Source: LisectAVT_2403002A_124.exe, 00000002.00000002.2914893392.00000000032F1000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name |
Source: LisectAVT_2403002A_124.exe, 00000002.00000002.2914893392.0000000003367000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://smtp.flying-fish-cn.com |
Source: LisectAVT_2403002A_124.exe, 00000002.00000002.2914893392.0000000003367000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://us2.smtp.mailhostbox.com |
Source: LisectAVT_2403002A_124.exe, 00000000.00000002.1710237885.0000000006912000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.apache.org/licenses/LICENSE-2.0 |
Source: LisectAVT_2403002A_124.exe, 00000000.00000002.1710237885.0000000006912000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.carterandcone.coml |
Source: LisectAVT_2403002A_124.exe, 00000000.00000002.1710237885.0000000006912000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.fontbureau.com |
Source: LisectAVT_2403002A_124.exe, 00000000.00000002.1710237885.0000000006912000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.fontbureau.com/designers |
Source: LisectAVT_2403002A_124.exe, 00000000.00000002.1710237885.0000000006912000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.fontbureau.com/designers/? |
Source: LisectAVT_2403002A_124.exe, 00000000.00000002.1710237885.0000000006912000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.fontbureau.com/designers/cabarga.htmlN |
Source: LisectAVT_2403002A_124.exe, 00000000.00000002.1710237885.0000000006912000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.fontbureau.com/designers/frere-user.html |
Source: LisectAVT_2403002A_124.exe, 00000000.00000002.1710237885.0000000006912000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.fontbureau.com/designers8 |
Source: LisectAVT_2403002A_124.exe, 00000000.00000002.1710237885.0000000006912000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.fontbureau.com/designers? |
Source: LisectAVT_2403002A_124.exe, 00000000.00000002.1710237885.0000000006912000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.fontbureau.com/designersG |
Source: LisectAVT_2403002A_124.exe, 00000000.00000002.1710237885.0000000006912000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.fonts.com |
Source: LisectAVT_2403002A_124.exe, 00000000.00000002.1710237885.0000000006912000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.founder.com.cn/cn |
Source: LisectAVT_2403002A_124.exe, 00000000.00000002.1710237885.0000000006912000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.founder.com.cn/cn/bThe |
Source: LisectAVT_2403002A_124.exe, 00000000.00000002.1710237885.0000000006912000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.founder.com.cn/cn/cThe |
Source: LisectAVT_2403002A_124.exe, 00000000.00000002.1710237885.0000000006912000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.galapagosdesign.com/DPlease |
Source: LisectAVT_2403002A_124.exe, 00000000.00000002.1710237885.0000000006912000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.galapagosdesign.com/staff/dennis.htm |
Source: LisectAVT_2403002A_124.exe, 00000000.00000002.1710237885.0000000006912000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.goodfont.co.kr |
Source: LisectAVT_2403002A_124.exe, 00000000.00000002.1707385764.0000000002841000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.google.com |
Source: LisectAVT_2403002A_124.exe | String found in binary or memory: http://www.google.com)Uygun |
Source: LisectAVT_2403002A_124.exe, 00000000.00000002.1710237885.0000000006912000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.jiyu-kobo.co.jp/ |
Source: LisectAVT_2403002A_124.exe, 00000000.00000002.1710237885.0000000006912000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.sajatypeworks.com |
Source: LisectAVT_2403002A_124.exe, 00000000.00000002.1710237885.0000000006912000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.sakkal.com |
Source: LisectAVT_2403002A_124.exe, 00000000.00000002.1710237885.0000000006912000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.sandoll.co.kr |
Source: LisectAVT_2403002A_124.exe, 00000000.00000002.1710237885.0000000006912000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.tiro.com |
Source: LisectAVT_2403002A_124.exe, 00000000.00000002.1710237885.0000000006912000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.typography.netD |
Source: LisectAVT_2403002A_124.exe, 00000000.00000002.1710237885.0000000006912000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.urwpp.deDPlease |
Source: LisectAVT_2403002A_124.exe, 00000000.00000002.1710237885.0000000006912000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.zhongyicts.com.cn |
Source: LisectAVT_2403002A_124.exe, 00000000.00000002.1707848434.00000000044A2000.00000004.00000800.00020000.00000000.sdmp, LisectAVT_2403002A_124.exe, 00000000.00000002.1707848434.0000000003B85000.00000004.00000800.00020000.00000000.sdmp, LisectAVT_2403002A_124.exe, 00000002.00000002.2912873981.0000000000402000.00000040.00000400.00020000.00000000.sdmp | String found in binary or memory: https://account.dyn.com/ |
Source: LisectAVT_2403002A_124.exe, 00000000.00000002.1707848434.00000000044A2000.00000004.00000800.00020000.00000000.sdmp, LisectAVT_2403002A_124.exe, 00000000.00000002.1707848434.0000000003B85000.00000004.00000800.00020000.00000000.sdmp, LisectAVT_2403002A_124.exe, 00000002.00000002.2912873981.0000000000402000.00000040.00000400.00020000.00000000.sdmp, LisectAVT_2403002A_124.exe, 00000002.00000002.2914893392.00000000032F1000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://api.ipify.org |
Source: LisectAVT_2403002A_124.exe, 00000002.00000002.2914893392.00000000032F1000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://api.ipify.org/ |
Source: LisectAVT_2403002A_124.exe, 00000002.00000002.2914893392.00000000032F1000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://api.ipify.org/t |
Source: LisectAVT_2403002A_124.exe | String found in binary or memory: https://www.google.com |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Section loaded: dwrite.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Section loaded: windowscodecs.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Section loaded: wbemcomn.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Section loaded: rasapi32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Section loaded: rasman.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Section loaded: rtutils.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Section loaded: dhcpcsvc6.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Section loaded: dhcpcsvc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Section loaded: dnsapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Section loaded: winnsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Section loaded: rasadhlp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Section loaded: fwpuclnt.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Section loaded: secur32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Section loaded: schannel.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Section loaded: mskeyprotect.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Section loaded: ntasn1.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Section loaded: ncrypt.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Section loaded: ncryptsslp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Section loaded: vaultcli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: 0.2.LisectAVT_2403002A_124.exe.7880000.8.raw.unpack, ruBmFpm4X0qjugVge7.cs | High entropy of concatenated method names: 'S4hYDT4hVy', 'jAUYI7axYT', 'WZJY3Elr6k', 'D9vY5ClB2P', 'JPAYKEccgk', 'dfQYbwDAe4', 'bvtYU9uIZF', 't4XYeJXCPk', 'blRpIpNBtSFVJVgOtym', 'zn89spNTw3lQBjZuXW0' |
Source: 0.2.LisectAVT_2403002A_124.exe.7880000.8.raw.unpack, pbkn9fEkmSVUYuCkvS.cs | High entropy of concatenated method names: 'lHAdaoBRre', 'JaidMqqhXx', 'Y1Hdx2BHyj', 'cgMdml8sG5', 'evidHNviOb', 'rENdJuVf2K', 'Next', 'Next', 'Next', 'NextBytes' |
Source: 0.2.LisectAVT_2403002A_124.exe.7880000.8.raw.unpack, bCFVduyjvCLQ4fLpy0.cs | High entropy of concatenated method names: 'wVEViUOos6', 'r8lV9C90dY', 'Cu6VcWblV1', 'xIrVRMiUm5', 'BgrV0ZU9Zh', 'KiiVFVexeN', 'bwhNZhreVx9QTSVG0w', 'jdLKgLcQa0AmHv311O', 'uvrVVft53X', 'XmXV6aaUBF' |
Source: 0.2.LisectAVT_2403002A_124.exe.7880000.8.raw.unpack, utNK7KUu6WblV1IIrM.cs | High entropy of concatenated method names: 'u57w513MuX', 've8wKvxG4J', 'BUswpC97rF', 'AH1wUhhCGV', 'l4Kw0MuSQo', 'BGXwFTAob0', 'pRKwtxxR0x', 'FA1wdWAmln', 'uVUwnYF3GV', 'Qk3wPHjDp4' |
Source: 0.2.LisectAVT_2403002A_124.exe.7880000.8.raw.unpack, PCflYOVCbwNgY8uR9ZV.cs | High entropy of concatenated method names: 'Eq2PI2KXmg', 'ksQPAKLZVi', 'mARP36VN2A', 'hCcOsY6jUSI9Nca7Q7u', 'G2QdN56zs4G0utlihuh', 'rHDVFVo2eP8gP5SJLbU', 'nxb3SZoYIeG1bDEO3ns' |
Source: 0.2.LisectAVT_2403002A_124.exe.7880000.8.raw.unpack, jUm5kmeyT99nKKgrZU.cs | High entropy of concatenated method names: 'eoUogLSHGI', 'uimobCU8VR', 'agZwxtZ9OU', 'ElswmJNOtg', 'B5qwJY8Wud', 'k18wZApgRe', 'WqYwToDcdY', 'vZbwG7Ugkt', 'n4ZwhUiEdd', 'odiwvoNa0h' |
Source: 0.2.LisectAVT_2403002A_124.exe.7880000.8.raw.unpack, srpiv49bMTiOWAWIP3.cs | High entropy of concatenated method names: 'LQc6r3Ccfh', 'FT861NkfK7', 'tQj6OcUoEm', 't4J6wGECDN', 'Wbt6oynHcT', 'CUg6Yt0Ve2', 'Txq6iqA8ca', 'Mk169Ivt6i', 'RRR68FfJIH', 'B1m6cwsllV' |
Source: 0.2.LisectAVT_2403002A_124.exe.7880000.8.raw.unpack, FKwAAtV6FrV5jsHTDqJ.cs | High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'Ry6PHS53I9', 'dpTP7YsDgW', 'FVNPl45Yqb', 'TPwPjFULh1', 'Nd0PkFclPS', 'LNmPWqdmOO', 'IMCPBw8vBt' |
Source: 0.2.LisectAVT_2403002A_124.exe.7880000.8.raw.unpack, sFUK1VC6q0OH8xExVy.cs | High entropy of concatenated method names: 'Vu334ekEs', 'JPq5pkCYl', 'WUDKRxgn6', 'ckrbxrSGa', 'IchU9ofiK', 'X43epn0Me', 'c8wa7WVXO5p3CEhh0w', 'vsNR35OlBJNIyrESnk', 'cqTdg8wto', 'PcNPN6oVE' |
Source: 0.2.LisectAVT_2403002A_124.exe.7880000.8.raw.unpack, kZhTiiaVexeNqOxELb.cs | High entropy of concatenated method names: 'UJiYrEPrQg', 'i6hYOVE34B', 'cJsYoqIbgU', 'uk1Yifve6j', 'mV1Y9fXm8M', 'VwcokXrvsr', 'hnSoWeDnv0', 'VItoBA5kHC', 'wAAouxNIAE', 'yM5oEtCRiv' |
Source: 0.2.LisectAVT_2403002A_124.exe.7880000.8.raw.unpack, MGTbHnl7vRYKMihGcc.cs | High entropy of concatenated method names: 'ToString', 'IgXF4346SE', 'isDFMUf9AG', 'T0HFxR3jWV', 'DjhFmL2WFf', 'j9JFJXMBtu', 'KLiFZurmi8', 'M1cFTg7qNM', 'U3DFGY1yGm', 'dkAFhJtNxh' |
Source: 0.2.LisectAVT_2403002A_124.exe.7880000.8.raw.unpack, INEnmnwF2qjVFH3cOR.cs | High entropy of concatenated method names: 'EditValue', 'GetEditStyle', 'glQCENeRIn', 'JYnCsOGBMY', 'AddCzwWwEr', 'Jbm6QsnyU7', 'CId6Vn8Pxv', 'upF6CQCx0S', 'yZm665kBk2', 'LgIL0TY7J5e1o8b17jT' |
Source: 0.2.LisectAVT_2403002A_124.exe.7880000.8.raw.unpack, mKDuTFVQE6QgBE6HCcr.cs | High entropy of concatenated method names: 'vdRnIakyo5', 'TwGnALl85N', 'XcXn3IceEe', 'Yfdn5ELvNx', 'KkZngSsdWt', 'Gg6nKXoeI8', 'Wm4nbsn1rN', 'krPnptNVOk', 'joSnUVNB7X', 'JUpnewItqN' |
Source: 0.2.LisectAVT_2403002A_124.exe.7880000.8.raw.unpack, k57hQczJTqFB4cKpLm.cs | High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'dWdnfZHMYu', 'Y4mn0l4tKP', 'FJlnFj7Dxn', 'jwPntvYLoC', 'DcNndoSHBq', 'kXrnnNny7M', 'qHQnPf59NG' |
Source: 0.2.LisectAVT_2403002A_124.exe.7880000.8.raw.unpack, TKpoFdOdwZBGcjEya7.cs | High entropy of concatenated method names: 'Dispose', 'atLVELYDVW', 'ayWCM2W53b', 's2nkkVcXR5', 'EofVsypCIY', 'AZlVzmt0Jr', 'ProcessDialogKey', 'EatCQbkn9f', 'UmSCVVUYuC', 'UvSCC26Awx' |
Source: 0.2.LisectAVT_2403002A_124.exe.7880000.8.raw.unpack, h8oSwShDsT51Fkc3yZ.cs | High entropy of concatenated method names: 'HSaiISTUjr', 'BKGiAGlGxD', 'VWqi3y98Cf', 'Fd4i5iTLI1', 'YXIiggRcQf', 'uhLiKFCL1r', 'SRHibyoaIj', 'lwpipg8lGw', 'ziYiU2oJZA', 'Fvpie7w4WZ' |
Source: 0.2.LisectAVT_2403002A_124.exe.7880000.8.raw.unpack, HSCItCjxsCrf5YKUOC.cs | High entropy of concatenated method names: 'rhWtcfRHdr', 'TGytR702cU', 'ToString', 'WH0t1u4ebR', 'ISxtOkH5Aw', 'q6ltwW2hc3', 'AZBtouaDnV', 'xaptYgkqpP', 'o0Rti0eyRB', 'EPTt9XwWOq' |
Source: 0.2.LisectAVT_2403002A_124.exe.7880000.8.raw.unpack, VVbjCDHVDfIQWckVYA.cs | High entropy of concatenated method names: 'TQV0vXSQnI', 'Cm10SOm0JP', 'XJ50H7Pvb8', 'mG707jxOrt', 'JVy0Mg597M', 'd3X0xFoRKE', 'hLZ0mxEQq2', 'R1E0JZXhDk', 'h2p0Z3GSru', 'qcy0T9H2Yc' |
Source: 0.2.LisectAVT_2403002A_124.exe.7880000.8.raw.unpack, XUOos6pd8lC90dYS16.cs | High entropy of concatenated method names: 'FrjOHoh6oI', 'LpkO70PuUI', 'rEsOlOTfKJ', 'cJiOj3ujJd', 'rZ2OkKYydR', 'QegOWk5kdB', 'bxoOBqqcvv', 'cTlOufJaqH', 'sE6OE5qpon', 'HbCOsmAMY7' |
Source: 0.2.LisectAVT_2403002A_124.exe.7880000.8.raw.unpack, hfypCIuY5Zlmt0JrUa.cs | High entropy of concatenated method names: 'k67d1Fm3Id', 'B5ndOCrnSo', 'KpndwmxoOe', 'dhPdo3uY82', 'dRVdYVHO9a', 'iOvdifxfDX', 'VpJd93sMuw', 'ua4d8hxpuC', 'iY0dcOslpR', 'IUhdRo9Ws4' |
Source: 0.2.LisectAVT_2403002A_124.exe.7880000.8.raw.unpack, icaxvCZ6aqZ3PiHMdJ.cs | High entropy of concatenated method names: 'H6OYlXsbK8', 'IsfYjvRcsM', 'MauYkqxqAg', 'ToString', 'oIMYWCMWjR', 'zOgYBXx1xq', 'Mk5OU7N3A0LruHsmAVI', 'G3Jy3MN0KlSPVL2MDiG', 'BiJGZSNXiGFkErotq7A' |
Source: 0.2.LisectAVT_2403002A_124.exe.7880000.8.raw.unpack, u6AwxmslUiHFvQuVn9.cs | High entropy of concatenated method names: 'McGnVrXXJT', 'KMKn6MnUaT', 'ms3ny8Giga', 'E0cn1hCbRC', 'amPnOcNo3f', 'KdAnoIAOWU', 'Sx8nYGe1Pe', 'XasdBGJOXS', 'dJtduLDXEy', 'zxXdEvFIm8' |
Source: 0.2.LisectAVT_2403002A_124.exe.7880000.8.raw.unpack, JRGbcDWbZCZ666nwc5.cs | High entropy of concatenated method names: 'MdItuyMSay', 'T1atsy64Zh', 'O2HdQiT6tI', 'mR6dVbDkxT', 'mSdt4mysjB', 'EFHtSZJ70x', 'UKQtqnn787', 'xvCtHJxETa', 'dnnt7Agea9', 'SmmtlmSuoi' |
Source: 0.2.LisectAVT_2403002A_124.exe.7880000.8.raw.unpack, KE2aSiTVAwAGmbGpIg.cs | High entropy of concatenated method names: 'rNai1r1vmg', 'cUOiwVfxye', 'ytbiYJR4uB', 'P4EYswsWIy', 'q9ZYzk6uPr', 'Og3iQlyA8s', 'qRFiVXjsRO', 'jYWiCqw3U2', 'Pchi6olICk', 'ne8iylpMdb' |
Source: 0.2.LisectAVT_2403002A_124.exe.7880000.8.raw.unpack, Vu60JKqx5NHLYX2BnX.cs | High entropy of concatenated method names: 'eZufpmlTjY', 'PblfU4x0uC', 'Drlfal8UGK', 'wnZfMy8mBe', 'rjXfm9aGps', 'YaLfJoEpbm', 'bblfTAvpSr', 'mVffGBQ8MS', 'j5kfvDhtgS', 'k1kf4POctu' |
Source: 0.2.LisectAVT_2403002A_124.exe.3c25f30.3.raw.unpack, ruBmFpm4X0qjugVge7.cs | High entropy of concatenated method names: 'S4hYDT4hVy', 'jAUYI7axYT', 'WZJY3Elr6k', 'D9vY5ClB2P', 'JPAYKEccgk', 'dfQYbwDAe4', 'bvtYU9uIZF', 't4XYeJXCPk', 'blRpIpNBtSFVJVgOtym', 'zn89spNTw3lQBjZuXW0' |
Source: 0.2.LisectAVT_2403002A_124.exe.3c25f30.3.raw.unpack, pbkn9fEkmSVUYuCkvS.cs | High entropy of concatenated method names: 'lHAdaoBRre', 'JaidMqqhXx', 'Y1Hdx2BHyj', 'cgMdml8sG5', 'evidHNviOb', 'rENdJuVf2K', 'Next', 'Next', 'Next', 'NextBytes' |
Source: 0.2.LisectAVT_2403002A_124.exe.3c25f30.3.raw.unpack, bCFVduyjvCLQ4fLpy0.cs | High entropy of concatenated method names: 'wVEViUOos6', 'r8lV9C90dY', 'Cu6VcWblV1', 'xIrVRMiUm5', 'BgrV0ZU9Zh', 'KiiVFVexeN', 'bwhNZhreVx9QTSVG0w', 'jdLKgLcQa0AmHv311O', 'uvrVVft53X', 'XmXV6aaUBF' |
Source: 0.2.LisectAVT_2403002A_124.exe.3c25f30.3.raw.unpack, utNK7KUu6WblV1IIrM.cs | High entropy of concatenated method names: 'u57w513MuX', 've8wKvxG4J', 'BUswpC97rF', 'AH1wUhhCGV', 'l4Kw0MuSQo', 'BGXwFTAob0', 'pRKwtxxR0x', 'FA1wdWAmln', 'uVUwnYF3GV', 'Qk3wPHjDp4' |
Source: 0.2.LisectAVT_2403002A_124.exe.3c25f30.3.raw.unpack, PCflYOVCbwNgY8uR9ZV.cs | High entropy of concatenated method names: 'Eq2PI2KXmg', 'ksQPAKLZVi', 'mARP36VN2A', 'hCcOsY6jUSI9Nca7Q7u', 'G2QdN56zs4G0utlihuh', 'rHDVFVo2eP8gP5SJLbU', 'nxb3SZoYIeG1bDEO3ns' |
Source: 0.2.LisectAVT_2403002A_124.exe.3c25f30.3.raw.unpack, jUm5kmeyT99nKKgrZU.cs | High entropy of concatenated method names: 'eoUogLSHGI', 'uimobCU8VR', 'agZwxtZ9OU', 'ElswmJNOtg', 'B5qwJY8Wud', 'k18wZApgRe', 'WqYwToDcdY', 'vZbwG7Ugkt', 'n4ZwhUiEdd', 'odiwvoNa0h' |
Source: 0.2.LisectAVT_2403002A_124.exe.3c25f30.3.raw.unpack, srpiv49bMTiOWAWIP3.cs | High entropy of concatenated method names: 'LQc6r3Ccfh', 'FT861NkfK7', 'tQj6OcUoEm', 't4J6wGECDN', 'Wbt6oynHcT', 'CUg6Yt0Ve2', 'Txq6iqA8ca', 'Mk169Ivt6i', 'RRR68FfJIH', 'B1m6cwsllV' |
Source: 0.2.LisectAVT_2403002A_124.exe.3c25f30.3.raw.unpack, FKwAAtV6FrV5jsHTDqJ.cs | High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'Ry6PHS53I9', 'dpTP7YsDgW', 'FVNPl45Yqb', 'TPwPjFULh1', 'Nd0PkFclPS', 'LNmPWqdmOO', 'IMCPBw8vBt' |
Source: 0.2.LisectAVT_2403002A_124.exe.3c25f30.3.raw.unpack, sFUK1VC6q0OH8xExVy.cs | High entropy of concatenated method names: 'Vu334ekEs', 'JPq5pkCYl', 'WUDKRxgn6', 'ckrbxrSGa', 'IchU9ofiK', 'X43epn0Me', 'c8wa7WVXO5p3CEhh0w', 'vsNR35OlBJNIyrESnk', 'cqTdg8wto', 'PcNPN6oVE' |
Source: 0.2.LisectAVT_2403002A_124.exe.3c25f30.3.raw.unpack, kZhTiiaVexeNqOxELb.cs | High entropy of concatenated method names: 'UJiYrEPrQg', 'i6hYOVE34B', 'cJsYoqIbgU', 'uk1Yifve6j', 'mV1Y9fXm8M', 'VwcokXrvsr', 'hnSoWeDnv0', 'VItoBA5kHC', 'wAAouxNIAE', 'yM5oEtCRiv' |
Source: 0.2.LisectAVT_2403002A_124.exe.3c25f30.3.raw.unpack, MGTbHnl7vRYKMihGcc.cs | High entropy of concatenated method names: 'ToString', 'IgXF4346SE', 'isDFMUf9AG', 'T0HFxR3jWV', 'DjhFmL2WFf', 'j9JFJXMBtu', 'KLiFZurmi8', 'M1cFTg7qNM', 'U3DFGY1yGm', 'dkAFhJtNxh' |
Source: 0.2.LisectAVT_2403002A_124.exe.3c25f30.3.raw.unpack, INEnmnwF2qjVFH3cOR.cs | High entropy of concatenated method names: 'EditValue', 'GetEditStyle', 'glQCENeRIn', 'JYnCsOGBMY', 'AddCzwWwEr', 'Jbm6QsnyU7', 'CId6Vn8Pxv', 'upF6CQCx0S', 'yZm665kBk2', 'LgIL0TY7J5e1o8b17jT' |
Source: 0.2.LisectAVT_2403002A_124.exe.3c25f30.3.raw.unpack, mKDuTFVQE6QgBE6HCcr.cs | High entropy of concatenated method names: 'vdRnIakyo5', 'TwGnALl85N', 'XcXn3IceEe', 'Yfdn5ELvNx', 'KkZngSsdWt', 'Gg6nKXoeI8', 'Wm4nbsn1rN', 'krPnptNVOk', 'joSnUVNB7X', 'JUpnewItqN' |
Source: 0.2.LisectAVT_2403002A_124.exe.3c25f30.3.raw.unpack, k57hQczJTqFB4cKpLm.cs | High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'dWdnfZHMYu', 'Y4mn0l4tKP', 'FJlnFj7Dxn', 'jwPntvYLoC', 'DcNndoSHBq', 'kXrnnNny7M', 'qHQnPf59NG' |
Source: 0.2.LisectAVT_2403002A_124.exe.3c25f30.3.raw.unpack, TKpoFdOdwZBGcjEya7.cs | High entropy of concatenated method names: 'Dispose', 'atLVELYDVW', 'ayWCM2W53b', 's2nkkVcXR5', 'EofVsypCIY', 'AZlVzmt0Jr', 'ProcessDialogKey', 'EatCQbkn9f', 'UmSCVVUYuC', 'UvSCC26Awx' |
Source: 0.2.LisectAVT_2403002A_124.exe.3c25f30.3.raw.unpack, h8oSwShDsT51Fkc3yZ.cs | High entropy of concatenated method names: 'HSaiISTUjr', 'BKGiAGlGxD', 'VWqi3y98Cf', 'Fd4i5iTLI1', 'YXIiggRcQf', 'uhLiKFCL1r', 'SRHibyoaIj', 'lwpipg8lGw', 'ziYiU2oJZA', 'Fvpie7w4WZ' |
Source: 0.2.LisectAVT_2403002A_124.exe.3c25f30.3.raw.unpack, HSCItCjxsCrf5YKUOC.cs | High entropy of concatenated method names: 'rhWtcfRHdr', 'TGytR702cU', 'ToString', 'WH0t1u4ebR', 'ISxtOkH5Aw', 'q6ltwW2hc3', 'AZBtouaDnV', 'xaptYgkqpP', 'o0Rti0eyRB', 'EPTt9XwWOq' |
Source: 0.2.LisectAVT_2403002A_124.exe.3c25f30.3.raw.unpack, VVbjCDHVDfIQWckVYA.cs | High entropy of concatenated method names: 'TQV0vXSQnI', 'Cm10SOm0JP', 'XJ50H7Pvb8', 'mG707jxOrt', 'JVy0Mg597M', 'd3X0xFoRKE', 'hLZ0mxEQq2', 'R1E0JZXhDk', 'h2p0Z3GSru', 'qcy0T9H2Yc' |
Source: 0.2.LisectAVT_2403002A_124.exe.3c25f30.3.raw.unpack, XUOos6pd8lC90dYS16.cs | High entropy of concatenated method names: 'FrjOHoh6oI', 'LpkO70PuUI', 'rEsOlOTfKJ', 'cJiOj3ujJd', 'rZ2OkKYydR', 'QegOWk5kdB', 'bxoOBqqcvv', 'cTlOufJaqH', 'sE6OE5qpon', 'HbCOsmAMY7' |
Source: 0.2.LisectAVT_2403002A_124.exe.3c25f30.3.raw.unpack, hfypCIuY5Zlmt0JrUa.cs | High entropy of concatenated method names: 'k67d1Fm3Id', 'B5ndOCrnSo', 'KpndwmxoOe', 'dhPdo3uY82', 'dRVdYVHO9a', 'iOvdifxfDX', 'VpJd93sMuw', 'ua4d8hxpuC', 'iY0dcOslpR', 'IUhdRo9Ws4' |
Source: 0.2.LisectAVT_2403002A_124.exe.3c25f30.3.raw.unpack, icaxvCZ6aqZ3PiHMdJ.cs | High entropy of concatenated method names: 'H6OYlXsbK8', 'IsfYjvRcsM', 'MauYkqxqAg', 'ToString', 'oIMYWCMWjR', 'zOgYBXx1xq', 'Mk5OU7N3A0LruHsmAVI', 'G3Jy3MN0KlSPVL2MDiG', 'BiJGZSNXiGFkErotq7A' |
Source: 0.2.LisectAVT_2403002A_124.exe.3c25f30.3.raw.unpack, u6AwxmslUiHFvQuVn9.cs | High entropy of concatenated method names: 'McGnVrXXJT', 'KMKn6MnUaT', 'ms3ny8Giga', 'E0cn1hCbRC', 'amPnOcNo3f', 'KdAnoIAOWU', 'Sx8nYGe1Pe', 'XasdBGJOXS', 'dJtduLDXEy', 'zxXdEvFIm8' |
Source: 0.2.LisectAVT_2403002A_124.exe.3c25f30.3.raw.unpack, JRGbcDWbZCZ666nwc5.cs | High entropy of concatenated method names: 'MdItuyMSay', 'T1atsy64Zh', 'O2HdQiT6tI', 'mR6dVbDkxT', 'mSdt4mysjB', 'EFHtSZJ70x', 'UKQtqnn787', 'xvCtHJxETa', 'dnnt7Agea9', 'SmmtlmSuoi' |
Source: 0.2.LisectAVT_2403002A_124.exe.3c25f30.3.raw.unpack, KE2aSiTVAwAGmbGpIg.cs | High entropy of concatenated method names: 'rNai1r1vmg', 'cUOiwVfxye', 'ytbiYJR4uB', 'P4EYswsWIy', 'q9ZYzk6uPr', 'Og3iQlyA8s', 'qRFiVXjsRO', 'jYWiCqw3U2', 'Pchi6olICk', 'ne8iylpMdb' |
Source: 0.2.LisectAVT_2403002A_124.exe.3c25f30.3.raw.unpack, Vu60JKqx5NHLYX2BnX.cs | High entropy of concatenated method names: 'eZufpmlTjY', 'PblfU4x0uC', 'Drlfal8UGK', 'wnZfMy8mBe', 'rjXfm9aGps', 'YaLfJoEpbm', 'bblfTAvpSr', 'mVffGBQ8MS', 'j5kfvDhtgS', 'k1kf4POctu' |
Source: 0.2.LisectAVT_2403002A_124.exe.5010000.6.raw.unpack, kdFvaMFVPKs73pA7Ae.cs | High entropy of concatenated method names: 'jlLbsIppcp4pe', 'HUDVafGQx3A5lYPXEbC', 'bWxlDPGFKtjOUjq8ME9', 'J13JY7Gs9VegMR0Usdn', 'gjnvHYGCPTFBSN5sXDA', 'UXn9pRGVr5JYGFjuCRJ', 'g8bQ3yGYPoLwrRusK3E', 'KwwAwLG5jtFVjgr5V0l', 'lJyLiGG0wAjthymuVo5', 'KrHGd2G9wj507LdZGDe' |
Source: 0.2.LisectAVT_2403002A_124.exe.5010000.6.raw.unpack, DD.cs | High entropy of concatenated method names: 'wgRxinKHcbWANUbFNm', 'dwveif1E9jqp4XTbTA', 'iYTXHL2SDoNZBJVsGw', 'hFySdn3keDBvJSvKal', 'PVIytPpWpuEYQLk40u' |
Source: 0.2.LisectAVT_2403002A_124.exe.5010000.6.raw.unpack, ihWImL1h2qjtIkVYDh.cs | High entropy of concatenated method names: 'qJUttacKFT', 'djwp7oGHZ8xfNf3m5ut', 'AZqALCG67UykKuowXP2', 'dkLCJpGlCfFdqtD7Epf', 'iHWSkAGjDuGN31hXJsT', 'u4UYnDGE5xCOMnt15QR', 'jhES7Va4c', 'jWmROKkjL', 'Dispose', 'BJj7gBhfp' |
Source: 0.2.LisectAVT_2403002A_124.exe.5010000.6.raw.unpack, oImfMJtvGUo8fMQNBQ.cs | High entropy of concatenated method names: 'cxsORewNJ', 'VvrninWuk', 'ustvIxt9o', 'QtXoY7g0N', 'cMKlMbnQu', 'w2KLAB5Xx', 'hNkF6TG2YCh7xU8s3hJ', 'hs4l1PGKtLhAeRnm1c4', 'Dispose', 'MoveNext' |
Source: 0.2.LisectAVT_2403002A_124.exe.5010000.6.raw.unpack, wehuuoKhMKMbnQu72K.cs | High entropy of concatenated method names: 'NXMyxc8eI', 'GTZadPHeP', 'DEVNaDCj9', 'cflmBNqev', 'VFQ0OImLC', 'PbYVMxZvt', 'UPdFjbLed', 'AeEi93ui9', 'oM66buTLn', 'nxFUIfcfn' |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe TID: 7316 | Thread sleep time: -922337203685477s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe TID: 7576 | Thread sleep count: 34 > 30 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe TID: 7576 | Thread sleep time: -31359464925306218s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe TID: 7576 | Thread sleep time: -100000s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe TID: 7580 | Thread sleep count: 1928 > 30 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe TID: 7576 | Thread sleep time: -99875s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe TID: 7576 | Thread sleep time: -99766s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe TID: 7576 | Thread sleep count: 44 > 30 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe TID: 7576 | Thread sleep time: -99641s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe TID: 7580 | Thread sleep count: 7875 > 30 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe TID: 7576 | Thread sleep time: -99531s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe TID: 7576 | Thread sleep time: -99420s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe TID: 7576 | Thread sleep time: -99312s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe TID: 7576 | Thread sleep time: -99204s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe TID: 7576 | Thread sleep time: -99079s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe TID: 7576 | Thread sleep time: -98954s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe TID: 7576 | Thread sleep time: -98829s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe TID: 7576 | Thread sleep time: -98704s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe TID: 7576 | Thread sleep time: -98579s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe TID: 7576 | Thread sleep time: -98454s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe TID: 7576 | Thread sleep time: -98329s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe TID: 7576 | Thread sleep time: -98204s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe TID: 7576 | Thread sleep time: -98079s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe TID: 7576 | Thread sleep time: -97954s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe TID: 7576 | Thread sleep time: -97829s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe TID: 7576 | Thread sleep time: -97704s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe TID: 7576 | Thread sleep time: -97579s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe TID: 7576 | Thread sleep time: -97454s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe TID: 7576 | Thread sleep time: -97329s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe TID: 7576 | Thread sleep time: -97204s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe TID: 7576 | Thread sleep time: -97079s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe TID: 7576 | Thread sleep time: -96954s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe TID: 7576 | Thread sleep time: -96829s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe TID: 7576 | Thread sleep time: -96704s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe TID: 7576 | Thread sleep time: -96579s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe TID: 7576 | Thread sleep time: -96454s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe TID: 7576 | Thread sleep time: -96329s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe TID: 7576 | Thread sleep time: -96204s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe TID: 7576 | Thread sleep time: -96079s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe TID: 7576 | Thread sleep time: -95954s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe TID: 7576 | Thread sleep time: -95829s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe TID: 7576 | Thread sleep time: -95704s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe TID: 7576 | Thread sleep time: -95579s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe TID: 7576 | Thread sleep time: -95454s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe TID: 7576 | Thread sleep time: -95329s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe TID: 7576 | Thread sleep time: -95204s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe TID: 7576 | Thread sleep time: -95079s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe TID: 7576 | Thread sleep time: -94954s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe TID: 7576 | Thread sleep time: -94829s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe TID: 7576 | Thread sleep time: -94704s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe TID: 7576 | Thread sleep time: -94579s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe TID: 7576 | Thread sleep time: -94454s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe TID: 7576 | Thread sleep time: -94329s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe TID: 7576 | Thread sleep time: -94204s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe TID: 7576 | Thread sleep time: -94079s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe TID: 7576 | Thread sleep time: -93954s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe TID: 7576 | Thread sleep time: -93829s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Thread delayed: delay time: 100000 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Thread delayed: delay time: 99875 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Thread delayed: delay time: 99766 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Thread delayed: delay time: 99641 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Thread delayed: delay time: 99531 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Thread delayed: delay time: 99420 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Thread delayed: delay time: 99312 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Thread delayed: delay time: 99204 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Thread delayed: delay time: 99079 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Thread delayed: delay time: 98954 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Thread delayed: delay time: 98829 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Thread delayed: delay time: 98704 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Thread delayed: delay time: 98579 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Thread delayed: delay time: 98454 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Thread delayed: delay time: 98329 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Thread delayed: delay time: 98204 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Thread delayed: delay time: 98079 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Thread delayed: delay time: 97954 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Thread delayed: delay time: 97829 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Thread delayed: delay time: 97704 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Thread delayed: delay time: 97579 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Thread delayed: delay time: 97454 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Thread delayed: delay time: 97329 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Thread delayed: delay time: 97204 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Thread delayed: delay time: 97079 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Thread delayed: delay time: 96954 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Thread delayed: delay time: 96829 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Thread delayed: delay time: 96704 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Thread delayed: delay time: 96579 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Thread delayed: delay time: 96454 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Thread delayed: delay time: 96329 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Thread delayed: delay time: 96204 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Thread delayed: delay time: 96079 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Thread delayed: delay time: 95954 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Thread delayed: delay time: 95829 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Thread delayed: delay time: 95704 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Thread delayed: delay time: 95579 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Thread delayed: delay time: 95454 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Thread delayed: delay time: 95329 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Thread delayed: delay time: 95204 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Thread delayed: delay time: 95079 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Thread delayed: delay time: 94954 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Thread delayed: delay time: 94829 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Thread delayed: delay time: 94704 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Thread delayed: delay time: 94579 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Thread delayed: delay time: 94454 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Thread delayed: delay time: 94329 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Thread delayed: delay time: 94204 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Thread delayed: delay time: 94079 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Thread delayed: delay time: 93954 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Thread delayed: delay time: 93829 | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\calibriz.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\cambria.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\cambriai.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\cambriab.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\cambriaz.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\cambria.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\Candara.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\Candaral.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\Candarai.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\Candarali.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\Candarab.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\Candaraz.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\comic.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\comici.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\comicbd.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\comicz.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\constan.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\constani.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\constanb.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\constanz.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\corbel.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\corbell.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\corbeli.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\corbelli.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\corbelb.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\corbelz.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\cour.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\couri.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\courbd.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\courbi.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\ebrima.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\ebrimabd.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\FRADM.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\FRADMIT.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\FRADMCN.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\FRAHV.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\FRAHVIT.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\gadugi.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\gadugib.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\georgia.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\georgiai.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\georgiab.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\georgiaz.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\impact.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\Inkfree.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\javatext.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\LeelawUI.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\LeelUIsl.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\LeelaUIb.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\lucon.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\l_10646.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\malgun.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\malgunsl.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\malgunbd.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\himalaya.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\msjh.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\msjhl.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\msjhbd.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\msjh.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\msjhl.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\ntailu.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\ntailub.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\phagspa.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\phagspab.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\micross.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\taile.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\taileb.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\msyh.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\msyhl.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\msyhbd.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\msyh.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\mingliub.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\mingliub.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\mingliub.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\monbaiti.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\msgothic.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\msgothic.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\msgothic.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\mvboli.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\mmrtext.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\mmrtextb.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\Nirmala.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\NirmalaB.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\pala.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\palai.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\palab.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\palabi.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\segoepr.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\segoeprb.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\segoesc.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\seguihis.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\simsun.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\simsunb.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\Sitka.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\SitkaI.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\SitkaB.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\SitkaZ.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\SitkaI.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\SitkaB.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\SitkaZ.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\Sitka.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\SitkaI.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\SitkaB.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\SitkaZ.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\Sitka.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\SitkaB.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\Sitka.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\SitkaI.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\SitkaB.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\SitkaZ.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\sylfaen.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\symbol.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\tahoma.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\tahomabd.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\timesi.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\timesbd.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\timesbi.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\trebuc.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\trebucit.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\trebucbd.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\trebucbi.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\verdana.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\verdanai.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\verdanab.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\verdanaz.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\webdings.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\wingding.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\YuGothR.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\YuGothM.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\YuGothL.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\YuGothB.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\YuGothM.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\holomdl2.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\AGENCYR.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\AGENCYB.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\ALGER.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\BKANT.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\ANTQUAI.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\ARLRDBD.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\BASKVILL.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\BELLB.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\BERNHC.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\BOD_R.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\BOD_BI.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\BOD_BLAR.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\BRLNSB.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\BRUSHSCI.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\BSSYM7.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\CALIFB.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\CALIST.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\CALISTI.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\CALISTBI.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\SCHLBKB.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\SCHLBKBI.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\COOPBL.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\COPRGTB.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\ERASBD.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\FRABK.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\FRSCRIPT.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\GARAIT.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\GIGI.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\GIL_____.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\GILB____.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\GOTHICBI.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\GOUDOS.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\GOUDOSB.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\HATTEN.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\HTOWERTI.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\JOKERMAN.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\KUNSTLER.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\LBRITEI.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\LBRITEDI.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\LEELAWAD.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\LFAX.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\LFAXDI.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\LTYPE.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\LTYPEO.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\MSUIGHUB.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\NIAGENG.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\NIAGSOL.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\PERTILI.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\RAVIE.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\REFSPCL.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Fonts\micross.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Security\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Security.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\LisectAVT_2403002A_124.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation | Jump to behavior |