 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Thread delayed: delay time: 1198485 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Thread delayed: delay time: 1198360 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Thread delayed: delay time: 1198235 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Thread delayed: delay time: 1198110 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Thread delayed: delay time: 1197985 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Thread delayed: delay time: 1197860 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Thread delayed: delay time: 1197735 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Thread delayed: delay time: 1197610 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Thread delayed: delay time: 1197485 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Thread delayed: delay time: 1197360 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Thread delayed: delay time: 1197235 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Thread delayed: delay time: 1197110 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Thread delayed: delay time: 1196985 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Thread delayed: delay time: 1196860 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Thread delayed: delay time: 1196735 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Thread delayed: delay time: 1196610 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Thread delayed: delay time: 1196485 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Thread delayed: delay time: 1196360 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Thread delayed: delay time: 1196235 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Thread delayed: delay time: 1196110 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Thread delayed: delay time: 1195985 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Thread delayed: delay time: 1195860 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Thread delayed: delay time: 1195735 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Thread delayed: delay time: 1195564 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Thread delayed: delay time: 1195438 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Thread delayed: delay time: 1195313 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Thread delayed: delay time: 1195188 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Thread delayed: delay time: 1195078 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Thread delayed: delay time: 1194969 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Thread delayed: delay time: 1194844 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Thread delayed: delay time: 1194735 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Thread delayed: delay time: 1194610 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Thread delayed: delay time: 1194485 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Thread delayed: delay time: 1194360 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Thread delayed: delay time: 1194235 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Thread delayed: delay time: 1194110 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Thread delayed: delay time: 1193985 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe TID: 2568 | Thread sleep time: -922337203685477s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe TID: 1492 | Thread sleep count: 36 > 30 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe TID: 1492 | Thread sleep time: -33204139332677172s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe TID: 1492 | Thread sleep time: -1200000s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe TID: 3288 | Thread sleep count: 1611 > 30 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe TID: 1492 | Thread sleep time: -1199891s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe TID: 3288 | Thread sleep count: 8211 > 30 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe TID: 1492 | Thread sleep count: 33 > 30 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe TID: 1492 | Thread sleep time: -1199766s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe TID: 1492 | Thread sleep time: -1199641s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe TID: 1492 | Thread sleep time: -1199531s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe TID: 1492 | Thread sleep time: -1199422s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe TID: 1492 | Thread sleep time: -1199313s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe TID: 1492 | Thread sleep time: -1199188s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe TID: 1492 | Thread sleep time: -1199063s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe TID: 1492 | Thread sleep time: -1198953s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe TID: 1492 | Thread sleep time: -1198844s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe TID: 1492 | Thread sleep time: -1198719s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe TID: 1492 | Thread sleep time: -1198610s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe TID: 1492 | Thread sleep time: -1198485s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe TID: 1492 | Thread sleep time: -1198360s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe TID: 1492 | Thread sleep time: -1198235s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe TID: 1492 | Thread sleep time: -1198110s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe TID: 1492 | Thread sleep time: -1197985s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe TID: 1492 | Thread sleep time: -1197860s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe TID: 1492 | Thread sleep time: -1197735s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe TID: 1492 | Thread sleep time: -1197610s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe TID: 1492 | Thread sleep time: -1197485s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe TID: 1492 | Thread sleep time: -1197360s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe TID: 1492 | Thread sleep time: -1197235s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe TID: 1492 | Thread sleep time: -1197110s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe TID: 1492 | Thread sleep time: -1196985s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe TID: 1492 | Thread sleep time: -1196860s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe TID: 1492 | Thread sleep time: -1196735s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe TID: 1492 | Thread sleep time: -1196610s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe TID: 1492 | Thread sleep time: -1196485s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe TID: 1492 | Thread sleep time: -1196360s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe TID: 1492 | Thread sleep time: -1196235s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe TID: 1492 | Thread sleep time: -1196110s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe TID: 1492 | Thread sleep time: -1195985s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe TID: 1492 | Thread sleep time: -1195860s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe TID: 1492 | Thread sleep time: -1195735s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe TID: 1492 | Thread sleep time: -1195564s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe TID: 1492 | Thread sleep time: -1195438s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe TID: 1492 | Thread sleep time: -1195313s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe TID: 1492 | Thread sleep time: -1195188s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe TID: 1492 | Thread sleep time: -1195078s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe TID: 1492 | Thread sleep time: -1194969s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe TID: 1492 | Thread sleep time: -1194844s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe TID: 1492 | Thread sleep time: -1194735s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe TID: 1492 | Thread sleep time: -1194610s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe TID: 1492 | Thread sleep time: -1194485s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe TID: 1492 | Thread sleep time: -1194360s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe TID: 1492 | Thread sleep time: -1194235s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe TID: 1492 | Thread sleep time: -1194110s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe TID: 1492 | Thread sleep time: -1193985s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Thread delayed: delay time: 1200000 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Thread delayed: delay time: 1199891 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Thread delayed: delay time: 1199766 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Thread delayed: delay time: 1199641 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Thread delayed: delay time: 1199531 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Thread delayed: delay time: 1199422 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Thread delayed: delay time: 1199313 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Thread delayed: delay time: 1199188 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Thread delayed: delay time: 1199063 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Thread delayed: delay time: 1198953 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Thread delayed: delay time: 1198844 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Thread delayed: delay time: 1198719 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Thread delayed: delay time: 1198610 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Thread delayed: delay time: 1198485 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Thread delayed: delay time: 1198360 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Thread delayed: delay time: 1198235 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Thread delayed: delay time: 1198110 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Thread delayed: delay time: 1197985 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Thread delayed: delay time: 1197860 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Thread delayed: delay time: 1197735 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Thread delayed: delay time: 1197610 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Thread delayed: delay time: 1197485 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Thread delayed: delay time: 1197360 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Thread delayed: delay time: 1197235 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Thread delayed: delay time: 1197110 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Thread delayed: delay time: 1196985 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Thread delayed: delay time: 1196860 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Thread delayed: delay time: 1196735 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Thread delayed: delay time: 1196610 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Thread delayed: delay time: 1196485 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Thread delayed: delay time: 1196360 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Thread delayed: delay time: 1196235 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Thread delayed: delay time: 1196110 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Thread delayed: delay time: 1195985 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Thread delayed: delay time: 1195860 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Thread delayed: delay time: 1195735 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Thread delayed: delay time: 1195564 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Thread delayed: delay time: 1195438 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Thread delayed: delay time: 1195313 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Thread delayed: delay time: 1195188 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Thread delayed: delay time: 1195078 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Thread delayed: delay time: 1194969 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Thread delayed: delay time: 1194844 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Thread delayed: delay time: 1194735 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Thread delayed: delay time: 1194610 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Thread delayed: delay time: 1194485 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Thread delayed: delay time: 1194360 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Thread delayed: delay time: 1194235 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Thread delayed: delay time: 1194110 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Thread delayed: delay time: 1193985 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Queries volume information: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Queries volume information: C:\Windows\Fonts\micross.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Queries volume information: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Security\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Security.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_134.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation | Jump to behavior |