Source: powershell.exe, 00000002.00000002.76780432500.000000000321D000.00000004.00000020.00020000.00000000.sdmp, Sammentrykket.exe, 00000004.00000003.77039711491.00000000048E2000.00000004.00000020.00020000.00000000.sdmp, Sammentrykket.exe, 00000004.00000003.77136216434.00000000048E2000.00000004.00000020.00020000.00000000.sdmp, Sammentrykket.exe, 00000004.00000003.77135468668.00000000048E2000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://crl.comodoca.com/AAACertificateServices.crl06 |
Source: powershell.exe, 00000002.00000002.76780432500.000000000321D000.00000004.00000020.00020000.00000000.sdmp, Sammentrykket.exe, 00000004.00000003.77039711491.00000000048E2000.00000004.00000020.00020000.00000000.sdmp, Sammentrykket.exe, 00000004.00000003.77136216434.00000000048E2000.00000004.00000020.00020000.00000000.sdmp, Sammentrykket.exe, 00000004.00000003.77135468668.00000000048E2000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://crl.globalsign.net/root-r2.crl0 |
Source: Sammentrykket.exe, 00000004.00000001.76671061814.0000000000649000.00000020.00000001.01000000.00000008.sdmp |
String found in binary or memory: http://inference.location.live.com11111111-1111-1111-1111-111111111111https://partnernext-inference. |
Source: PO Tournefortian2453525525235235623425523235.exe, 00000000.00000002.76393471413.000000000040A000.00000004.00000001.01000000.00000003.sdmp, PO Tournefortian2453525525235235623425523235.exe, 00000000.00000000.76378317578.000000000040A000.00000008.00000001.01000000.00000003.sdmp |
String found in binary or memory: http://nsis.sf.net/NSIS_ErrorError |
Source: powershell.exe, 00000002.00000002.76785949957.000000000612A000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://nuget.org/NuGet.exe |
Source: powershell.exe, 00000002.00000002.76782450843.0000000005217000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://pesterbdd.com/images/Pester.png |
Source: powershell.exe, 00000002.00000002.76782450843.0000000005217000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://pesterbdd.com/images/Pester.png4 |
Source: powershell.exe, 00000002.00000002.76782450843.00000000050C1000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name |
Source: powershell.exe, 00000002.00000002.76782450843.0000000005217000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://www.apache.org/licenses/LICENSE-2.0.html |
Source: powershell.exe, 00000002.00000002.76782450843.0000000005217000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://www.apache.org/licenses/LICENSE-2.0.html4 |
Source: Sammentrykket.exe, 00000004.00000001.76671061814.0000000000649000.00000020.00000001.01000000.00000008.sdmp |
String found in binary or memory: http://www.gopher.ftp://ftp. |
Source: Sammentrykket.exe, 00000004.00000001.76671061814.0000000000626000.00000020.00000001.01000000.00000008.sdmp |
String found in binary or memory: http://www.ibm.com/data/dtd/v11/ibmxhtml1-transitional.dtd-//W3O//DTD |
Source: powershell.exe, 00000002.00000002.76780432500.000000000321D000.00000004.00000020.00020000.00000000.sdmp, Sammentrykket.exe, 00000004.00000003.77039711491.00000000048E2000.00000004.00000020.00020000.00000000.sdmp, Sammentrykket.exe, 00000004.00000003.77136216434.00000000048E2000.00000004.00000020.00020000.00000000.sdmp, Sammentrykket.exe, 00000004.00000003.77135468668.00000000048E2000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://www.quovadis.bm0 |
Source: powershell.exe, 00000002.00000002.76782450843.00000000050C1000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://aka.ms/pscore6lB |
Source: powershell.exe, 00000002.00000002.76785949957.000000000612A000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://contoso.com/ |
Source: powershell.exe, 00000002.00000002.76785949957.000000000612A000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://contoso.com/Icon |
Source: powershell.exe, 00000002.00000002.76785949957.000000000612A000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://contoso.com/License |
Source: powershell.exe, 00000002.00000002.76782450843.0000000005217000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://github.com/Pester/Pester |
Source: powershell.exe, 00000002.00000002.76782450843.0000000005217000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://github.com/Pester/Pester4 |
Source: Sammentrykket.exe, 00000004.00000001.76671061814.0000000000649000.00000020.00000001.01000000.00000008.sdmp |
String found in binary or memory: https://inference.location.live.net/inferenceservice/v21/Pox/GetLocationUsingFingerprinte1e71f6b-214 |
Source: powershell.exe, 00000002.00000002.76785949957.000000000612A000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://nuget.org/nuget.exe |
Source: powershell.exe, 00000002.00000002.76780432500.000000000321D000.00000004.00000020.00020000.00000000.sdmp, Sammentrykket.exe, 00000004.00000003.77039711491.00000000048E2000.00000004.00000020.00020000.00000000.sdmp, Sammentrykket.exe, 00000004.00000003.77136216434.00000000048E2000.00000004.00000020.00020000.00000000.sdmp, Sammentrykket.exe, 00000004.00000003.77135468668.00000000048E2000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://ocsp.quovadisoffshore.com0 |
Source: Sammentrykket.exe, 00000004.00000003.77136726603.0000000004890000.00000004.00000020.00020000.00000000.sdmp, Sammentrykket.exe, 00000004.00000002.77592580545.0000000004891000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://villa-ventura.com/ |
Source: Sammentrykket.exe, 00000004.00000003.77136726603.00000000048A7000.00000004.00000020.00020000.00000000.sdmp, Sammentrykket.exe, 00000004.00000002.77592493794.0000000004868000.00000004.00000020.00020000.00000000.sdmp, Sammentrykket.exe, 00000004.00000002.77592580545.00000000048A7000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://villa-ventura.com/FPkXcnPDrjTal168.bin |
Source: Sammentrykket.exe, 00000004.00000002.77592493794.0000000004868000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://villa-ventura.com/FPkXcnPDrjTal168.binwt? |
Source: C:\Users\user\Desktop\PO Tournefortian2453525525235235623425523235.exe |
Section loaded: edgegdi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\PO Tournefortian2453525525235235623425523235.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\PO Tournefortian2453525525235235623425523235.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\PO Tournefortian2453525525235235623425523235.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\PO Tournefortian2453525525235235623425523235.exe |
Section loaded: propsys.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\PO Tournefortian2453525525235235623425523235.exe |
Section loaded: dwmapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\PO Tournefortian2453525525235235623425523235.exe |
Section loaded: cryptbase.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\PO Tournefortian2453525525235235623425523235.exe |
Section loaded: oleacc.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\PO Tournefortian2453525525235235623425523235.exe |
Section loaded: ntmarta.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\PO Tournefortian2453525525235235623425523235.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\PO Tournefortian2453525525235235623425523235.exe |
Section loaded: shfolder.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\PO Tournefortian2453525525235235623425523235.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\PO Tournefortian2453525525235235623425523235.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\PO Tournefortian2453525525235235623425523235.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\PO Tournefortian2453525525235235623425523235.exe |
Section loaded: riched20.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\PO Tournefortian2453525525235235623425523235.exe |
Section loaded: usp10.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\PO Tournefortian2453525525235235623425523235.exe |
Section loaded: msls31.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\PO Tournefortian2453525525235235623425523235.exe |
Section loaded: textinputframework.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\PO Tournefortian2453525525235235623425523235.exe |
Section loaded: coreuicomponents.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\PO Tournefortian2453525525235235623425523235.exe |
Section loaded: coremessaging.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\PO Tournefortian2453525525235235623425523235.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\PO Tournefortian2453525525235235623425523235.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\PO Tournefortian2453525525235235623425523235.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\PO Tournefortian2453525525235235623425523235.exe |
Section loaded: textshaping.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: atl.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: mscoree.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: edgegdi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: vcruntime140_clr0400.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: cryptsp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: rsaenh.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: cryptbase.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: msasn1.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: amsi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: gpapi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: msisip.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: wshext.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: appxsip.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: opcservices.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: urlmon.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: xmllite.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: iertutil.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: srvcli.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: netutils.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: secur32.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: wbemcomn.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: napinsp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: pnrpnsp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: wshbth.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: nlaapi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: iphlpapi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: mswsock.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: dnsapi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: winrnr.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: fwpuclnt.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: rasadhlp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: ntmarta.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: msi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Section loaded: iertutil.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Section loaded: powrprof.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Section loaded: winhttp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Section loaded: wkscli.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Section loaded: netutils.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Section loaded: edgegdi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Section loaded: umpdc.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Section loaded: msi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Section loaded: wininet.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Section loaded: ondemandconnroutehelper.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Section loaded: mswsock.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Section loaded: iphlpapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Section loaded: winnsi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Section loaded: urlmon.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Section loaded: srvcli.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Section loaded: dnsapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Section loaded: rasadhlp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Section loaded: fwpuclnt.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Section loaded: schannel.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Section loaded: mskeyprotect.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Section loaded: ntasn1.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Section loaded: msasn1.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Section loaded: dpapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Section loaded: cryptsp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Section loaded: rsaenh.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Section loaded: cryptbase.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Section loaded: gpapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Section loaded: ncrypt.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Section loaded: ncryptsslp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\PO Tournefortian2453525525235235623425523235.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_2091C090 mov eax, dword ptr fs:[00000030h] |
4_2_2091C090 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_2091A093 mov ecx, dword ptr fs:[00000030h] |
4_2_2091A093 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_209F4080 mov eax, dword ptr fs:[00000030h] |
4_2_209F4080 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_209F4080 mov eax, dword ptr fs:[00000030h] |
4_2_209F4080 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_209F4080 mov eax, dword ptr fs:[00000030h] |
4_2_209F4080 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_209F4080 mov eax, dword ptr fs:[00000030h] |
4_2_209F4080 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_209F4080 mov eax, dword ptr fs:[00000030h] |
4_2_209F4080 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_209F4080 mov eax, dword ptr fs:[00000030h] |
4_2_209F4080 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_209F4080 mov eax, dword ptr fs:[00000030h] |
4_2_209F4080 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_209F50B7 mov eax, dword ptr fs:[00000030h] |
4_2_209F50B7 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_209DB0AF mov eax, dword ptr fs:[00000030h] |
4_2_209DB0AF |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_209600A5 mov eax, dword ptr fs:[00000030h] |
4_2_209600A5 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_209CF0A5 mov eax, dword ptr fs:[00000030h] |
4_2_209CF0A5 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_209CF0A5 mov eax, dword ptr fs:[00000030h] |
4_2_209CF0A5 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_209CF0A5 mov eax, dword ptr fs:[00000030h] |
4_2_209CF0A5 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_209CF0A5 mov eax, dword ptr fs:[00000030h] |
4_2_209CF0A5 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_209CF0A5 mov eax, dword ptr fs:[00000030h] |
4_2_209CF0A5 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_209CF0A5 mov eax, dword ptr fs:[00000030h] |
4_2_209CF0A5 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_209CF0A5 mov eax, dword ptr fs:[00000030h] |
4_2_209CF0A5 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_2093B0D0 mov eax, dword ptr fs:[00000030h] |
4_2_2093B0D0 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_2091B0D6 mov eax, dword ptr fs:[00000030h] |
4_2_2091B0D6 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_2091B0D6 mov eax, dword ptr fs:[00000030h] |
4_2_2091B0D6 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_2091B0D6 mov eax, dword ptr fs:[00000030h] |
4_2_2091B0D6 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_2091B0D6 mov eax, dword ptr fs:[00000030h] |
4_2_2091B0D6 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_2095D0F0 mov eax, dword ptr fs:[00000030h] |
4_2_2095D0F0 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_2095D0F0 mov ecx, dword ptr fs:[00000030h] |
4_2_2095D0F0 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_2091C0F6 mov eax, dword ptr fs:[00000030h] |
4_2_2091C0F6 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_209190F8 mov eax, dword ptr fs:[00000030h] |
4_2_209190F8 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_209190F8 mov eax, dword ptr fs:[00000030h] |
4_2_209190F8 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_209190F8 mov eax, dword ptr fs:[00000030h] |
4_2_209190F8 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_209190F8 mov eax, dword ptr fs:[00000030h] |
4_2_209190F8 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_20945004 mov eax, dword ptr fs:[00000030h] |
4_2_20945004 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_20945004 mov ecx, dword ptr fs:[00000030h] |
4_2_20945004 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_20928009 mov eax, dword ptr fs:[00000030h] |
4_2_20928009 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_2091D02D mov eax, dword ptr fs:[00000030h] |
4_2_2091D02D |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_20921051 mov eax, dword ptr fs:[00000030h] |
4_2_20921051 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_20921051 mov eax, dword ptr fs:[00000030h] |
4_2_20921051 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_209F505B mov eax, dword ptr fs:[00000030h] |
4_2_209F505B |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_20950044 mov eax, dword ptr fs:[00000030h] |
4_2_20950044 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_20927072 mov eax, dword ptr fs:[00000030h] |
4_2_20927072 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_20926074 mov eax, dword ptr fs:[00000030h] |
4_2_20926074 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_20926074 mov eax, dword ptr fs:[00000030h] |
4_2_20926074 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_209C9060 mov eax, dword ptr fs:[00000030h] |
4_2_209C9060 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_20949194 mov eax, dword ptr fs:[00000030h] |
4_2_20949194 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_20961190 mov eax, dword ptr fs:[00000030h] |
4_2_20961190 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_20961190 mov eax, dword ptr fs:[00000030h] |
4_2_20961190 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_20924180 mov eax, dword ptr fs:[00000030h] |
4_2_20924180 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_20924180 mov eax, dword ptr fs:[00000030h] |
4_2_20924180 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_20924180 mov eax, dword ptr fs:[00000030h] |
4_2_20924180 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_209F51B6 mov eax, dword ptr fs:[00000030h] |
4_2_209F51B6 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_209531BE mov eax, dword ptr fs:[00000030h] |
4_2_209531BE |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_209531BE mov eax, dword ptr fs:[00000030h] |
4_2_209531BE |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_209541BB mov ecx, dword ptr fs:[00000030h] |
4_2_209541BB |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_209541BB mov eax, dword ptr fs:[00000030h] |
4_2_209541BB |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_209541BB mov eax, dword ptr fs:[00000030h] |
4_2_209541BB |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_2095E1A4 mov eax, dword ptr fs:[00000030h] |
4_2_2095E1A4 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_2095E1A4 mov eax, dword ptr fs:[00000030h] |
4_2_2095E1A4 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_209301C0 mov eax, dword ptr fs:[00000030h] |
4_2_209301C0 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_209301C0 mov eax, dword ptr fs:[00000030h] |
4_2_209301C0 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_209351C0 mov eax, dword ptr fs:[00000030h] |
4_2_209351C0 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_209351C0 mov eax, dword ptr fs:[00000030h] |
4_2_209351C0 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_209351C0 mov eax, dword ptr fs:[00000030h] |
4_2_209351C0 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_209351C0 mov eax, dword ptr fs:[00000030h] |
4_2_209351C0 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_209191F0 mov eax, dword ptr fs:[00000030h] |
4_2_209191F0 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_209191F0 mov eax, dword ptr fs:[00000030h] |
4_2_209191F0 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_209301F1 mov eax, dword ptr fs:[00000030h] |
4_2_209301F1 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_209301F1 mov eax, dword ptr fs:[00000030h] |
4_2_209301F1 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_209301F1 mov eax, dword ptr fs:[00000030h] |
4_2_209301F1 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_2094F1F0 mov eax, dword ptr fs:[00000030h] |
4_2_2094F1F0 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_2094F1F0 mov eax, dword ptr fs:[00000030h] |
4_2_2094F1F0 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_209E81EE mov eax, dword ptr fs:[00000030h] |
4_2_209E81EE |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_209E81EE mov eax, dword ptr fs:[00000030h] |
4_2_209E81EE |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_2092A1E3 mov eax, dword ptr fs:[00000030h] |
4_2_2092A1E3 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_2092A1E3 mov eax, dword ptr fs:[00000030h] |
4_2_2092A1E3 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_2092A1E3 mov eax, dword ptr fs:[00000030h] |
4_2_2092A1E3 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_2092A1E3 mov eax, dword ptr fs:[00000030h] |
4_2_2092A1E3 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_2092A1E3 mov eax, dword ptr fs:[00000030h] |
4_2_2092A1E3 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_2094B1E0 mov eax, dword ptr fs:[00000030h] |
4_2_2094B1E0 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_2094B1E0 mov eax, dword ptr fs:[00000030h] |
4_2_2094B1E0 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_2094B1E0 mov eax, dword ptr fs:[00000030h] |
4_2_2094B1E0 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_2094B1E0 mov eax, dword ptr fs:[00000030h] |
4_2_2094B1E0 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_2094B1E0 mov eax, dword ptr fs:[00000030h] |
4_2_2094B1E0 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_2094B1E0 mov eax, dword ptr fs:[00000030h] |
4_2_2094B1E0 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_2094B1E0 mov eax, dword ptr fs:[00000030h] |
4_2_2094B1E0 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_209291E5 mov eax, dword ptr fs:[00000030h] |
4_2_209291E5 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_209291E5 mov eax, dword ptr fs:[00000030h] |
4_2_209291E5 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_209181EB mov eax, dword ptr fs:[00000030h] |
4_2_209181EB |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_2091F113 mov eax, dword ptr fs:[00000030h] |
4_2_2091F113 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_2091F113 mov eax, dword ptr fs:[00000030h] |
4_2_2091F113 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_2091F113 mov eax, dword ptr fs:[00000030h] |
4_2_2091F113 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_2091F113 mov eax, dword ptr fs:[00000030h] |
4_2_2091F113 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_2091F113 mov eax, dword ptr fs:[00000030h] |
4_2_2091F113 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_2091F113 mov eax, dword ptr fs:[00000030h] |
4_2_2091F113 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_2091F113 mov eax, dword ptr fs:[00000030h] |
4_2_2091F113 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_2091F113 mov eax, dword ptr fs:[00000030h] |
4_2_2091F113 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_2091F113 mov eax, dword ptr fs:[00000030h] |
4_2_2091F113 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_2091F113 mov eax, dword ptr fs:[00000030h] |
4_2_2091F113 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_2091F113 mov eax, dword ptr fs:[00000030h] |
4_2_2091F113 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_2091F113 mov eax, dword ptr fs:[00000030h] |
4_2_2091F113 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_2091F113 mov eax, dword ptr fs:[00000030h] |
4_2_2091F113 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_2091F113 mov eax, dword ptr fs:[00000030h] |
4_2_2091F113 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_2091F113 mov eax, dword ptr fs:[00000030h] |
4_2_2091F113 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_2091F113 mov eax, dword ptr fs:[00000030h] |
4_2_2091F113 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_2091F113 mov eax, dword ptr fs:[00000030h] |
4_2_2091F113 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_2091F113 mov eax, dword ptr fs:[00000030h] |
4_2_2091F113 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_2091F113 mov eax, dword ptr fs:[00000030h] |
4_2_2091F113 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_2091F113 mov eax, dword ptr fs:[00000030h] |
4_2_2091F113 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_2091F113 mov eax, dword ptr fs:[00000030h] |
4_2_2091F113 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_20950118 mov eax, dword ptr fs:[00000030h] |
4_2_20950118 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_2094510F mov eax, dword ptr fs:[00000030h] |
4_2_2094510F |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_2094510F mov eax, dword ptr fs:[00000030h] |
4_2_2094510F |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_2094510F mov eax, dword ptr fs:[00000030h] |
4_2_2094510F |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_2094510F mov eax, dword ptr fs:[00000030h] |
4_2_2094510F |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_2094510F mov eax, dword ptr fs:[00000030h] |
4_2_2094510F |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_2094510F mov eax, dword ptr fs:[00000030h] |
4_2_2094510F |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_2094510F mov eax, dword ptr fs:[00000030h] |
4_2_2094510F |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_2094510F mov eax, dword ptr fs:[00000030h] |
4_2_2094510F |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_2094510F mov eax, dword ptr fs:[00000030h] |
4_2_2094510F |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_2094510F mov eax, dword ptr fs:[00000030h] |
4_2_2094510F |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_2094510F mov eax, dword ptr fs:[00000030h] |
4_2_2094510F |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_2094510F mov eax, dword ptr fs:[00000030h] |
4_2_2094510F |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_2094510F mov eax, dword ptr fs:[00000030h] |
4_2_2094510F |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_2092510D mov eax, dword ptr fs:[00000030h] |
4_2_2092510D |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_209DF13E mov eax, dword ptr fs:[00000030h] |
4_2_209DF13E |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_20957128 mov eax, dword ptr fs:[00000030h] |
4_2_20957128 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_20957128 mov eax, dword ptr fs:[00000030h] |
4_2_20957128 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_209F3157 mov eax, dword ptr fs:[00000030h] |
4_2_209F3157 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_209F3157 mov eax, dword ptr fs:[00000030h] |
4_2_209F3157 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_209F3157 mov eax, dword ptr fs:[00000030h] |
4_2_209F3157 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_2095415F mov eax, dword ptr fs:[00000030h] |
4_2_2095415F |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_209B314A mov eax, dword ptr fs:[00000030h] |
4_2_209B314A |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_209B314A mov eax, dword ptr fs:[00000030h] |
4_2_209B314A |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_209B314A mov eax, dword ptr fs:[00000030h] |
4_2_209B314A |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_209B314A mov eax, dword ptr fs:[00000030h] |
4_2_209B314A |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_209F5149 mov eax, dword ptr fs:[00000030h] |
4_2_209F5149 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_2091A147 mov eax, dword ptr fs:[00000030h] |
4_2_2091A147 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_2091A147 mov eax, dword ptr fs:[00000030h] |
4_2_2091A147 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_2091A147 mov eax, dword ptr fs:[00000030h] |
4_2_2091A147 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_20926179 mov eax, dword ptr fs:[00000030h] |
4_2_20926179 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_2097717A mov eax, dword ptr fs:[00000030h] |
4_2_2097717A |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_2097717A mov eax, dword ptr fs:[00000030h] |
4_2_2097717A |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_20927290 mov eax, dword ptr fs:[00000030h] |
4_2_20927290 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_20927290 mov eax, dword ptr fs:[00000030h] |
4_2_20927290 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_20927290 mov eax, dword ptr fs:[00000030h] |
4_2_20927290 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_2099E289 mov eax, dword ptr fs:[00000030h] |
4_2_2099E289 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_2091C2B0 mov ecx, dword ptr fs:[00000030h] |
4_2_2091C2B0 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_209FB2BC mov eax, dword ptr fs:[00000030h] |
4_2_209FB2BC |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_209FB2BC mov eax, dword ptr fs:[00000030h] |
4_2_209FB2BC |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_209FB2BC mov eax, dword ptr fs:[00000030h] |
4_2_209FB2BC |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_209FB2BC mov eax, dword ptr fs:[00000030h] |
4_2_209FB2BC |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_209DF2AE mov eax, dword ptr fs:[00000030h] |
4_2_209DF2AE |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_209E92AB mov eax, dword ptr fs:[00000030h] |
4_2_209E92AB |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_209442AF mov eax, dword ptr fs:[00000030h] |
4_2_209442AF |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_209442AF mov eax, dword ptr fs:[00000030h] |
4_2_209442AF |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_209192AF mov eax, dword ptr fs:[00000030h] |
4_2_209192AF |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_209432C5 mov eax, dword ptr fs:[00000030h] |
4_2_209432C5 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_209532C0 mov eax, dword ptr fs:[00000030h] |
4_2_209532C0 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_209532C0 mov eax, dword ptr fs:[00000030h] |
4_2_209532C0 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_209F32C9 mov eax, dword ptr fs:[00000030h] |
4_2_209F32C9 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_209302F9 mov eax, dword ptr fs:[00000030h] |
4_2_209302F9 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_209302F9 mov eax, dword ptr fs:[00000030h] |
4_2_209302F9 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_209302F9 mov eax, dword ptr fs:[00000030h] |
4_2_209302F9 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_209302F9 mov eax, dword ptr fs:[00000030h] |
4_2_209302F9 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_209302F9 mov eax, dword ptr fs:[00000030h] |
4_2_209302F9 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_209302F9 mov eax, dword ptr fs:[00000030h] |
4_2_209302F9 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_209302F9 mov eax, dword ptr fs:[00000030h] |
4_2_209302F9 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_209302F9 mov eax, dword ptr fs:[00000030h] |
4_2_209302F9 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_209172E0 mov eax, dword ptr fs:[00000030h] |
4_2_209172E0 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_2092A2E0 mov eax, dword ptr fs:[00000030h] |
4_2_2092A2E0 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_2092A2E0 mov eax, dword ptr fs:[00000030h] |
4_2_2092A2E0 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_2092A2E0 mov eax, dword ptr fs:[00000030h] |
4_2_2092A2E0 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_2092A2E0 mov eax, dword ptr fs:[00000030h] |
4_2_2092A2E0 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_2092A2E0 mov eax, dword ptr fs:[00000030h] |
4_2_2092A2E0 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_2092A2E0 mov eax, dword ptr fs:[00000030h] |
4_2_2092A2E0 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_209282E0 mov eax, dword ptr fs:[00000030h] |
4_2_209282E0 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_209282E0 mov eax, dword ptr fs:[00000030h] |
4_2_209282E0 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_209282E0 mov eax, dword ptr fs:[00000030h] |
4_2_209282E0 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_209282E0 mov eax, dword ptr fs:[00000030h] |
4_2_209282E0 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_2091D2EC mov eax, dword ptr fs:[00000030h] |
4_2_2091D2EC |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_2091D2EC mov eax, dword ptr fs:[00000030h] |
4_2_2091D2EC |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_2091821B mov eax, dword ptr fs:[00000030h] |
4_2_2091821B |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_209AB214 mov eax, dword ptr fs:[00000030h] |
4_2_209AB214 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_209AB214 mov eax, dword ptr fs:[00000030h] |
4_2_209AB214 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_2091A200 mov eax, dword ptr fs:[00000030h] |
4_2_2091A200 |
Source: C:\Users\user\AppData\Local\Temp\Sammentrykket.exe |
Code function: 4_2_20940230 mov ecx, dword ptr fs:[00000030h] |
4_2_20940230 |