Source: global traffic |
HTTP traffic detected: POST /bot6240128422:AAGfewUxVcQqKio_MV181yAuk31JpsBcgy8/sendDocument HTTP/1.1Content-Type: multipart/form-data; boundary=---------------------------8dcacd37f51b3f3Host: api.telegram.orgContent-Length: 975Expect: 100-continueConnection: Keep-Alive |
Source: global traffic |
HTTP traffic detected: POST /bot6240128422:AAGfewUxVcQqKio_MV181yAuk31JpsBcgy8/sendDocument HTTP/1.1Content-Type: multipart/form-data; boundary=---------------------------8dcb9d07bd4088fHost: api.telegram.orgContent-Length: 59488Expect: 100-continue |
Source: global traffic |
HTTP traffic detected: POST /bot6240128422:AAGfewUxVcQqKio_MV181yAuk31JpsBcgy8/sendDocument HTTP/1.1Content-Type: multipart/form-data; boundary=---------------------------8dcbd2f89f881a1Host: api.telegram.orgContent-Length: 57562Expect: 100-continue |
Source: global traffic |
HTTP traffic detected: POST /bot6240128422:AAGfewUxVcQqKio_MV181yAuk31JpsBcgy8/sendDocument HTTP/1.1Content-Type: multipart/form-data; boundary=---------------------------8dcbf70b25255b6Host: api.telegram.orgContent-Length: 57562Expect: 100-continueConnection: Keep-Alive |
Source: global traffic |
HTTP traffic detected: POST /bot6240128422:AAGfewUxVcQqKio_MV181yAuk31JpsBcgy8/sendDocument HTTP/1.1Content-Type: multipart/form-data; boundary=---------------------------8dcc56227d5fe15Host: api.telegram.orgContent-Length: 57551Expect: 100-continue |
Source: global traffic |
HTTP traffic detected: POST /bot6240128422:AAGfewUxVcQqKio_MV181yAuk31JpsBcgy8/sendDocument HTTP/1.1Content-Type: multipart/form-data; boundary=---------------------------8dcc9f9cbbe4ea1Host: api.telegram.orgContent-Length: 57551Expect: 100-continueConnection: Keep-Alive |
Source: global traffic |
HTTP traffic detected: POST /bot6240128422:AAGfewUxVcQqKio_MV181yAuk31JpsBcgy8/sendDocument HTTP/1.1Content-Type: multipart/form-data; boundary=---------------------------8dccc3999cbfb48Host: api.telegram.orgContent-Length: 57551Expect: 100-continueConnection: Keep-Alive |
Source: global traffic |
HTTP traffic detected: POST /bot6240128422:AAGfewUxVcQqKio_MV181yAuk31JpsBcgy8/sendDocument HTTP/1.1Content-Type: multipart/form-data; boundary=---------------------------8dcceb63c23233eHost: api.telegram.orgContent-Length: 57551Expect: 100-continueConnection: Keep-Alive |
Source: global traffic |
HTTP traffic detected: POST /bot6240128422:AAGfewUxVcQqKio_MV181yAuk31JpsBcgy8/sendDocument HTTP/1.1Content-Type: multipart/form-data; boundary=---------------------------8dcd5311bcd1988Host: api.telegram.orgContent-Length: 57551Expect: 100-continueConnection: Keep-Alive |
Source: global traffic |
HTTP traffic detected: POST /bot6240128422:AAGfewUxVcQqKio_MV181yAuk31JpsBcgy8/sendDocument HTTP/1.1Content-Type: multipart/form-data; boundary=---------------------------8dcd883f159ae3dHost: api.telegram.orgContent-Length: 57551Expect: 100-continueConnection: Keep-Alive |
Source: global traffic |
HTTP traffic detected: POST /bot6240128422:AAGfewUxVcQqKio_MV181yAuk31JpsBcgy8/sendDocument HTTP/1.1Content-Type: multipart/form-data; boundary=---------------------------8dcdb04645b2b88Host: api.telegram.orgContent-Length: 57551Expect: 100-continueConnection: Keep-Alive |
Source: global traffic |
HTTP traffic detected: POST /bot6240128422:AAGfewUxVcQqKio_MV181yAuk31JpsBcgy8/sendDocument HTTP/1.1Content-Type: multipart/form-data; boundary=---------------------------8dcdf0de441e7a8Host: api.telegram.orgContent-Length: 57551Expect: 100-continueConnection: Keep-Alive |
Source: global traffic |
HTTP traffic detected: POST /bot6240128422:AAGfewUxVcQqKio_MV181yAuk31JpsBcgy8/sendDocument HTTP/1.1Content-Type: multipart/form-data; boundary=---------------------------8dce4e1dc8f71b2Host: api.telegram.orgContent-Length: 57551Expect: 100-continueConnection: Keep-Alive |
Source: global traffic |
HTTP traffic detected: POST /bot6240128422:AAGfewUxVcQqKio_MV181yAuk31JpsBcgy8/sendDocument HTTP/1.1Content-Type: multipart/form-data; boundary=---------------------------8dce963108a87c4Host: api.telegram.orgContent-Length: 57558Expect: 100-continueConnection: Keep-Alive |
Source: global traffic |
HTTP traffic detected: POST /bot6240128422:AAGfewUxVcQqKio_MV181yAuk31JpsBcgy8/sendDocument HTTP/1.1Content-Type: multipart/form-data; boundary=---------------------------8dcec75a72c3e04Host: api.telegram.orgContent-Length: 57558Expect: 100-continueConnection: Keep-Alive |
Source: global traffic |
HTTP traffic detected: POST /bot6240128422:AAGfewUxVcQqKio_MV181yAuk31JpsBcgy8/sendDocument HTTP/1.1Content-Type: multipart/form-data; boundary=---------------------------8dcef2136d34414Host: api.telegram.orgContent-Length: 57558Expect: 100-continue |
Source: global traffic |
HTTP traffic detected: POST /bot6240128422:AAGfewUxVcQqKio_MV181yAuk31JpsBcgy8/sendDocument HTTP/1.1Content-Type: multipart/form-data; boundary=---------------------------8dcf244c2bc1a24Host: api.telegram.orgContent-Length: 61460Expect: 100-continueConnection: Keep-Alive |
Source: global traffic |
HTTP traffic detected: POST /bot6240128422:AAGfewUxVcQqKio_MV181yAuk31JpsBcgy8/sendDocument HTTP/1.1Content-Type: multipart/form-data; boundary=---------------------------8dcf5eb5d0922e3Host: api.telegram.orgContent-Length: 57558Expect: 100-continueConnection: Keep-Alive |
Source: global traffic |
HTTP traffic detected: POST /bot6240128422:AAGfewUxVcQqKio_MV181yAuk31JpsBcgy8/sendDocument HTTP/1.1Content-Type: multipart/form-data; boundary=---------------------------8dcfac024112999Host: api.telegram.orgContent-Length: 57558Expect: 100-continueConnection: Keep-Alive |
Source: global traffic |
HTTP traffic detected: POST /bot6240128422:AAGfewUxVcQqKio_MV181yAuk31JpsBcgy8/sendDocument HTTP/1.1Content-Type: multipart/form-data; boundary=---------------------------8dd0041be87c706Host: api.telegram.orgContent-Length: 57558Expect: 100-continueConnection: Keep-Alive |
Source: global traffic |
HTTP traffic detected: POST /bot6240128422:AAGfewUxVcQqKio_MV181yAuk31JpsBcgy8/sendDocument HTTP/1.1Content-Type: multipart/form-data; boundary=---------------------------8dd077b581d181aHost: api.telegram.orgContent-Length: 57558Expect: 100-continueConnection: Keep-Alive |
Source: global traffic |
HTTP traffic detected: POST /bot6240128422:AAGfewUxVcQqKio_MV181yAuk31JpsBcgy8/sendDocument HTTP/1.1Content-Type: multipart/form-data; boundary=---------------------------8dd0c9d0c344755Host: api.telegram.orgContent-Length: 57558Expect: 100-continueConnection: Keep-Alive |
Source: global traffic |
HTTP traffic detected: POST /bot6240128422:AAGfewUxVcQqKio_MV181yAuk31JpsBcgy8/sendDocument HTTP/1.1Content-Type: multipart/form-data; boundary=---------------------------8dd1001a144c656Host: api.telegram.orgContent-Length: 57561Expect: 100-continueConnection: Keep-Alive |
Source: global traffic |
HTTP traffic detected: POST /bot6240128422:AAGfewUxVcQqKio_MV181yAuk31JpsBcgy8/sendDocument HTTP/1.1Content-Type: multipart/form-data; boundary=---------------------------8dd1279d3482702Host: api.telegram.orgContent-Length: 60931Expect: 100-continueConnection: Keep-Alive |
Source: global traffic |
HTTP traffic detected: POST /bot6240128422:AAGfewUxVcQqKio_MV181yAuk31JpsBcgy8/sendDocument HTTP/1.1Content-Type: multipart/form-data; boundary=---------------------------8dd14f0e836a8c1Host: api.telegram.orgContent-Length: 57561Expect: 100-continueConnection: Keep-Alive |
Source: global traffic |
HTTP traffic detected: POST /bot6240128422:AAGfewUxVcQqKio_MV181yAuk31JpsBcgy8/sendDocument HTTP/1.1Content-Type: multipart/form-data; boundary=---------------------------8dd183344abb936Host: api.telegram.orgContent-Length: 57561Expect: 100-continueConnection: Keep-Alive |
Source: global traffic |
HTTP traffic detected: POST /bot6240128422:AAGfewUxVcQqKio_MV181yAuk31JpsBcgy8/sendDocument HTTP/1.1Content-Type: multipart/form-data; boundary=---------------------------8dd1ad724ca83faHost: api.telegram.orgContent-Length: 57561Expect: 100-continueConnection: Keep-Alive |
Source: global traffic |
HTTP traffic detected: POST /bot6240128422:AAGfewUxVcQqKio_MV181yAuk31JpsBcgy8/sendDocument HTTP/1.1Content-Type: multipart/form-data; boundary=---------------------------8dcacd40e7a0308Host: api.telegram.orgContent-Length: 57561Expect: 100-continueConnection: Keep-Alive |
Source: LisectAVT_2403002A_127.exe, 00000003.00000002.4574383032.00000000034B3000.00000004.00000800.00020000.00000000.sdmp, LisectAVT_2403002A_127.exe, 00000003.00000002.4574383032.00000000036B6000.00000004.00000800.00020000.00000000.sdmp, LisectAVT_2403002A_127.exe, 00000003.00000002.4574383032.0000000003668000.00000004.00000800.00020000.00000000.sdmp, LisectAVT_2403002A_127.exe, 00000003.00000002.4574383032.000000000334B000.00000004.00000800.00020000.00000000.sdmp, LisectAVT_2403002A_127.exe, 00000003.00000002.4574383032.000000000341E000.00000004.00000800.00020000.00000000.sdmp, LisectAVT_2403002A_127.exe, 00000003.00000002.4574383032.0000000003351000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://api.telegram.org |
Source: LisectAVT_2403002A_127.exe, 00000003.00000002.4574383032.00000000030E1000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name |
Source: LisectAVT_2403002A_127.exe, 00000000.00000002.2194739001.000000000428D000.00000004.00000800.00020000.00000000.sdmp, LisectAVT_2403002A_127.exe, 00000000.00000002.2194739001.0000000004BB0000.00000004.00000800.00020000.00000000.sdmp, LisectAVT_2403002A_127.exe, 00000003.00000002.4572559454.0000000000402000.00000040.00000400.00020000.00000000.sdmp |
String found in binary or memory: https://account.dyn.com/ |
Source: LisectAVT_2403002A_127.exe, 00000000.00000002.2194739001.000000000428D000.00000004.00000800.00020000.00000000.sdmp, LisectAVT_2403002A_127.exe, 00000000.00000002.2194739001.0000000004BB0000.00000004.00000800.00020000.00000000.sdmp, LisectAVT_2403002A_127.exe, 00000003.00000002.4574383032.00000000030E1000.00000004.00000800.00020000.00000000.sdmp, LisectAVT_2403002A_127.exe, 00000003.00000002.4572559454.0000000000402000.00000040.00000400.00020000.00000000.sdmp |
String found in binary or memory: https://api.ipify.org |
Source: LisectAVT_2403002A_127.exe, 00000003.00000002.4574383032.00000000030E1000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://api.ipify.org/ |
Source: LisectAVT_2403002A_127.exe, 00000003.00000002.4574383032.00000000030E1000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://api.ipify.org/t |
Source: LisectAVT_2403002A_127.exe, 00000003.00000002.4574383032.000000000325A000.00000004.00000800.00020000.00000000.sdmp, LisectAVT_2403002A_127.exe, 00000003.00000002.4574383032.00000000034B3000.00000004.00000800.00020000.00000000.sdmp, LisectAVT_2403002A_127.exe, 00000003.00000002.4574383032.00000000036B6000.00000004.00000800.00020000.00000000.sdmp, LisectAVT_2403002A_127.exe, 00000003.00000002.4574383032.0000000003668000.00000004.00000800.00020000.00000000.sdmp, LisectAVT_2403002A_127.exe, 00000003.00000002.4574383032.00000000031EE000.00000004.00000800.00020000.00000000.sdmp, LisectAVT_2403002A_127.exe, 00000003.00000002.4574383032.000000000334B000.00000004.00000800.00020000.00000000.sdmp, LisectAVT_2403002A_127.exe, 00000003.00000002.4574383032.000000000341E000.00000004.00000800.00020000.00000000.sdmp, LisectAVT_2403002A_127.exe, 00000003.00000002.4574383032.0000000003309000.00000004.00000800.00020000.00000000.sdmp, LisectAVT_2403002A_127.exe, 00000003.00000002.4574383032.0000000003131000.00000004.00000800.00020000.00000000.sdmp, LisectAVT_2403002A_127.exe, 00000003.00000002.4574383032.0000000003351000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://api.telegram.org |
Source: LisectAVT_2403002A_127.exe, 00000000.00000002.2194739001.000000000428D000.00000004.00000800.00020000.00000000.sdmp, LisectAVT_2403002A_127.exe, 00000000.00000002.2194739001.0000000004BB0000.00000004.00000800.00020000.00000000.sdmp, LisectAVT_2403002A_127.exe, 00000003.00000002.4574383032.00000000030E1000.00000004.00000800.00020000.00000000.sdmp, LisectAVT_2403002A_127.exe, 00000003.00000002.4572559454.0000000000402000.00000040.00000400.00020000.00000000.sdmp |
String found in binary or memory: https://api.telegram.org/bot6240128422:AAGfewUxVcQqKio_MV181yAuk31JpsBcgy8/ |
Source: LisectAVT_2403002A_127.exe, 00000003.00000002.4574383032.000000000325A000.00000004.00000800.00020000.00000000.sdmp, LisectAVT_2403002A_127.exe, 00000003.00000002.4574383032.00000000034B3000.00000004.00000800.00020000.00000000.sdmp, LisectAVT_2403002A_127.exe, 00000003.00000002.4574383032.00000000036B6000.00000004.00000800.00020000.00000000.sdmp, LisectAVT_2403002A_127.exe, 00000003.00000002.4574383032.0000000003668000.00000004.00000800.00020000.00000000.sdmp, LisectAVT_2403002A_127.exe, 00000003.00000002.4574383032.00000000031EE000.00000004.00000800.00020000.00000000.sdmp, LisectAVT_2403002A_127.exe, 00000003.00000002.4574383032.000000000334B000.00000004.00000800.00020000.00000000.sdmp, LisectAVT_2403002A_127.exe, 00000003.00000002.4574383032.0000000003186000.00000004.00000800.00020000.00000000.sdmp, LisectAVT_2403002A_127.exe, 00000003.00000002.4574383032.000000000341E000.00000004.00000800.00020000.00000000.sdmp, LisectAVT_2403002A_127.exe, 00000003.00000002.4574383032.0000000003309000.00000004.00000800.00020000.00000000.sdmp, LisectAVT_2403002A_127.exe, 00000003.00000002.4574383032.0000000003131000.00000004.00000800.00020000.00000000.sdmp, LisectAVT_2403002A_127.exe, 00000003.00000002.4574383032.0000000003351000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://api.telegram.org/bot6240128422:AAGfewUxVcQqKio_MV181yAuk31JpsBcgy8/sendDocument |
Source: LisectAVT_2403002A_127.exe |
String found in binary or memory: https://download.alegsoftware.ga/ws_switches/contatore/ltromatic.ttf |
Source: LisectAVT_2403002A_127.exe |
String found in binary or memory: https://fsf.org/ |
Source: LisectAVT_2403002A_127.exe |
String found in binary or memory: https://www.gnu.org/licenses/ |
Source: LisectAVT_2403002A_127.exe |
String found in binary or memory: https://www.gnu.org/licenses/why-not-lgpl.html |
Source: unknown |
Network traffic detected: HTTP traffic on port 49733 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 49744 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 49743 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 49742 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 49741 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 49740 |
Source: unknown |
Network traffic detected: HTTP traffic on port 49743 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 49746 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 49738 |
Source: unknown |
Network traffic detected: HTTP traffic on port 49717 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 49736 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 49737 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 49736 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 49735 |
Source: unknown |
Network traffic detected: HTTP traffic on port 49753 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 49734 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 49733 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 49732 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 49731 |
Source: unknown |
Network traffic detected: HTTP traffic on port 49732 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 49730 |
Source: unknown |
Network traffic detected: HTTP traffic on port 49742 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 49728 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 49752 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 49728 |
Source: unknown |
Network traffic detected: HTTP traffic on port 49735 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 49756 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 49731 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 49741 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 49748 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 49745 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 49751 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 49717 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 49716 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 49757 |
Source: unknown |
Network traffic detected: HTTP traffic on port 49738 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 49755 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 49756 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 49755 |
Source: unknown |
Network traffic detected: HTTP traffic on port 49757 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 49734 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 49754 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 49753 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 49752 |
Source: unknown |
Network traffic detected: HTTP traffic on port 49730 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 49751 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 49750 |
Source: unknown |
Network traffic detected: HTTP traffic on port 49740 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 49747 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 49744 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 49716 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 49750 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 49748 |
Source: unknown |
Network traffic detected: HTTP traffic on port 49754 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 49747 |
Source: unknown |
Network traffic detected: HTTP traffic on port 49737 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 49746 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 49745 |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Section loaded: mscoree.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Section loaded: vcruntime140_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Section loaded: cryptsp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Section loaded: rsaenh.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Section loaded: cryptbase.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Section loaded: dwrite.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Section loaded: riched20.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Section loaded: usp10.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Section loaded: msls31.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Section loaded: amsi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Section loaded: msasn1.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Section loaded: gpapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Section loaded: windowscodecs.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Section loaded: mscoree.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Section loaded: vcruntime140_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Section loaded: cryptsp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Section loaded: rsaenh.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Section loaded: cryptbase.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Section loaded: wbemcomn.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Section loaded: amsi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Section loaded: rasapi32.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Section loaded: rasman.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Section loaded: rtutils.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Section loaded: mswsock.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Section loaded: winhttp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Section loaded: ondemandconnroutehelper.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Section loaded: iphlpapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Section loaded: dhcpcsvc6.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Section loaded: dhcpcsvc.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Section loaded: dnsapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Section loaded: winnsi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Section loaded: rasadhlp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Section loaded: fwpuclnt.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Section loaded: secur32.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Section loaded: schannel.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Section loaded: mskeyprotect.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Section loaded: ntasn1.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Section loaded: ncrypt.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Section loaded: ncryptsslp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Section loaded: msasn1.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Section loaded: gpapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Section loaded: vaultcli.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Section loaded: edputil.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Section loaded: windowscodecs.dll |
Jump to behavior |
Source: 0.2.LisectAVT_2403002A_127.exe.7c80000.8.raw.unpack, md1b4YpvsopcyTG0K9.cs |
High entropy of concatenated method names: 'e9XetV0sq', 'O6i1U5xFi', 'XXOEanaRY', 'xPe3F6cs5', 'NP8ZiDEjS', 'EBWaYJrL8', 'fWV07D8Ze4EXaq5gmH', 'sNjZ5KaJOMypsC6u6V', 'r5DSvC5cP', 'qQayyahym' |
Source: 0.2.LisectAVT_2403002A_127.exe.7c80000.8.raw.unpack, uhdXDir4lKqJA5L4Sp.cs |
High entropy of concatenated method names: 'A7vMT4BgEO', 'vhxMGLB6k6', 'NteMxIB5ws', 'bfVM5mkOfU', 'GEyMkRRgUu', 'XJuMCFnZbR', 'v45MBvlXIE', 'lIsMPcMPFj', 'zpxM4CZTdk', 'r7uMwwUZfF' |
Source: 0.2.LisectAVT_2403002A_127.exe.7c80000.8.raw.unpack, klmAZ8HTeMLVuJRsAH.cs |
High entropy of concatenated method names: 'Xy1xKSBOe2', 'kcNxHXalOR', 'NLNxLdeeye', 'S1jxpsgdBe', 'fkIxqgDaW2', 'QDgxjnFsaY', 'V4MxQCKLBJ', 'pW5xX3SiNJ', 'Nigxm041ZV', 'v7AxVnoIRU' |
Source: 0.2.LisectAVT_2403002A_127.exe.7c80000.8.raw.unpack, Odwx2LjYANljE05Rb8.cs |
High entropy of concatenated method names: 'ToString', 'kXot9FUpm4', 'nbqtDL6yee', 'wIrt2EsOiT', 'RVptY1LD9G', 'BOGtoRkIWh', 'nMetssyPBT', 'kP3tUBwjvH', 'DBEtc3qCi1', 'ko6tNUjGFH' |
Source: 0.2.LisectAVT_2403002A_127.exe.7c80000.8.raw.unpack, AX1Xgv4D1Q2EKuupqj.cs |
High entropy of concatenated method names: 'Ai3Fb0VorA', 'WOVFZ8Jmxb', 'CSOFJtkspK', 'CC1FDPYNUc', 'himFYoux7j', 'BF5FotB6mC', 'Jg4FUTi5J7', 'EfkFcXxG2w', 'QEGF8d2k5f', 'ewXF9caTmx' |
Source: 0.2.LisectAVT_2403002A_127.exe.7c80000.8.raw.unpack, sWdKaCOIM2sgOvHeej.cs |
High entropy of concatenated method names: 'b0XBf5k8oN', 'DsCBRXWdoS', 'pG8BemC6Xd', 'iufB1oCKtI', 'ro3BO3sl8j', 'PI1BEiWtCR', 'AJVB30SnKp', 'LFNBbYGE9o', 'PQ7BZiMH6g', 'drCBaat4a0' |
Source: 0.2.LisectAVT_2403002A_127.exe.7c80000.8.raw.unpack, pWNYPZ5V9av2f1UrTvd.cs |
High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'zlFyKislS5', 'W7uyHQxOwY', 'udayLkexRT', 'eCOypfnF7t', 'DO1yqYFbML', 'CUMyjZ8X8R', 'fFhyQ8KDkG' |
Source: 0.2.LisectAVT_2403002A_127.exe.7c80000.8.raw.unpack, wMJB2RQRit9u0tKky6.cs |
High entropy of concatenated method names: 'xxTIwDVOTD', 'D4IIrdvact', 'ToString', 'LCQIGPjEU7', 'RTwIxfMai0', 'cZgI5CsuGI', 'KbAIkGviec', 'WAWIC7guxt', 'YivIBoQHlq', 'kBxIPE47H9' |
Source: 0.2.LisectAVT_2403002A_127.exe.7c80000.8.raw.unpack, ftvGXn5aX1cl3NfwNG9.cs |
High entropy of concatenated method names: 'gkk6f3VFlx', 'zbd6RNQBTX', 'Sbh6exKZgY', 'BPn617MX6h', 'mjb6O1UUsD', 'Oab6EkdgUL', 'eta63XKAAN', 'jo66bfyjyu', 'm5u6ZMX6NR', 'e426aa48U6' |
Source: 0.2.LisectAVT_2403002A_127.exe.7c80000.8.raw.unpack, iaZwSv7NUZ7lnset1d.cs |
High entropy of concatenated method names: 'morCTbZ37O', 'nvwCxJgxeq', 'uovCkuI2Dc', 'PgJCBmcl7a', 'EEJCPGDXKk', 'u2OkqZGrpM', 'nxakjt8g4f', 'GivkQMoYBc', 'oajkXhnsCN', 'MJckmZBgOg' |
Source: 0.2.LisectAVT_2403002A_127.exe.7c80000.8.raw.unpack, Cro2EFbkj2fvPZbku3.cs |
High entropy of concatenated method names: 'vnl6uj0Wu4', 'vxl6MZZoj7', 'gMm67Dnuyd', 'NbU6G9ZpKS', 'D156xFOCsB', 'fBr6kQJFQT', 'XoF6CvvlEU', 'O7ESQZWOst', 'jPeSXj6KXl', 'Gc3SmUI2fH' |
Source: 0.2.LisectAVT_2403002A_127.exe.7c80000.8.raw.unpack, kR6xFVcWjByQkEUqC9.cs |
High entropy of concatenated method names: 'Dispose', 'PNxumD58lP', 'rmChD72DZm', 'KTHddUYMU3', 'GDCuV5YNgN', 'xoXuzXEfed', 'ProcessDialogKey', 'FBIhvfVLhw', 'w61hu2dTS1', 'FZqhhSwIkh' |
Source: 0.2.LisectAVT_2403002A_127.exe.7c80000.8.raw.unpack, ajUyEO0gYae1kdByrk.cs |
High entropy of concatenated method names: 'U5pIXQYXC5', 'm3SIVrrGRZ', 'EiLSvZJZoX', 'LI8SuLHTaE', 'DWWI9kdOEM', 'A6wIib3TkX', 'EQ6In2EBrL', 'r5fIKpiEHP', 'DERIHvrney', 'e08ILEML5p' |
Source: 0.2.LisectAVT_2403002A_127.exe.7c80000.8.raw.unpack, mcP8dfxCsy0XIot8V2.cs |
High entropy of concatenated method names: 'KdR51LjgZq', 'DyD5EDefN0', 'UXC5bDqeFl', 'DiX5ZgAmde', 'fqe5gJ5oAg', 'PRS5tC4QlC', 'Gqk5IoXpHu', 'X3Q5SbwIEA', 'Vob56v3OnS', 'jZa5ynRhZC' |
Source: 0.2.LisectAVT_2403002A_127.exe.7c80000.8.raw.unpack, erqSUTsy0FA1KhqLIs.cs |
High entropy of concatenated method names: 'pEQuBkUejR', 'VBPuP0JLvt', 'vwjuwLv0y1', 'RHourNLG43', 'sTjugV521J', 'T07utB3lao', 'RItiAfCBvB5x6h7b5a', 'Nw9PSvAv655kLoFC4J', 'NJVFWi7LBvbvj7Z3Bu', 'kruuuxuqkh' |
Source: 0.2.LisectAVT_2403002A_127.exe.7c80000.8.raw.unpack, OoFyZfoyccIPM6eUm3.cs |
High entropy of concatenated method names: 'DJpSG05kw7', 'A6gSx4vgYy', 'k3TS5lAbbm', 'tXVSkXvI8X', 'tsZSCvym87', 'RVkSBX8367', 'Le3SPY1Ffm', 'UgLS485LXE', 'lwlSwm1Vj2', 'E9eSrl0NCk' |
Source: 0.2.LisectAVT_2403002A_127.exe.7c80000.8.raw.unpack, W2xqs255xweGuk9IvRb.cs |
High entropy of concatenated method names: 'ToString', 'LfOyMiVwAd', 'buPy7bvvAd', 'MIIyTCh6Ls', 'Q1XyGTmcTm', 'w3fyxbZQxq', 'wlAy5318VN', 'knhykJUyQV', 'Pwkoa3jai4QaaQF4vGg', 'HNkQMGjbjWh4TEenjmJ' |
Source: 0.2.LisectAVT_2403002A_127.exe.7c80000.8.raw.unpack, kdFuKdGJyNY9AlcONn.cs |
High entropy of concatenated method names: 'UA1g8fJH8V', 'a4wgijuDJx', 'v50gK0G6Up', 'w4DgHFunli', 'eFxgD9LyN1', 'K0dg2A78nN', 'vGJgYkmwrk', 'fb7goxEf84', 'WPdgsAoLhO', 're9gUfpgjY' |
Source: 0.2.LisectAVT_2403002A_127.exe.7c80000.8.raw.unpack, rYxoLNI0oTSuT0iyWI.cs |
High entropy of concatenated method names: 'dDsBGWkORU', 'cq2B5brhxX', 'yTRBCMwHLe', 'sOWCVDovrm', 'rYmCz1jVn1', 'ElKBvE8gfY', 'zH9BuAAfbA', 'rxXBhEbWam', 'pZvBMg7FAJ', 'LqGB7Dv5tp' |
Source: 0.2.LisectAVT_2403002A_127.exe.4334350.3.raw.unpack, md1b4YpvsopcyTG0K9.cs |
High entropy of concatenated method names: 'e9XetV0sq', 'O6i1U5xFi', 'XXOEanaRY', 'xPe3F6cs5', 'NP8ZiDEjS', 'EBWaYJrL8', 'fWV07D8Ze4EXaq5gmH', 'sNjZ5KaJOMypsC6u6V', 'r5DSvC5cP', 'qQayyahym' |
Source: 0.2.LisectAVT_2403002A_127.exe.4334350.3.raw.unpack, uhdXDir4lKqJA5L4Sp.cs |
High entropy of concatenated method names: 'A7vMT4BgEO', 'vhxMGLB6k6', 'NteMxIB5ws', 'bfVM5mkOfU', 'GEyMkRRgUu', 'XJuMCFnZbR', 'v45MBvlXIE', 'lIsMPcMPFj', 'zpxM4CZTdk', 'r7uMwwUZfF' |
Source: 0.2.LisectAVT_2403002A_127.exe.4334350.3.raw.unpack, klmAZ8HTeMLVuJRsAH.cs |
High entropy of concatenated method names: 'Xy1xKSBOe2', 'kcNxHXalOR', 'NLNxLdeeye', 'S1jxpsgdBe', 'fkIxqgDaW2', 'QDgxjnFsaY', 'V4MxQCKLBJ', 'pW5xX3SiNJ', 'Nigxm041ZV', 'v7AxVnoIRU' |
Source: 0.2.LisectAVT_2403002A_127.exe.4334350.3.raw.unpack, Odwx2LjYANljE05Rb8.cs |
High entropy of concatenated method names: 'ToString', 'kXot9FUpm4', 'nbqtDL6yee', 'wIrt2EsOiT', 'RVptY1LD9G', 'BOGtoRkIWh', 'nMetssyPBT', 'kP3tUBwjvH', 'DBEtc3qCi1', 'ko6tNUjGFH' |
Source: 0.2.LisectAVT_2403002A_127.exe.4334350.3.raw.unpack, AX1Xgv4D1Q2EKuupqj.cs |
High entropy of concatenated method names: 'Ai3Fb0VorA', 'WOVFZ8Jmxb', 'CSOFJtkspK', 'CC1FDPYNUc', 'himFYoux7j', 'BF5FotB6mC', 'Jg4FUTi5J7', 'EfkFcXxG2w', 'QEGF8d2k5f', 'ewXF9caTmx' |
Source: 0.2.LisectAVT_2403002A_127.exe.4334350.3.raw.unpack, sWdKaCOIM2sgOvHeej.cs |
High entropy of concatenated method names: 'b0XBf5k8oN', 'DsCBRXWdoS', 'pG8BemC6Xd', 'iufB1oCKtI', 'ro3BO3sl8j', 'PI1BEiWtCR', 'AJVB30SnKp', 'LFNBbYGE9o', 'PQ7BZiMH6g', 'drCBaat4a0' |
Source: 0.2.LisectAVT_2403002A_127.exe.4334350.3.raw.unpack, pWNYPZ5V9av2f1UrTvd.cs |
High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'zlFyKislS5', 'W7uyHQxOwY', 'udayLkexRT', 'eCOypfnF7t', 'DO1yqYFbML', 'CUMyjZ8X8R', 'fFhyQ8KDkG' |
Source: 0.2.LisectAVT_2403002A_127.exe.4334350.3.raw.unpack, wMJB2RQRit9u0tKky6.cs |
High entropy of concatenated method names: 'xxTIwDVOTD', 'D4IIrdvact', 'ToString', 'LCQIGPjEU7', 'RTwIxfMai0', 'cZgI5CsuGI', 'KbAIkGviec', 'WAWIC7guxt', 'YivIBoQHlq', 'kBxIPE47H9' |
Source: 0.2.LisectAVT_2403002A_127.exe.4334350.3.raw.unpack, ftvGXn5aX1cl3NfwNG9.cs |
High entropy of concatenated method names: 'gkk6f3VFlx', 'zbd6RNQBTX', 'Sbh6exKZgY', 'BPn617MX6h', 'mjb6O1UUsD', 'Oab6EkdgUL', 'eta63XKAAN', 'jo66bfyjyu', 'm5u6ZMX6NR', 'e426aa48U6' |
Source: 0.2.LisectAVT_2403002A_127.exe.4334350.3.raw.unpack, iaZwSv7NUZ7lnset1d.cs |
High entropy of concatenated method names: 'morCTbZ37O', 'nvwCxJgxeq', 'uovCkuI2Dc', 'PgJCBmcl7a', 'EEJCPGDXKk', 'u2OkqZGrpM', 'nxakjt8g4f', 'GivkQMoYBc', 'oajkXhnsCN', 'MJckmZBgOg' |
Source: 0.2.LisectAVT_2403002A_127.exe.4334350.3.raw.unpack, Cro2EFbkj2fvPZbku3.cs |
High entropy of concatenated method names: 'vnl6uj0Wu4', 'vxl6MZZoj7', 'gMm67Dnuyd', 'NbU6G9ZpKS', 'D156xFOCsB', 'fBr6kQJFQT', 'XoF6CvvlEU', 'O7ESQZWOst', 'jPeSXj6KXl', 'Gc3SmUI2fH' |
Source: 0.2.LisectAVT_2403002A_127.exe.4334350.3.raw.unpack, kR6xFVcWjByQkEUqC9.cs |
High entropy of concatenated method names: 'Dispose', 'PNxumD58lP', 'rmChD72DZm', 'KTHddUYMU3', 'GDCuV5YNgN', 'xoXuzXEfed', 'ProcessDialogKey', 'FBIhvfVLhw', 'w61hu2dTS1', 'FZqhhSwIkh' |
Source: 0.2.LisectAVT_2403002A_127.exe.4334350.3.raw.unpack, ajUyEO0gYae1kdByrk.cs |
High entropy of concatenated method names: 'U5pIXQYXC5', 'm3SIVrrGRZ', 'EiLSvZJZoX', 'LI8SuLHTaE', 'DWWI9kdOEM', 'A6wIib3TkX', 'EQ6In2EBrL', 'r5fIKpiEHP', 'DERIHvrney', 'e08ILEML5p' |
Source: 0.2.LisectAVT_2403002A_127.exe.4334350.3.raw.unpack, mcP8dfxCsy0XIot8V2.cs |
High entropy of concatenated method names: 'KdR51LjgZq', 'DyD5EDefN0', 'UXC5bDqeFl', 'DiX5ZgAmde', 'fqe5gJ5oAg', 'PRS5tC4QlC', 'Gqk5IoXpHu', 'X3Q5SbwIEA', 'Vob56v3OnS', 'jZa5ynRhZC' |
Source: 0.2.LisectAVT_2403002A_127.exe.4334350.3.raw.unpack, erqSUTsy0FA1KhqLIs.cs |
High entropy of concatenated method names: 'pEQuBkUejR', 'VBPuP0JLvt', 'vwjuwLv0y1', 'RHourNLG43', 'sTjugV521J', 'T07utB3lao', 'RItiAfCBvB5x6h7b5a', 'Nw9PSvAv655kLoFC4J', 'NJVFWi7LBvbvj7Z3Bu', 'kruuuxuqkh' |
Source: 0.2.LisectAVT_2403002A_127.exe.4334350.3.raw.unpack, OoFyZfoyccIPM6eUm3.cs |
High entropy of concatenated method names: 'DJpSG05kw7', 'A6gSx4vgYy', 'k3TS5lAbbm', 'tXVSkXvI8X', 'tsZSCvym87', 'RVkSBX8367', 'Le3SPY1Ffm', 'UgLS485LXE', 'lwlSwm1Vj2', 'E9eSrl0NCk' |
Source: 0.2.LisectAVT_2403002A_127.exe.4334350.3.raw.unpack, W2xqs255xweGuk9IvRb.cs |
High entropy of concatenated method names: 'ToString', 'LfOyMiVwAd', 'buPy7bvvAd', 'MIIyTCh6Ls', 'Q1XyGTmcTm', 'w3fyxbZQxq', 'wlAy5318VN', 'knhykJUyQV', 'Pwkoa3jai4QaaQF4vGg', 'HNkQMGjbjWh4TEenjmJ' |
Source: 0.2.LisectAVT_2403002A_127.exe.4334350.3.raw.unpack, kdFuKdGJyNY9AlcONn.cs |
High entropy of concatenated method names: 'UA1g8fJH8V', 'a4wgijuDJx', 'v50gK0G6Up', 'w4DgHFunli', 'eFxgD9LyN1', 'K0dg2A78nN', 'vGJgYkmwrk', 'fb7goxEf84', 'WPdgsAoLhO', 're9gUfpgjY' |
Source: 0.2.LisectAVT_2403002A_127.exe.4334350.3.raw.unpack, rYxoLNI0oTSuT0iyWI.cs |
High entropy of concatenated method names: 'dDsBGWkORU', 'cq2B5brhxX', 'yTRBCMwHLe', 'sOWCVDovrm', 'rYmCz1jVn1', 'ElKBvE8gfY', 'zH9BuAAfbA', 'rxXBhEbWam', 'pZvBMg7FAJ', 'LqGB7Dv5tp' |
Source: 0.2.LisectAVT_2403002A_127.exe.57e0000.6.raw.unpack, kdFvaMFVPKs73pA7Ae.cs |
High entropy of concatenated method names: 'jlLbsIppcp4pe', 'HUDVafGQx3A5lYPXEbC', 'bWxlDPGFKtjOUjq8ME9', 'J13JY7Gs9VegMR0Usdn', 'gjnvHYGCPTFBSN5sXDA', 'UXn9pRGVr5JYGFjuCRJ', 'g8bQ3yGYPoLwrRusK3E', 'KwwAwLG5jtFVjgr5V0l', 'lJyLiGG0wAjthymuVo5', 'KrHGd2G9wj507LdZGDe' |
Source: 0.2.LisectAVT_2403002A_127.exe.57e0000.6.raw.unpack, DD.cs |
High entropy of concatenated method names: 'wgRxinKHcbWANUbFNm', 'dwveif1E9jqp4XTbTA', 'iYTXHL2SDoNZBJVsGw', 'hFySdn3keDBvJSvKal', 'PVIytPpWpuEYQLk40u' |
Source: 0.2.LisectAVT_2403002A_127.exe.57e0000.6.raw.unpack, ihWImL1h2qjtIkVYDh.cs |
High entropy of concatenated method names: 'qJUttacKFT', 'djwp7oGHZ8xfNf3m5ut', 'AZqALCG67UykKuowXP2', 'dkLCJpGlCfFdqtD7Epf', 'iHWSkAGjDuGN31hXJsT', 'u4UYnDGE5xCOMnt15QR', 'jhES7Va4c', 'jWmROKkjL', 'Dispose', 'BJj7gBhfp' |
Source: 0.2.LisectAVT_2403002A_127.exe.57e0000.6.raw.unpack, oImfMJtvGUo8fMQNBQ.cs |
High entropy of concatenated method names: 'cxsORewNJ', 'VvrninWuk', 'ustvIxt9o', 'QtXoY7g0N', 'cMKlMbnQu', 'w2KLAB5Xx', 'hNkF6TG2YCh7xU8s3hJ', 'hs4l1PGKtLhAeRnm1c4', 'Dispose', 'MoveNext' |
Source: 0.2.LisectAVT_2403002A_127.exe.57e0000.6.raw.unpack, wehuuoKhMKMbnQu72K.cs |
High entropy of concatenated method names: 'NXMyxc8eI', 'GTZadPHeP', 'DEVNaDCj9', 'cflmBNqev', 'VFQ0OImLC', 'PbYVMxZvt', 'UPdFjbLed', 'AeEi93ui9', 'oM66buTLn', 'nxFUIfcfn' |
Source: 0.2.LisectAVT_2403002A_127.exe.2f75dd4.2.raw.unpack, kdFvaMFVPKs73pA7Ae.cs |
High entropy of concatenated method names: 'jlLbsIppcp4pe', 'HUDVafGQx3A5lYPXEbC', 'bWxlDPGFKtjOUjq8ME9', 'J13JY7Gs9VegMR0Usdn', 'gjnvHYGCPTFBSN5sXDA', 'UXn9pRGVr5JYGFjuCRJ', 'g8bQ3yGYPoLwrRusK3E', 'KwwAwLG5jtFVjgr5V0l', 'lJyLiGG0wAjthymuVo5', 'KrHGd2G9wj507LdZGDe' |
Source: 0.2.LisectAVT_2403002A_127.exe.2f75dd4.2.raw.unpack, DD.cs |
High entropy of concatenated method names: 'wgRxinKHcbWANUbFNm', 'dwveif1E9jqp4XTbTA', 'iYTXHL2SDoNZBJVsGw', 'hFySdn3keDBvJSvKal', 'PVIytPpWpuEYQLk40u' |
Source: 0.2.LisectAVT_2403002A_127.exe.2f75dd4.2.raw.unpack, ihWImL1h2qjtIkVYDh.cs |
High entropy of concatenated method names: 'qJUttacKFT', 'djwp7oGHZ8xfNf3m5ut', 'AZqALCG67UykKuowXP2', 'dkLCJpGlCfFdqtD7Epf', 'iHWSkAGjDuGN31hXJsT', 'u4UYnDGE5xCOMnt15QR', 'jhES7Va4c', 'jWmROKkjL', 'Dispose', 'BJj7gBhfp' |
Source: 0.2.LisectAVT_2403002A_127.exe.2f75dd4.2.raw.unpack, oImfMJtvGUo8fMQNBQ.cs |
High entropy of concatenated method names: 'cxsORewNJ', 'VvrninWuk', 'ustvIxt9o', 'QtXoY7g0N', 'cMKlMbnQu', 'w2KLAB5Xx', 'hNkF6TG2YCh7xU8s3hJ', 'hs4l1PGKtLhAeRnm1c4', 'Dispose', 'MoveNext' |
Source: 0.2.LisectAVT_2403002A_127.exe.2f75dd4.2.raw.unpack, wehuuoKhMKMbnQu72K.cs |
High entropy of concatenated method names: 'NXMyxc8eI', 'GTZadPHeP', 'DEVNaDCj9', 'cflmBNqev', 'VFQ0OImLC', 'PbYVMxZvt', 'UPdFjbLed', 'AeEi93ui9', 'oM66buTLn', 'nxFUIfcfn' |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Thread delayed: delay time: 922337203685477 |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Thread delayed: delay time: 922337203685477 |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Thread delayed: delay time: 600000 |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Thread delayed: delay time: 599891 |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Thread delayed: delay time: 599778 |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Thread delayed: delay time: 599672 |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Thread delayed: delay time: 599563 |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Thread delayed: delay time: 599438 |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Thread delayed: delay time: 599328 |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Thread delayed: delay time: 599219 |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Thread delayed: delay time: 599094 |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Thread delayed: delay time: 598984 |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Thread delayed: delay time: 598875 |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Thread delayed: delay time: 598766 |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Thread delayed: delay time: 598656 |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Thread delayed: delay time: 598547 |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Thread delayed: delay time: 598423 |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Thread delayed: delay time: 598297 |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Thread delayed: delay time: 598188 |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Thread delayed: delay time: 598063 |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Thread delayed: delay time: 597953 |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Thread delayed: delay time: 597844 |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Thread delayed: delay time: 597722 |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Thread delayed: delay time: 597594 |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Thread delayed: delay time: 597485 |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Thread delayed: delay time: 597374 |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Thread delayed: delay time: 597266 |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Thread delayed: delay time: 597141 |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Thread delayed: delay time: 597016 |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Thread delayed: delay time: 596906 |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Thread delayed: delay time: 596797 |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Thread delayed: delay time: 596688 |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Thread delayed: delay time: 596563 |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Thread delayed: delay time: 596438 |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Thread delayed: delay time: 596328 |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Thread delayed: delay time: 596219 |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Thread delayed: delay time: 596094 |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Thread delayed: delay time: 595985 |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Thread delayed: delay time: 595860 |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Thread delayed: delay time: 595735 |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Thread delayed: delay time: 595610 |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Thread delayed: delay time: 595485 |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Thread delayed: delay time: 595360 |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Thread delayed: delay time: 595235 |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Thread delayed: delay time: 595110 |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Thread delayed: delay time: 594985 |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Thread delayed: delay time: 594860 |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Thread delayed: delay time: 594735 |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Thread delayed: delay time: 594595 |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Thread delayed: delay time: 594469 |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Thread delayed: delay time: 594359 |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Thread delayed: delay time: 594250 |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe TID: 5880 |
Thread sleep time: -922337203685477s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe TID: 3784 |
Thread sleep time: -28592453314249787s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe TID: 3784 |
Thread sleep time: -600000s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe TID: 3784 |
Thread sleep time: -599891s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe TID: 3784 |
Thread sleep time: -599778s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe TID: 3784 |
Thread sleep time: -599672s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe TID: 3784 |
Thread sleep time: -599563s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe TID: 3784 |
Thread sleep time: -599438s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe TID: 3784 |
Thread sleep time: -599328s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe TID: 3784 |
Thread sleep time: -599219s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe TID: 3784 |
Thread sleep time: -599094s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe TID: 3784 |
Thread sleep time: -598984s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe TID: 3784 |
Thread sleep time: -598875s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe TID: 3784 |
Thread sleep time: -598766s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe TID: 3784 |
Thread sleep time: -598656s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe TID: 3784 |
Thread sleep time: -598547s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe TID: 3784 |
Thread sleep time: -598423s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe TID: 3784 |
Thread sleep time: -598297s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe TID: 3784 |
Thread sleep time: -598188s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe TID: 3784 |
Thread sleep time: -598063s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe TID: 3784 |
Thread sleep time: -597953s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe TID: 3784 |
Thread sleep time: -597844s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe TID: 3784 |
Thread sleep time: -597722s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe TID: 3784 |
Thread sleep time: -597594s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe TID: 3784 |
Thread sleep time: -597485s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe TID: 3784 |
Thread sleep time: -597374s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe TID: 3784 |
Thread sleep time: -597266s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe TID: 3784 |
Thread sleep time: -597141s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe TID: 3784 |
Thread sleep time: -597016s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe TID: 3784 |
Thread sleep time: -596906s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe TID: 3784 |
Thread sleep time: -596797s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe TID: 3784 |
Thread sleep time: -596688s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe TID: 3784 |
Thread sleep time: -596563s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe TID: 3784 |
Thread sleep time: -596438s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe TID: 3784 |
Thread sleep time: -596328s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe TID: 3784 |
Thread sleep time: -596219s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe TID: 3784 |
Thread sleep time: -596094s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe TID: 3784 |
Thread sleep time: -595985s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe TID: 3784 |
Thread sleep time: -595860s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe TID: 3784 |
Thread sleep time: -595735s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe TID: 3784 |
Thread sleep time: -595610s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe TID: 3784 |
Thread sleep time: -595485s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe TID: 3784 |
Thread sleep time: -595360s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe TID: 3784 |
Thread sleep time: -595235s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe TID: 3784 |
Thread sleep time: -595110s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe TID: 3784 |
Thread sleep time: -594985s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe TID: 3784 |
Thread sleep time: -594860s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe TID: 3784 |
Thread sleep time: -594735s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe TID: 3784 |
Thread sleep time: -594595s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe TID: 3784 |
Thread sleep time: -594469s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe TID: 3784 |
Thread sleep time: -594359s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe TID: 3784 |
Thread sleep time: -594250s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
WMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Thread delayed: delay time: 922337203685477 |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Thread delayed: delay time: 922337203685477 |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Thread delayed: delay time: 600000 |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Thread delayed: delay time: 599891 |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Thread delayed: delay time: 599778 |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Thread delayed: delay time: 599672 |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Thread delayed: delay time: 599563 |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Thread delayed: delay time: 599438 |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Thread delayed: delay time: 599328 |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Thread delayed: delay time: 599219 |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Thread delayed: delay time: 599094 |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Thread delayed: delay time: 598984 |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Thread delayed: delay time: 598875 |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Thread delayed: delay time: 598766 |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Thread delayed: delay time: 598656 |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Thread delayed: delay time: 598547 |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Thread delayed: delay time: 598423 |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Thread delayed: delay time: 598297 |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Thread delayed: delay time: 598188 |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Thread delayed: delay time: 598063 |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Thread delayed: delay time: 597953 |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Thread delayed: delay time: 597844 |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Thread delayed: delay time: 597722 |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Thread delayed: delay time: 597594 |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Thread delayed: delay time: 597485 |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Thread delayed: delay time: 597374 |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Thread delayed: delay time: 597266 |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Thread delayed: delay time: 597141 |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Thread delayed: delay time: 597016 |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Thread delayed: delay time: 596906 |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Thread delayed: delay time: 596797 |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Thread delayed: delay time: 596688 |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Thread delayed: delay time: 596563 |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Thread delayed: delay time: 596438 |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Thread delayed: delay time: 596328 |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Thread delayed: delay time: 596219 |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Thread delayed: delay time: 596094 |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Thread delayed: delay time: 595985 |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Thread delayed: delay time: 595860 |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Thread delayed: delay time: 595735 |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Thread delayed: delay time: 595610 |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Thread delayed: delay time: 595485 |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Thread delayed: delay time: 595360 |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Thread delayed: delay time: 595235 |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Thread delayed: delay time: 595110 |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Thread delayed: delay time: 594985 |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Thread delayed: delay time: 594860 |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Thread delayed: delay time: 594735 |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Thread delayed: delay time: 594595 |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Thread delayed: delay time: 594469 |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Thread delayed: delay time: 594359 |
Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_127.exe |
Thread delayed: delay time: 594250 |
Jump to behavior |