Source: DMINktnUtY.exe, 00000003.00000002.1708371377.0000000007222000.00000004.00000800.00020000.00000000.sdmp, J48w21dBmF.exe, 00000004.00000002.1709171602.0000000006F32000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.apache.org/licenses/LICENSE-2.0 |
Source: DMINktnUtY.exe, 00000003.00000002.1708371377.0000000007222000.00000004.00000800.00020000.00000000.sdmp, J48w21dBmF.exe, 00000004.00000002.1709171602.0000000006F32000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.carterandcone.coml |
Source: DMINktnUtY.exe, 00000003.00000002.1708371377.0000000007222000.00000004.00000800.00020000.00000000.sdmp, J48w21dBmF.exe, 00000004.00000002.1709171602.0000000006F32000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.fontbureau.com |
Source: J48w21dBmF.exe, 00000004.00000002.1709171602.0000000006F32000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.fontbureau.com/designers |
Source: J48w21dBmF.exe, 00000004.00000002.1709171602.0000000006F32000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.fontbureau.com/designers/? |
Source: DMINktnUtY.exe, 00000003.00000002.1708371377.0000000007222000.00000004.00000800.00020000.00000000.sdmp, J48w21dBmF.exe, 00000004.00000002.1709171602.0000000006F32000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.fontbureau.com/designers/cabarga.htmlN |
Source: DMINktnUtY.exe, 00000003.00000002.1708371377.0000000007222000.00000004.00000800.00020000.00000000.sdmp, J48w21dBmF.exe, 00000004.00000002.1709171602.0000000006F32000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.fontbureau.com/designers/frere-user.html |
Source: DMINktnUtY.exe, 00000003.00000002.1708371377.0000000007222000.00000004.00000800.00020000.00000000.sdmp, J48w21dBmF.exe, 00000004.00000002.1709171602.0000000006F32000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.fontbureau.com/designers8 |
Source: DMINktnUtY.exe, 00000003.00000002.1708371377.0000000007222000.00000004.00000800.00020000.00000000.sdmp, J48w21dBmF.exe, 00000004.00000002.1709171602.0000000006F32000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.fontbureau.com/designers? |
Source: DMINktnUtY.exe, 00000003.00000002.1708371377.0000000007222000.00000004.00000800.00020000.00000000.sdmp, J48w21dBmF.exe, 00000004.00000002.1709171602.0000000006F32000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.fontbureau.com/designersG |
Source: DMINktnUtY.exe, 00000003.00000002.1708371377.0000000007222000.00000004.00000800.00020000.00000000.sdmp, J48w21dBmF.exe, 00000004.00000002.1709171602.0000000006F32000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.fonts.com |
Source: DMINktnUtY.exe, 00000003.00000002.1708371377.0000000007222000.00000004.00000800.00020000.00000000.sdmp, J48w21dBmF.exe, 00000004.00000002.1709171602.0000000006F32000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.founder.com.cn/cn |
Source: DMINktnUtY.exe, 00000003.00000002.1708371377.0000000007222000.00000004.00000800.00020000.00000000.sdmp, J48w21dBmF.exe, 00000004.00000002.1709171602.0000000006F32000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.founder.com.cn/cn/bThe |
Source: DMINktnUtY.exe, 00000003.00000002.1708371377.0000000007222000.00000004.00000800.00020000.00000000.sdmp, J48w21dBmF.exe, 00000004.00000002.1709171602.0000000006F32000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.founder.com.cn/cn/cThe |
Source: DMINktnUtY.exe, 00000003.00000002.1708371377.0000000007222000.00000004.00000800.00020000.00000000.sdmp, J48w21dBmF.exe, 00000004.00000002.1709171602.0000000006F32000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.galapagosdesign.com/DPlease |
Source: DMINktnUtY.exe, 00000003.00000002.1708371377.0000000007222000.00000004.00000800.00020000.00000000.sdmp, J48w21dBmF.exe, 00000004.00000002.1709171602.0000000006F32000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.galapagosdesign.com/staff/dennis.htm |
Source: DMINktnUtY.exe, 00000003.00000002.1708371377.0000000007222000.00000004.00000800.00020000.00000000.sdmp, J48w21dBmF.exe, 00000004.00000002.1709171602.0000000006F32000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.goodfont.co.kr |
Source: DMINktnUtY.exe, 00000003.00000002.1708371377.0000000007222000.00000004.00000800.00020000.00000000.sdmp, J48w21dBmF.exe, 00000004.00000002.1709171602.0000000006F32000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.jiyu-kobo.co.jp/ |
Source: DMINktnUtY.exe, 00000003.00000002.1708371377.0000000007222000.00000004.00000800.00020000.00000000.sdmp, J48w21dBmF.exe, 00000004.00000002.1709171602.0000000006F32000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.sajatypeworks.com |
Source: J48w21dBmF.exe, 00000004.00000002.1709171602.0000000006F32000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.sakkal.com |
Source: DMINktnUtY.exe, 00000003.00000002.1708371377.0000000007222000.00000004.00000800.00020000.00000000.sdmp, J48w21dBmF.exe, 00000004.00000002.1709171602.0000000006F32000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.sandoll.co.kr |
Source: J48w21dBmF.exe, 00000004.00000002.1709171602.0000000006F32000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.tiro.com |
Source: DMINktnUtY.exe, 00000003.00000002.1708371377.0000000007222000.00000004.00000800.00020000.00000000.sdmp, J48w21dBmF.exe, 00000004.00000002.1709171602.0000000006F32000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.typography.netD |
Source: DMINktnUtY.exe, 00000003.00000002.1708371377.0000000007222000.00000004.00000800.00020000.00000000.sdmp, J48w21dBmF.exe, 00000004.00000002.1709171602.0000000006F32000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.urwpp.deDPlease |
Source: DMINktnUtY.exe, 00000003.00000002.1708371377.0000000007222000.00000004.00000800.00020000.00000000.sdmp, J48w21dBmF.exe, 00000004.00000002.1709171602.0000000006F32000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.zhongyicts.com.cn |
Source: DMINktnUtY.exe, 00000003.00000002.1702039637.0000000003271000.00000004.00000800.00020000.00000000.sdmp, J48w21dBmF.exe, 00000004.00000002.1701185664.0000000002C1E000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://api.ip.s |
Source: J48w21dBmF.exe, 00000004.00000002.1701185664.0000000002C1E000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://api.ip.sb/ip |
Source: J48w21dBmF.exe, 00000004.00000002.1701185664.0000000002CB0000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://discord.com/api/v9/users/ |
Source: C:\Users\user\Desktop\file.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\file.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Section loaded: aclayers.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Section loaded: sfc.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Section loaded: sfc_os.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Section loaded: edputil.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Section loaded: windows.staterepositoryps.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Section loaded: appresolver.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Section loaded: bcp47langs.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Section loaded: slc.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Section loaded: sppc.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Section loaded: onecorecommonproxystub.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Section loaded: onecoreuapcommonproxystub.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Section loaded: dwrite.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Section loaded: textshaping.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Section loaded: dwrite.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Section loaded: textshaping.dll | Jump to behavior |
Source: 2.2.RegAsm.exe.4b3c60.2.raw.unpack, Strings.cs | High entropy of concatenated method names: 'Init', 'Decrypt', 'Get', 'SW7XlrLiUtWtnAPuFtV', 'gyNMMlLMaRRJZVA8Zga', 'syvAAsLSYSns17kCQ5l', 'uoNmVrLh7m9eQTQYps9', 'NweWaRL2PB9sh4II1Mv', 'tWLdQsLOBsFU6dULcLx', 'BmavqDL0KlWIly2fF0m' |
Source: 2.2.RegAsm.exe.4b3c60.2.raw.unpack, Uv6YUiUwiQlDKPLBKM.cs | High entropy of concatenated method names: 'oLBfmLT9Ns', 'GomfrRgoqL', 'IDTf9oF32T', 'htnfzOZWFw', 'gcrDcvOcXR', 'FVQDjt0k05', 'DseDu7FOUI', 'mKXNW2MpLBiURKss36f', 'yrJ9qyMZn4AGtbXbRmy', 'YG5D7PsP0l' |
Source: 2.2.RegAsm.exe.4b3c60.2.raw.unpack, kU5tliBImvaQ8ijXHBH.cs | High entropy of concatenated method names: 'ENaBSnTU1B', 'qATBhpGvvj', 'So3BOCaM1G', 'lusBkeD34a', 'nKhBaiF9lU', 'XMYB8Kr8g0', 'm21B5VgJPV', 'rJyBg516vu', 'wMMBbJ4gGv', 'o3DBLjrrPH' |
Source: 2.2.RegAsm.exe.4b3c60.2.raw.unpack, fFbZwlX6ufedP3VVdMU.cs | High entropy of concatenated method names: 'T8AXE6QJcl', 'PqTXVvxFFR', 'FT8X3mstF7', 'dINXUPmirf', 'd79Xv913rb', 'aOdu0hsMnOTcuTXEmyZ', 'ax8DabsSZaBB4wDSxjR', 'd87FcWsiiHfIY3bAgvj', 'wdia52sLpfwFS8sbo9O', 'CFr89Zs1cE4IO3gDp0m' |
Source: 2.2.RegAsm.exe.4b3c60.2.raw.unpack, OawTOsXok9dLIGUygKV.cs | High entropy of concatenated method names: 'wguXwrkVYN', 'M18XYmqCaV', 'IeXXITOoen', 'iFHXsbDTkd', 'Ly9Xb2eD0U', 'Mo9XLmnBFS', 'XD9X1XKkSC', 'DkJXMI13AW', 'Dh1XSEVscu', 'TyeXiNy2ho' |
Source: 2.2.RegAsm.exe.4b3c60.2.raw.unpack, gWZbR7uUo3Ecmavde4A.cs | High entropy of concatenated method names: 'PxZutvKsUo', 'atGuFpZi5w', 'hVvuqZaPyc', 'FvJunRVQED', 'RkDuo2sZUm', 'qyguW9EbFq', 'h1Jufy2HhS', 'Ud1uD0xNYq', 'h8auTW89UE', 'LieudcDK10' |
Source: 2.2.RegAsm.exe.4b3c60.2.raw.unpack, LAmgpAMJb2FSRsQu6M.cs | High entropy of concatenated method names: 'Field1', 'vbdDjbY8DHesv4vMlbr', 'ySTYUcYGBhEEbwjBjoA', 'DGDHkqY5GmAedjA9rtO', 'qS4qC3Yg4YVNc2ih286', 'zDRZsSYK7tomF32MpxA', 'GmheqfYQhhLKAbILsd3', 'AIRZ0kYasBsVaTidhA9' |
Source: 2.2.RegAsm.exe.4b3c60.2.raw.unpack, GTUJybuyb8qluZH6i7u.cs | High entropy of concatenated method names: 'D8burCwhun', 'k3Pu9vMvoh', 'Dispose', 'va5uzN0G6r', 'idgGZbs45KVbGmhOslP', 'CT37LyslFBUQsgaHYao', 's5hCBwstxBAmqJ5rwnN', 'GB3WsLsPlYBfJifTq2c', 'oYAL6msFGFhXb89fJu3' |
Source: 2.2.RegAsm.exe.4b3c60.2.raw.unpack, VGSE25XrYZJ1Kcb1FkT.cs | High entropy of concatenated method names: 'sxsXzROfXo', 'mDu7csjce6', 'Trx7jS1097', 'p8W7ucG7hK', 'IW57XK0iJI', 'XqD77RQKWn', 'PLt7BriMAb', 'wrq7HaZwYY', 'rjM7eYvTMK', 'lKI76bjIxt' |
Source: 2.2.RegAsm.exe.4b3c60.2.raw.unpack, kZrCypXugJuhBYjNYsQ.cs | High entropy of concatenated method names: 'cnfXBaVqTM', 'Ex3X7koON5', 'Xdr0ZRsxo8SnAZKT8ex', 'FCYeLBsoVmZUo0s9SfY', 'Nd39M5sW5HCVAq1ksFP', 'Kdarb7swNPtnuAwPT5p', 'CGVlu3sYgVotCauIRjk', 'yOCNDosI2YClmmPS4gH', 'hjjpuBss62PZd2bJx9B', 'WUkekWsqL0q1wZxJ7mX' |
Source: 2.2.RegAsm.exe.4b3c60.2.raw.unpack, IHXC94YXWFClKfVysr.cs | High entropy of concatenated method names: 'TgQsedPD0', 'Mosbcbnbh', 'C6jL72jyy', 'I\u04344', 'XDNyPHYMM3F0XLUMcaU', 'WsGq7IYSXsg8QKfp3dp', 'PvPPojYiJ8nfwmrifFt', 'rXar4lYhpYFDSirtGBP', 'sc7lcTY2ywa2TQ6NuPd', 'GhZJLAYOGXMqjUumvlM' |
Source: 2.2.RegAsm.exe.4b3c60.2.raw.unpack, mWn2uTXfABRTA9gvJpL.cs | High entropy of concatenated method names: 'vIPXTPbiHE', 'Y2oXdbqFYx', 'MgRXRHWLG9', 'uBUXJKE8vn', 'LOTX4C1EqN', 'kWRXlr11Fh', 'rnfXtVIjAE', 'YcFXP5Vhrc', 'VlHXFvNsEc', 'eiTXAJKJmf' |
Source: 2.2.RegAsm.exe.4b3c60.2.raw.unpack, SyxKifekd28kxBNqQqx.cs | High entropy of concatenated method names: 'YN8dsVrSIj', 'RU6cEqiX5QgF0tko90y', 'UDHrY4i738uKB2LNpv7', 'INJxuYiB951gZhacsRN', 'Yu4dL6TqLq', 'fBDd1an2gj', 'a34dMsYUke', 'MSXdS0iJav', 'WX9VMvieHIjYRgo3JC5', 'LOWQ83i6oc0PgAgZiXa' |
Source: 2.2.RegAsm.exe.4b3c60.2.raw.unpack, hmpfoCjvg4hqsFP0LjP.cs | High entropy of concatenated method names: 'zqZToFyuAq', 'yZnTWTUmx2', 'w6Ke6MSt5X64q3us6AB', 'SNWnVqSPbaWEOi19otP', 'TudkPFSF0j9tpnlLnIm', 'wOqEBPSq1RrJhiw9NZZ', 'DHqnrJSnEPSTn6QEnQe', 'G06TIkdJJT', 'J2AKG6SoUaiRRlOdTE4', 'Q0EBytSWLONhTf6Ngkb' |
Source: 2.2.RegAsm.exe.4b3c60.2.raw.unpack, UtoRl5uKb9Fp7h6R4GX.cs | High entropy of concatenated method names: 'qqsTaE1Kd4', 'JFT3e1Sa09e5ForaSx7', 'yWh9ddS8fvVek9GibGu', 'CDruZ2INIZ', 'xdbuNPYrWZ', 'u55JW2sDJreFKL0aOEW', 'LfFYNasTMxN2pbTNPyk', 'lEcpIHsdX0RViQjS4X3', 'ldAqc0sRN5Is49aM0Wr' |
Source: 2.2.RegAsm.exe.4b3c60.2.raw.unpack, DJTcgV7fSIieAeqHgA0.cs | High entropy of concatenated method names: 'jt543GErCe', 'W3r4USIhU8', 'KYn4EQQiGT', 'na74v95gdW', 'E3k4f3mExU', 'Ix34DsZaLf', 'Ob94T23cie', 'tMD4dl9KQh', 'hyt7T6hnHo', 'U4V4R7McRE' |
Source: 2.2.RegAsm.exe.4b3c60.2.raw.unpack, SkL3LGHeejS7o6KAb0B.cs | High entropy of concatenated method names: 'BVkHC3dpCK', 'LwOHV8KlEn', 'sB2H3eb6A1', 'TDrHUfDXNx', 'dyqHvKO0fC', 'RGZHf44N66', 'Fk8HDKQoT1', 'X6IHTQmFp3', 'OLmHdkZrHR', 'UltHRusjRv' |
Source: 2.2.RegAsm.exe.4b3c60.2.raw.unpack, q9oNCQ3LukRHjfJdSTn.cs | High entropy of concatenated method names: 'c7j3MPyune', 'gLJ3SMxcXC', 'KGX3hm1pLD', 'oKv32ycjs1', 'cQj30nect3', 'Eox3Q0Qemp', 'C9p3aPl5s1', 'ToString', 'gFCTclMlI2t0jthLBHA', 'DHIqVrMtW3DA82BJgk4' |
Source: 2.2.RegAsm.exe.4b3c60.2.raw.unpack, uwnKjGF06wYI5Nb9kX.cs | High entropy of concatenated method names: 'Field1', 'hjyqMrTso', 'Field2', 'Field3', 'QTcnZLsMC', 'VrxxFFebR', 'IG9o5pFLF', 'rRuWXPYAN4NRB3yykmS', 'C1CBtYYqVKVt3DlngCD', 'Mh7QX2YPcLclddWJlZ7' |
Source: 2.2.RegAsm.exe.4b3c60.2.raw.unpack, LrFTpY7iUXI47XuL87C.cs | High entropy of concatenated method names: 'jt543GErCe', 'dD944UjqUM', 'Vwy724cqDJ', 'iTs7OR04P9', 'AWX70R6edo', 'Jk07kRZIgf', 'qmh7Q8DXhP', 'KYn4EQQiGT', 'W3r4USIhU8', 'kDO4lnWoY1' |
Source: 2.2.RegAsm.exe.4b3c60.2.raw.unpack, ior9Akd5ddZSi4JUE3I.cs | High entropy of concatenated method names: 'hEOCU7hWD8mjKfipxt7', 'MxBfikhwhN3ZGOjYMed', 'srQJ4tvwkf', 'cUaCX9hbaGAcxyqube5', 'NDE0gahLlVvO4PiMDwb', 'dhgUeUh1uSEJhGs0GMW', 'Q3RJfVhMSkAgEi3kLH0', 'snyhUahSAZWer9Hi99X', 'g38PJ8K3c0', 'korJn9sVu4' |
Source: 2.2.RegAsm.exe.4b3c60.2.raw.unpack, dWsk2suC6DIcKHHbQrw.cs | High entropy of concatenated method names: 'ExpandEnvironmentVariable', 'j5quVNpYfo', 'b4Uu3r0uip', 'HP2eMvIypBAMvbdafSK', 'BUUvTZIm87YYpjgFyVd', 'G7FcPXIrP2If1e4e5rO', 'wypZ9WI951lHn1XIn2h', 'AMgnc5IzGmxR5mPTpEQ', 'gJn5J7scObuOBLKLmWq' |
Source: 2.2.RegAsm.exe.4b3c60.2.raw.unpack, AGCC1qjaZnIu24AH3bt.cs | High entropy of concatenated method names: 'J28uc9oq4Q', 'cL8jGTwbHJ', 'uaIj5It8WI', 'DAfjgD2kUN', 'XP0jKjQj02', 'QubjpLKfRY', 'pm1jZrrVHS', 'mgUjNfux08', 'zxajy2Mhao', 'NxIjmwTHvn' |
Source: 2.2.RegAsm.exe.4b3c60.2.raw.unpack, cnM5KpB9Si7YRITptjy.cs | High entropy of concatenated method names: 'nb6Hc2ZIfx', 'CiEHjWUS0G', 'dIOHudqMg3', 'z1jHXYvPwI', 'SJSH7klKfW', 'Ce28quLcvR3ePOS1vwW', 'Fhn3wWLjimtpHhSkrih', 'LPQC5DLuIKtTL6HAMsD', 'RANFXYLXEqyiwsHhWbQ' |
Source: 2.2.RegAsm.exe.4b3c60.2.raw.unpack, zgHUwGHNI1chR8xhv4v.cs | High entropy of concatenated method names: 'vPFdoIb660', 'GC4dW2P2cY', 'JqPPI2S9I1aALueYFRs', 'mnTkbrSzGCki1QonSM2', 'fdeMYCicWgi14v1w47F', 'IGTPAlijB4EOU9emPMK', 'wwYHmJqSlU', 'fLXHrXKglT', 'dsBH9msXjp', 'yAgA8qLIkxsJjLaQabN' |
Source: 2.2.RegAsm.exe.4b3c60.2.raw.unpack, X5iBUftytZuo7rW1lJ.cs | High entropy of concatenated method names: 'Field1', 'Field2', 'Field3', 'zDEAfxYf60yVfYmhRvB', 'RHKd3bYDFFwx4jZ6e2R', 'nxf7i4YTgrRvbQZE50r', 'ImeXrHYdkppaCTrFegj', 'rRYWxdYREeaSJPOg2qD', 'El1TWVYJTw7cBuSVEXm', 'xy4h9CY4yGwlbXMloxx' |
Source: 2.2.RegAsm.exe.436060.0.raw.unpack, MI9HRSOvwZeUK3VMWUm.cs | High entropy of concatenated method names: 'XOV0JT40t6', 'S3vO3m9uVf', 'lITONJBd7h', 'qfoO5LUYma', 'kVMO1CEX7T', 'VUrOIm3Qe0', 'zb9OMY15M4', 'wgcOGZ5nwc', 'btBObjfDOs', 'lfWO7kI64e' |
Source: 2.2.RegAsm.exe.436060.0.raw.unpack, UAFCoqEm5t2t628Rj6.cs | High entropy of concatenated method names: 'Field1', 'Field2', 'Field3', 'YqBkX1iv89WPRoZ0KM7', 'tOAjcmijKbAwKRZOEF8', 'ObIRZbi35BpjIcfeVOT', 'dECfuMiNjUcGcnHFQ4C', 'XhxfQ9i5pfNRIwaCcq2', 'ej4sbxiVU8nLjyuEq6W', 'KCOGO5iEcB6WwTBV2QZ' |
Source: 2.2.RegAsm.exe.436060.0.raw.unpack, IRxSG6qt0JkYwKh1cA1.cs | High entropy of concatenated method names: 'm6CqvvqbXE', 'NFPqV2WPSM', 'CjXqEkbwJ7', 'EX13R0CKHPRgghmyZ57', 'oIn5JWCzrb8BfPFNrij', 'K1dM6PwJmFq8lTrvnL5', 'vCmpHDwOQ5JVPsAWIGn', 'KBtg2lw0IK1U9N6lhsV', 'XHwKVmwsFQFhiov5n26' |
Source: 2.2.RegAsm.exe.436060.0.raw.unpack, x4QOh80pVtb236KIyss.cs | High entropy of concatenated method names: 'KYd0Z3Dffe', 'zyn0x7m082', 'LgX0e4cslF', 'HQD0PEU9KR', 'sH20yHT1fA', 'zFU0u0apw2', 'fax0DR3qlS', 'xJA0ce8nCb', 'tlE0A2B9K3', 'W0B0h2cZkh' |
Source: 2.2.RegAsm.exe.436060.0.raw.unpack, svBIiPpoOPB51PVt4u.cs | High entropy of concatenated method names: 'ECdD7lsjFc', 'StpDYnKHya', 'pLCDKa2Phd', 'PFiDzqXTG5', 'iA2cJWX11O', 'YHhcOdliie', 'XDSc0mEwCW', 'UEhKNWWjIlKKkrnFk9k', 'BAj3vTW3jQrwsrkqlEH', 'Field1' |
Source: 2.2.RegAsm.exe.436060.0.raw.unpack, IySwrSs0IOLUMRVYwiw.cs | High entropy of concatenated method names: 'G2Os6cplpi', 'KsnsUZRZmp', 'poM7WTg29bEDyfMmkI0', 'sJcFN7gWK1BaNeoVguL', 'laesU4gkH0xqOFQywS8', 'UH4ImKg9mF64DdgkiQ7', 'ib32oigtLFxiVhrVG7H', 'PfN6nmg87dp2i75I9dx', 'aYMriWgV4xn3aF3sBac', 'LOfaBtgErGkSVc90pgQ' |
Source: 2.2.RegAsm.exe.436060.0.raw.unpack, RlBF8Yl8Mnqswvfy6T.cs | High entropy of concatenated method names: 'ObpFUuDsX', 'qSlgsu09H', 'DI7d5XObG', 'I\u04344', 'YG8nAuis3Gfeu0gcIEA', 'zty0ZGiU0TvxlVce1Lt', 'prXVsFi6dbVUo65JnX8', 'MMm5Kciq3LOQrX3tWdB', 'gvvQKmiH5SlJNxgI9CC', 'Un5Y4tiXCTTvxS6Oq1Y' |
Source: 2.2.RegAsm.exe.436060.0.raw.unpack, s6ECEhpmkusi0Qv5kY0.cs | High entropy of concatenated method names: 'z88pDarpDl', 'z0hpACi43S', 'AJvp40rrEV', 'nylpSKeLNo', 'fwnppgyNHT', 'rjXpBJNORc', 'k5AcsEWQZ6dEHyVcNB7', 'tfsBeLWeqEMcGXExYR7', 'huC179WofcMXsHx0maD', 'WZB071Wx6ICnsKgQXte' |
Source: 2.2.RegAsm.exe.436060.0.raw.unpack, RamrfvUW8b4LOT78xRN.cs | High entropy of concatenated method names: 'inlnSs5o2E', 'aFRnn0WNmS', 'nmcU9QMh4h', 'D0jUtK8e9Z', 'CAdU8YqWcM', 'bR3UVkb2ah', 'scSUEWLZXO', 'SPinmyoBYJ', 'ITPnpCntwG', 'UnynTWIRZh' |
Source: 2.2.RegAsm.exe.436060.0.raw.unpack, ywXCBSsXL20GxCBwtB4.cs | High entropy of concatenated method names: 'WGIA7pXqls', 'bM6AYyD5eA', 'BHWRf3kIwneTDcINIsb', 'lim8qDkMusJMyNYtL4L', 'puGxYVkGpSVPlZ938f7', 'BChsm5DupI', 'iTJsrO1qgZ', 'ggssSgv0DB', 'R8GspFYU51', 'v1vsBqB1WQ' |
Source: 2.2.RegAsm.exe.436060.0.raw.unpack, iycOc4OBrCIqcimjTAQ.cs | High entropy of concatenated method names: 'VNJAypw7OG', 'qJiAusskyB', 'uy18Ytkhisf2ExTJW1J', 'n3nvUFk4OosKZo4bCnA', 'o9Ux5fkndnCLoYNQFhn', 'CvI3xykTow12KjcAvLx', 'UlAAi6V5CM', 'R2hn1lkoAcrBZOQsvLb', 'CKV74pkxarYvZMXr0MZ', 'VmApTLkeC243cc92203' |
Source: 2.2.RegAsm.exe.436060.0.raw.unpack, u0NXHu0bkvMRgbfSJy8.cs | High entropy of concatenated method names: 'hgYAMdmK0g', 'M8fGurk3eZ1FFnYRI5U', 'NGqB8DkNlLEpOAMjIdq', 'iUsDmtk5WwBGjhj4PBr', 'vbo0Y17V2X', 'aMX0KbUph3', 'Dispose', 'rb80zO43DU', 'Q0pvd0gLxuGFYco0pN4', 'rR1KPygn8JrTspKJlEp' |
Source: 2.2.RegAsm.exe.436060.0.raw.unpack, rKvsa3syrS73YeA7jyA.cs | High entropy of concatenated method names: 'F1msaJHgRl', 'AYpslkP5a2', 'n6DsiA7tnZ', 'cXlsFQYH2M', 'c9JsgWaU7y', 'RxZsdTg57w', 'hJBsCoCt0O', 'aduswwBmWf', 'Qt7s2vb2FY', 'mZ7sWobLdG' |
Source: 2.2.RegAsm.exe.436060.0.raw.unpack, ASIA32GE8WnZlNuPFd.cs | High entropy of concatenated method names: 'AmxAPiyHXf', 'EAWYjBkBJd2GPPQeYy6', 'uS6jlEkDPSKUyhYrhW5', 'zlWhKXkcbEUjNDYpCeE', 'Field2', 'Field3', 'L5K7X4GXU', 'off206F04Lyl7CYs3xx', 'RDqLtOFJFt63rZo8nmD', 'fuE2WfFOx1XZOnj8trm' |
Source: 2.2.RegAsm.exe.436060.0.raw.unpack, rSDSpq6PNmQKVcpcMNZ.cs | High entropy of concatenated method names: 'nCe6yn3XSf', 'ryC6uTKVnP', 'Qq86adOyQv', 'Tmh6lG8APu', 'hiIJhiCfZHOG3Tqtuj7', 'cIyvZqCmi469eHl14Hr', 'nQkrrICr0hJuZDFQZjv', 'oXdU7rCS8hhC3yGPtqc', 'LaRnqQCHWJ2OGsK2Bfp', 'zfaPCWCX0gbZZA0KZjv' |
Source: 2.2.RegAsm.exe.436060.0.raw.unpack, gesyyeL87s3PHycCwjB.cs | High entropy of concatenated method names: 'gfSLbNeAbF', 'LCML7PG00q', 'FHcLY3S5QT', 'eVeLKxmD1W', 'bHeLz7hKNq', 'aKOnJNM6Nk', 'TLFnOoPsAI', 'rC8n0UOcIQ', 'lDcnslAAF4', 'HrSnUgr0kd' |
Source: 2.2.RegAsm.exe.436060.0.raw.unpack, Vjy70LqGwwWppi5TZNJ.cs | High entropy of concatenated method names: 'hoLhylep9E', 'LWIhuUiHS8', 'SDSKSxk7PIpNHQwjjGW', 'tPh0hSkYr9sqNTtnwuZ', 'CGamJgkKFB2uaMWkP3c', 'KchWIykz1IdHLFwkjmw', 'iZrK3c9Jffj7ahtDWPe', 'NpJ3GW9Ooy7UJMXZI8K', 'CRb2f190Z79p3eyfnFd', 'asrbLg9sxmhFIivRY6h' |
Source: 2.2.RegAsm.exe.436060.0.raw.unpack, oXutQK0fHr1rqG4SV0v.cs | High entropy of concatenated method names: 'ExpandEnvironmentVariable', 'WAp0r7xB9F', 'sDa0SlWmQ9', 'OMnZmCFIxKFkpSD6bLn', 'ONtDvZFM5hd1AbanMeU', 'euyBq6FGBestpSSCiVx', 'AHcHL4Fb7oGTcdEeZiW', 'KNO7dmF7lBjgiBgJ5M8', 'UyTcFcFYut9VLjoxExr' |
Source: 2.2.RegAsm.exe.436060.0.raw.unpack, UEdYIrZeVJVB5DkBei.cs | High entropy of concatenated method names: 'Field1', 'Field2', 'Field3', 'xeENITlioHIS6jx5fS6', 'cVhSIMlFHMlZXDghyP2', 'exlNxIlg4cxfDXLCnph', 'GcjOX1ldVoEWIXgZtWG', 'vmbugalCWfHO5EVpgXp', 'O7hmcTlwmpXbfF9W1w6', 's58uxvl2uk4hmIWiRRF' |
Source: 2.2.RegAsm.exe.436060.0.raw.unpack, XF74h1wZjOuXiQCriF.cs | High entropy of concatenated method names: 'Field1', 'KcYEWoioxRmXbg14ZTg', 'M0g4MJixxeWvfq06X6v', 'h7W86RiQYxEQfQyceC2', 'HJTrZKieIQDUiZVx0sV', 'fNvMGUiPToCS3pwmf9Z', 'qIEHRBiRUbneLEsKkoQ', 'hC4NVXiyqEGBQbfb4n4', 'cE1k67iTKwDtVQn6dD2', 'm7ji8qiZ4rMEx5EuwD9' |
Source: 2.2.RegAsm.exe.436060.0.raw.unpack, EvIl806iCqlrVic9EL7.cs | High entropy of concatenated method names: 'M0H62wkQxa', 'kVP6kf3p9p', 'Tg66tnnwQA', 'Mk26VYfoxj', 'owJ6vab0RD', 'gDC6jaPI0c', 'yg26NWt2nn', 'Eyo65wv3LO', 'KsB6gDmZNP', 'DES6dul3E7' |
Source: 2.2.RegAsm.exe.436060.0.raw.unpack, cBNyi2sYfgL3550bGU3.cs | High entropy of concatenated method names: 'RM5szeEQ1t', 'lXNUJr8S5h', 'XBEUOrC4na', 'BLiU0lb5ax', 'vbXUsIuYeN', 'Yd5UU0tqGG', 'YrKU6dHILU', 'sAaUqov7q3', 'ouQUHEZBRs', 'J72UXJwyCt' |
Source: 2.2.RegAsm.exe.436060.0.raw.unpack, nsSneXq3eaD03mDbw7B.cs | High entropy of concatenated method names: 'HX6q5uO1hq', 'ERMq1W3NeI', 'hSaqIwS2Bm', 'DVPqMuYeZA', 'glPijjwHTjK1ij1NAAI', 's6PIJpw6B88fTvQkEDr', 'DOa6D6wqfDmqpO5Gh08', 'hFRVq7wXKQG031SyYX5', 'wQgrckwfFLw3WZ1uwCh', 'wvVcUAwm7lVIB62iR2a' |
Source: 2.2.RegAsm.exe.436060.0.raw.unpack, qMNlr7xOiu102s6Kub.cs | High entropy of concatenated method names: 'Field1', 'CePe5a3BF', 'Field2', 'Field3', 'e02PBbjL3', 'fY8RRRypK', 'jZPyB5nGB', 'DBnZHdlE98h2Mipj0qJ', 'YsS9jZl8cK645wB2LsJ', 'cnYOa0lVlYqwk6Ay8nq' |
Source: 2.2.RegAsm.exe.436060.0.raw.unpack, sRdhkaHVfRZvwMXFLXj.cs | High entropy of concatenated method names: 'eBihFcTG1B', 'S9fgDp9HUEC8yBow2E0', 'ppaNEP9XZIHMcXVlv0v', 'HLgBQj9fh9qdedanDa7', 'FLbhdruviE', 'N5yhCBkiJ9', 'yQPhwW5K00', 'o8mh2rUcBe', 'vFB0vH9rYSiK024lKgO', 'gckLAi9S86bmEPmvc8k' |
Source: 2.2.RegAsm.exe.436060.0.raw.unpack, bYCbSc01eTuvRcAM3VG.cs | High entropy of concatenated method names: 'cvoAvslYP2', 'ADRE15ktrZqTrvCrUHd', 'lCsRAwk8HAe8EKkGIoZ', 'opo0MiOINU', 'zH60GTR4JY', 'r4Q0wqgcU0CebOvxxsX', 'UI9bsOgAPv6yL5FZO9F', 'C9OXVZghAg33SaXBFig' |
Source: 2.2.RegAsm.exe.436060.0.raw.unpack, f6ZghHUDBXH2tYmbacT.cs | High entropy of concatenated method names: 'inlnSs5o2E', 'ITPnpCntwG', 'SPinmyoBYJ', 'VKnnBkR2Ev', 'XUEnDLjCNi', 'kppncMZvGA', 'hhbnAHm1XX', 'j8gnhuTAPg', 'eTuUAqgkg4', 'kq8n4vkfpL' |
Source: 2.2.RegAsm.exe.436060.0.raw.unpack, C56DgqqHHPFZ3wjEp9K.cs | High entropy of concatenated method names: 'RwmqfVsYjb', 'YRpqrM6bO2', 'dt4qSHpYWO', 'Qw1qpMtuB7', 'LXXqBLRwVC', 'oEHqDhnw3g', 'Msmqcx9tRn', 'SQVqAVyR49', 'Nd0qh1npyC', 'LAlq4o51Sx' |
Source: 2.2.RegAsm.exe.436060.0.raw.unpack, rukH9XSdr6847h0UoRO.cs | High entropy of concatenated method names: 'kwZSwIFouV', 'rOlS22NOjF', 'CVkSk7ZYLY', 'YnoS9lDe8j', 'hm7S8SFMwd', 'm6VSEUxt7r', 'j7ySvCbJny', 'ToString', 'xR3nQVWpiSONisnYS9I', 'xoGMiiWBYOpihJvvA2r' |
Source: 2.2.RegAsm.exe.436060.0.raw.unpack, U3g2Fn0EMjdn1l2OYvs.cs | High entropy of concatenated method names: 'UuU0jDnJ9p', 'Eqr0NWRU3h', 'eyY052nXxo', 'iBi53ngrYwj6CBfJ2Gs', 'NnhUEFgf8vvSHwsF98v', 'gOWgAGgmTs3CM8QWTlu', 'GmDmRDgSbCqKpcglVEo', 'Endlltgp4TLDXxui6mq', 'PWLAKagBmMnDnAHYqN8' |
Source: 2.2.RegAsm.exe.436060.0.raw.unpack, X92ilY6hK042XbCPDTJ.cs | High entropy of concatenated method names: 'fN96Lh5Ox5', 'N7W6n7rkw2', 'D5d7yIdYwGVL8tjfENp', 'dU2ukIdKWFyyViKIQi9', 'mQOmt2dz5i8WoquQYBQ', 'lsDFXsCJwLAMHNM5PPc', 'VExMMpCOjJujvRPkYRg', 'EeIe5vdbmvTVtbsXnI5', 'ddcpYsd7xPXvp3scuYu', 'Ye3MOSC09lD59ZMFlq8' |
Source: 2.2.RegAsm.exe.436060.0.raw.unpack, ymPuo7hNqu7rH1NPowv.cs | High entropy of concatenated method names: 'pnFoJytIaQQM80HZRJF', 'Cl74jxtMDXLqLkPr77R', 'ceZLn1T8aH', 'uH21uRtYsLSpa2r1swI', 'a5OGRGtKMsbVJLIZQj4', 'qOkHXitzKZgOdiaKTpE', 'eqZY6O8JBhHIqwXiNVH', 'fqA6tl8OebDEe0jERat', 'bn9bBP800j6jcT3F1xa', 'PVEDbE8sG80Uja4IWdT' |
Source: 2.2.RegAsm.exe.436060.0.raw.unpack, JXkW8tsDkYjKfFXHfYT.cs | High entropy of concatenated method names: 'aMasAS4Zf3', 'J5oshtQCCC', 'XKPs4kGo99', 'fFSsLZdN04', 'FCFsnrI8NZ', 'mB4sTcQIok', 'QuIsZvvrPX', 'u9oso7lnLU', 'HXYsxm61Qs', 'W8wsQZVH95' |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Users\user\AppData\Roaming\DMINktnUtY.exe VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\calibrii.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\calibrili.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\calibrib.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\calibriz.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\cambria.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\Candaral.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\Candarab.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\comic.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\comicbd.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\comicz.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\constan.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\constani.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\constanb.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\constanz.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\corbel.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\corbeli.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\corbelli.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\corbelz.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\cour.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\couri.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\courbd.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\courbi.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\ebrimabd.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\FRADM.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\framdit.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\FRADMIT.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\FRAMDCN.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\FRADMCN.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\FRAHV.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\FRAHVIT.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\Gabriola.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\gadugi.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\impact.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\javatext.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\LeelawUI.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\LeelUIsl.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\LeelaUIb.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\lucon.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\l_10646.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\malgun.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\malgunsl.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\malgunbd.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\msjh.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\msjhl.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\msjhbd.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\msjh.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\ntailub.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\phagspa.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\phagspab.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\msyh.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\msyhl.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\msyhbd.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\msyh.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\msyhl.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\msyhbd.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\msyi.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\mingliub.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\monbaiti.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\msgothic.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\msgothic.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\msgothic.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\mvboli.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\mmrtext.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\mmrtextb.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\Nirmala.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\NirmalaS.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\NirmalaB.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\palai.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\palabi.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\segoepr.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\seguihis.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\simsunb.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\Sitka.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\SitkaI.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\SitkaB.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\SitkaZ.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\Sitka.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\SitkaB.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\Sitka.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\SitkaB.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\SitkaB.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\SitkaZ.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\Sitka.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\SitkaI.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\SitkaB.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\SitkaZ.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\sylfaen.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\symbol.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\tahomabd.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\timesbd.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\timesbi.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\verdana.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\verdanab.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\webdings.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\YuGothB.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\YuGothR.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\YuGothL.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\holomdl2.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\AGENCYR.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\ANTQUAB.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\ANTQUABI.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\BELLB.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\BERNHC.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\BOD_PSTC.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\BOOKOSI.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\BRLNSB.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\BROADW.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\CALIFI.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\CALISTB.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\SCHLBKB.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\SCHLBKBI.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\CENTURY.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\CHILLER.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\COOPBL.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\DUBAI-REGULAR.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\DUBAI-BOLD.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\ENGR.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\FRSCRIPT.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\GOUDOS.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\LBRITEI.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\MTCORSVA.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\NIAGENG.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\SCRIPTBL.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\SHOWG.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\SNAP____.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\TCCB____.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\TCCEB.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\DMINktnUtY.exe | Queries volume information: C:\Windows\Fonts\micross.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Users\user\AppData\Roaming\J48w21dBmF.exe VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\calibrii.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\calibrib.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\cambria.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\cambriab.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\cambriaz.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\cambria.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\Candara.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\Candaral.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\Candarai.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\Candarali.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\Candarab.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\Candaraz.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\comic.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\constanb.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\corbel.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\corbell.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\corbeli.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\corbelli.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\corbelb.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\corbelz.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\FRADM.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\georgiab.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\impact.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\Inkfree.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\javatext.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\LeelawUI.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\lucon.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\malgunbd.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\himalaya.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\msjh.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\msjhl.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\msjhbd.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\msjh.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\ntailu.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\phagspab.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\micross.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\taileb.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\msyh.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\msyhbd.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\msyh.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\msyhl.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\msyhbd.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\msyi.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\mingliub.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\mingliub.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\monbaiti.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\msgothic.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\msgothic.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\mvboli.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\mmrtext.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\mmrtextb.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\Nirmala.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\NirmalaS.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\pala.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\palai.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\palab.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\palabi.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\segoeprb.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\segoesc.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\seguihis.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\simsun.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\simsunb.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\Sitka.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\SitkaB.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\SitkaZ.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\Sitka.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\SitkaI.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\SitkaZ.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\Sitka.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\SitkaZ.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\Sitka.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\SitkaI.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\SitkaB.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\sylfaen.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\symbol.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\tahoma.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\tahomabd.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\timesi.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\timesbd.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\timesbi.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\trebuc.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\trebucbi.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\verdana.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\verdanai.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\verdanab.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\wingding.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\YuGothM.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\YuGothL.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\YuGothB.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\YuGothM.ttc VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\ANTQUAB.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\BELLI.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\BERNHC.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\BOD_CBI.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\BOD_PSTC.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\BOOKOSB.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\BRLNSB.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\BROADW.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\BRUSHSCI.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\CALIFR.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\CALIFI.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\CALISTI.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\CALISTBI.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\CENSCBK.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\SCHLBKBI.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\COLONNA.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\COOPBL.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\COPRGTB.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\ELEPHNTI.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\GARA.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\GOTHIC.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\GOTHICB.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\GOTHICBI.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\GOUDOS.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\GOUDOSI.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\GOUDYSTO.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\HARLOWSI.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\HATTEN.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\ITCEDSCR.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\LBRITED.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\MAGNETOB.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\OCRAEXT.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\ROCC____.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\WINGDNG2.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\flat_officeFontsPreview.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\J48w21dBmF.exe | Queries volume information: C:\Windows\Fonts\OFFSYM.TTF VolumeInformation | Jump to behavior |