Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Section loaded: dwrite.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Section loaded: windowscodecs.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Section loaded: edputil.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Section loaded: windows.staterepositoryps.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Section loaded: appresolver.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Section loaded: bcp47langs.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Section loaded: slc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Section loaded: sppc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Section loaded: onecorecommonproxystub.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Section loaded: onecoreuapcommonproxystub.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: atl.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: msisip.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wshext.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: appxsip.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: opcservices.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: secur32.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: microsoft.management.infrastructure.native.unmanaged.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: mi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: miutils.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wmidcom.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: dpapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wbemcomn.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Section loaded: dwrite.dll | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Section loaded: textshaping.dll | Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: fastprox.dll | Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: ncobjapi.dll | Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: wbemcomn.dll | Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: mpclient.dll | Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: wmitomi.dll | Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: mi.dll | Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: miutils.dll | Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: 0.2.ZcgffemBWp.exe.70f0000.5.raw.unpack, RjO3RPnTMH1KqcUWDG.cs | High entropy of concatenated method names: 'OCkn7eu6o3', 'qwGnp8NwIZ', 'b87nkp81Qd', 'Ow5ncsOXSd', 'Hn7n24U9Ng', 'd4HnR2RVjJ', 'Next', 'Next', 'Next', 'NextBytes' |
Source: 0.2.ZcgffemBWp.exe.70f0000.5.raw.unpack, nr89pgEAhRqo2QJF5r.cs | High entropy of concatenated method names: 'os6SWey45K', 'rcuSX1HX8o', 'ToString', 'jDISBDW7Hj', 'seESy7dp0a', 'fBjShFYpAO', 'prxSdqf82U', 'FiZSEyVrph', 'mSRSAmdy8O', 'BCtSiF2iNV' |
Source: 0.2.ZcgffemBWp.exe.70f0000.5.raw.unpack, RdpYCcw7UMt0N8clvA.cs | High entropy of concatenated method names: 'Dispose', 'rIgrII9Z77', 'YLggpQCLUY', 'agI33vWiui', 'KrWr4YV0qM', 'C0Trz2jNMv', 'ProcessDialogKey', 'VCDgxDmjHE', 't4ggrOLBhh', 'x2EggMVNOF' |
Source: 0.2.ZcgffemBWp.exe.70f0000.5.raw.unpack, OnvPYosFf2nWMIm3kP.cs | High entropy of concatenated method names: 'KePEVphedB', 'EkJEyld4FO', 'MRIEdTB0ie', 'qJfEAa31q7', 'vBvEilNWsF', 'f5NdtjIOTQ', 'hGIdlRCxcV', 'O0WdG5VZmy', 'I0ndHgRjbL', 'wbjdI1cdUQ' |
Source: 0.2.ZcgffemBWp.exe.70f0000.5.raw.unpack, i8AtpdtvCURvGU0NbhD.cs | High entropy of concatenated method names: 'etYPKfixyf', 'yNZPaln1Kl', 'f9vPFRRcvu', 'UYJPvlUjQa', 'pX7PoyaeYM', 'C1FPULYYjH', 'T8mPTpSA55', 'VRjPDx0MvC', 'i0VP8vhqlP', 'cu6PCO9DGq' |
Source: 0.2.ZcgffemBWp.exe.70f0000.5.raw.unpack, MBBvcBf8kf5GGuFkOm.cs | High entropy of concatenated method names: 'fAvNV1ZZqV', 'ztYNBMHUoo', 'WksNySlScb', 'c2DNhAwE7i', 'ly0NdJw33K', 'kWXNEtNhEr', 'pisNAj5fO2', 'qZENiDl1y8', 'eGqN0ib1bX', 's7wNWbTrVv' |
Source: 0.2.ZcgffemBWp.exe.70f0000.5.raw.unpack, uOXew4dD1eZDatbFKv.cs | High entropy of concatenated method names: 'DmXdoVvdnb', 'MrrdTVjeUi', 'a6HhkLIxex', 'cflhc2KnRk', 'QHDhRhaJDH', 'RZah1cI7xL', 'iMKhqGy3uJ', 'dYThYjIUAd', 'mJWhbCHhKO', 'sSphJjBtjk' |
Source: 0.2.ZcgffemBWp.exe.70f0000.5.raw.unpack, eGqJt7oKvi0y967BJG.cs | High entropy of concatenated method names: 'ToString', 'p4gsjcqffC', 'xtIspUdVIu', 'aRuskrFZXY', 'eQxscily38', 'tDKsRXdnny', 'O3Ns1a5TLG', 'hQOsqWG6IX', 'PNZsYbJDXR', 'm56sbxtsIJ' |
Source: 0.2.ZcgffemBWp.exe.70f0000.5.raw.unpack, xN3n22Jp0YXX3FHQTm.cs | High entropy of concatenated method names: 'clySHGbjil', 'vZRS4JssZX', 'm5lnxrxa3x', 'MfNnrj93y2', 'vU2SjqihVx', 'M3nSZ8nwww', 'kvASLOuq0G', 'fkUS2wr2Fa', 'f69Sf7ugEe', 'E29SMZiIPn' |
Source: 0.2.ZcgffemBWp.exe.70f0000.5.raw.unpack, up2kaViOnATUcYntqe.cs | High entropy of concatenated method names: 'A0QPr7tXmV', 'oXAPNMy1iF', 'i83P53d8I2', 'Xr4PBkhc6m', 'KxiPyC3vEq', 'TwJPdVC5ZG', 'L01PE2ovWH', 'at6nGD6b7s', 'wDOnH2YKFB', 'FSenINu4xl' |
Source: 0.2.ZcgffemBWp.exe.70f0000.5.raw.unpack, fy4kHNtL0suihuKkwNC.cs | High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'cdFm2g93LN', 'S46mfrvFVQ', 'bZ7mMNdXgq', 'dNtmQxkJT3', 'kQJmt1uku2', 'dAHmlwMs2R', 'AvgmGDC3QY' |
Source: 0.2.ZcgffemBWp.exe.70f0000.5.raw.unpack, xQjaQJ7ZEwHbUHQYA2.cs | High entropy of concatenated method names: 'NRnOJsEWWZ', 'ELUOZNBvO8', 'DBiO2rmdqM', 'AneOfDYWNs', 'ahaOp3cP7u', 'BK7OkiSLNH', 'xWyOcVLBPu', 'xUxORdCx3v', 'f3ZO1alnL3', 'fdXOqkUNbo' |
Source: 0.2.ZcgffemBWp.exe.70f0000.5.raw.unpack, eRvQqLArlXcm0BVAZm.cs | High entropy of concatenated method names: 'JtBnBhO02j', 'U65nyAwoOv', 'TLvnhYsTAX', 'QV2nd6Rlvd', 'x63nEhrAGM', 'aI7nAXfd1I', 'K9knifqGK0', 'OjJn06toUL', 'cRknWM2buh', 'TNSnXLBpbp' |
Source: 0.2.ZcgffemBWp.exe.70f0000.5.raw.unpack, o88qFSgu4m6VMRNM8P.cs | High entropy of concatenated method names: 'EditValue', 'GetEditStyle', 'dJSgIVcLwx', 's0tg4PsLgc', 'KIOgzXAJEB', 'MuuNxgorRX', 'G6FNrRP5mE', 'PtCNgbtb53', 'Af3NN4kl8k', 'y9NDUfqVik1BxlCYHC3' |
Source: 0.2.ZcgffemBWp.exe.70f0000.5.raw.unpack, KkrvGjYCLl3uQQbnn9.cs | High entropy of concatenated method names: 'NJ5hv60fuK', 'qTkhU0THlu', 'mo7hD94AFm', 'd8Kh819my7', 'YIxhOypr7e', 'dAwhsyTED9', 'BYhhSmNQ1M', 'OKrhnakRF3', 'TBihPbXh9S', 'UYHhmqcJvM' |
Source: 0.2.ZcgffemBWp.exe.70f0000.5.raw.unpack, gjiVYZhCPPtooM9pcg.cs | High entropy of concatenated method names: 'uRDFDPEAV', 'YZvvvRvQP', 'aBoUiOpIk', 'uVaTXoYG2', 'hkp8fxGOY', 'ThCC3PmlG', 'HLDpkDIn3nKsRatUBh', 'ls66uftl00NeFDr8mj', 'Iw6nKikxB', 'mqWmVSZxh' |
Source: 0.2.ZcgffemBWp.exe.70f0000.5.raw.unpack, y7Cwv6c5ajJPop7SjO.cs | High entropy of concatenated method names: 'FLty2bUNiT', 'Abdyfkv118', 'jaAyM8h0yo', 'qjOyQc72ZS', 'djCytBGZ8C', 'rBayljC52x', 'nHByG3dPS0', 'y55yHpunnB', 'oU9yIJGJxy', 'seQy4Y1Yh6' |
Source: 0.2.ZcgffemBWp.exe.70f0000.5.raw.unpack, dyU4AYbaGTu7GuQY2B.cs | High entropy of concatenated method names: 'gMJeDqp7g4', 'eIQe83pqXR', 'u7ee7bS7Pc', 'RnxepgkPmQ', 'PjPecyjhd7', 'iPOeRiSFjU', 'ewSeqgZXqO', 'n6ZeYarUQm', 'WiqeJp4p65', 'vWJej7oiAR' |
Source: 0.2.ZcgffemBWp.exe.70f0000.5.raw.unpack, xEbooG4hGoYmSBC4jx.cs | High entropy of concatenated method names: 'NuZABeN9Gb', 'QP0AhHAR50', 'uHCAEbNJDy', 'jMmE47J4Kq', 'AfMEzYA6jJ', 'uiYAxJ5fsS', 'TtoArTri2H', 'zMWAgeFv7W', 'jmlANypBpL', 'n4PA5T6Rmk' |
Source: 0.2.ZcgffemBWp.exe.70f0000.5.raw.unpack, NRQr7yB2nnP3x5rkFK.cs | High entropy of concatenated method names: 'UpbrAoVna6', 'lRQriunB0I', 'LpTrWG0kHm', 'qpIrXRaJPl', 'oQprOchx2F', 'WV0rsEYVaO', 'dH2FZPQjWdRxbCCpF5', 'A89B2vlaFZf5VDxOd6', 's4Zrr4o4ru', 'C2drNw3FQk' |
Source: 0.2.ZcgffemBWp.exe.70f0000.5.raw.unpack, YbODDa5X6B3PDws3lJ.cs | High entropy of concatenated method names: 'gcMAKq83Kb', 'SwvAa3pGCt', 'jBeAF3dbYK', 'GidAvy8p8s', 'iiiAoGMfTe', 'sdGAUlSLQ7', 'SjYATmKfVO', 'C5iADcqyrf', 'CyYA8VxI7v', 'xWuAC9eci1' |
Source: 0.2.ZcgffemBWp.exe.4254308.1.raw.unpack, RjO3RPnTMH1KqcUWDG.cs | High entropy of concatenated method names: 'OCkn7eu6o3', 'qwGnp8NwIZ', 'b87nkp81Qd', 'Ow5ncsOXSd', 'Hn7n24U9Ng', 'd4HnR2RVjJ', 'Next', 'Next', 'Next', 'NextBytes' |
Source: 0.2.ZcgffemBWp.exe.4254308.1.raw.unpack, nr89pgEAhRqo2QJF5r.cs | High entropy of concatenated method names: 'os6SWey45K', 'rcuSX1HX8o', 'ToString', 'jDISBDW7Hj', 'seESy7dp0a', 'fBjShFYpAO', 'prxSdqf82U', 'FiZSEyVrph', 'mSRSAmdy8O', 'BCtSiF2iNV' |
Source: 0.2.ZcgffemBWp.exe.4254308.1.raw.unpack, RdpYCcw7UMt0N8clvA.cs | High entropy of concatenated method names: 'Dispose', 'rIgrII9Z77', 'YLggpQCLUY', 'agI33vWiui', 'KrWr4YV0qM', 'C0Trz2jNMv', 'ProcessDialogKey', 'VCDgxDmjHE', 't4ggrOLBhh', 'x2EggMVNOF' |
Source: 0.2.ZcgffemBWp.exe.4254308.1.raw.unpack, OnvPYosFf2nWMIm3kP.cs | High entropy of concatenated method names: 'KePEVphedB', 'EkJEyld4FO', 'MRIEdTB0ie', 'qJfEAa31q7', 'vBvEilNWsF', 'f5NdtjIOTQ', 'hGIdlRCxcV', 'O0WdG5VZmy', 'I0ndHgRjbL', 'wbjdI1cdUQ' |
Source: 0.2.ZcgffemBWp.exe.4254308.1.raw.unpack, i8AtpdtvCURvGU0NbhD.cs | High entropy of concatenated method names: 'etYPKfixyf', 'yNZPaln1Kl', 'f9vPFRRcvu', 'UYJPvlUjQa', 'pX7PoyaeYM', 'C1FPULYYjH', 'T8mPTpSA55', 'VRjPDx0MvC', 'i0VP8vhqlP', 'cu6PCO9DGq' |
Source: 0.2.ZcgffemBWp.exe.4254308.1.raw.unpack, MBBvcBf8kf5GGuFkOm.cs | High entropy of concatenated method names: 'fAvNV1ZZqV', 'ztYNBMHUoo', 'WksNySlScb', 'c2DNhAwE7i', 'ly0NdJw33K', 'kWXNEtNhEr', 'pisNAj5fO2', 'qZENiDl1y8', 'eGqN0ib1bX', 's7wNWbTrVv' |
Source: 0.2.ZcgffemBWp.exe.4254308.1.raw.unpack, uOXew4dD1eZDatbFKv.cs | High entropy of concatenated method names: 'DmXdoVvdnb', 'MrrdTVjeUi', 'a6HhkLIxex', 'cflhc2KnRk', 'QHDhRhaJDH', 'RZah1cI7xL', 'iMKhqGy3uJ', 'dYThYjIUAd', 'mJWhbCHhKO', 'sSphJjBtjk' |
Source: 0.2.ZcgffemBWp.exe.4254308.1.raw.unpack, eGqJt7oKvi0y967BJG.cs | High entropy of concatenated method names: 'ToString', 'p4gsjcqffC', 'xtIspUdVIu', 'aRuskrFZXY', 'eQxscily38', 'tDKsRXdnny', 'O3Ns1a5TLG', 'hQOsqWG6IX', 'PNZsYbJDXR', 'm56sbxtsIJ' |
Source: 0.2.ZcgffemBWp.exe.4254308.1.raw.unpack, xN3n22Jp0YXX3FHQTm.cs | High entropy of concatenated method names: 'clySHGbjil', 'vZRS4JssZX', 'm5lnxrxa3x', 'MfNnrj93y2', 'vU2SjqihVx', 'M3nSZ8nwww', 'kvASLOuq0G', 'fkUS2wr2Fa', 'f69Sf7ugEe', 'E29SMZiIPn' |
Source: 0.2.ZcgffemBWp.exe.4254308.1.raw.unpack, up2kaViOnATUcYntqe.cs | High entropy of concatenated method names: 'A0QPr7tXmV', 'oXAPNMy1iF', 'i83P53d8I2', 'Xr4PBkhc6m', 'KxiPyC3vEq', 'TwJPdVC5ZG', 'L01PE2ovWH', 'at6nGD6b7s', 'wDOnH2YKFB', 'FSenINu4xl' |
Source: 0.2.ZcgffemBWp.exe.4254308.1.raw.unpack, fy4kHNtL0suihuKkwNC.cs | High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'cdFm2g93LN', 'S46mfrvFVQ', 'bZ7mMNdXgq', 'dNtmQxkJT3', 'kQJmt1uku2', 'dAHmlwMs2R', 'AvgmGDC3QY' |
Source: 0.2.ZcgffemBWp.exe.4254308.1.raw.unpack, xQjaQJ7ZEwHbUHQYA2.cs | High entropy of concatenated method names: 'NRnOJsEWWZ', 'ELUOZNBvO8', 'DBiO2rmdqM', 'AneOfDYWNs', 'ahaOp3cP7u', 'BK7OkiSLNH', 'xWyOcVLBPu', 'xUxORdCx3v', 'f3ZO1alnL3', 'fdXOqkUNbo' |
Source: 0.2.ZcgffemBWp.exe.4254308.1.raw.unpack, eRvQqLArlXcm0BVAZm.cs | High entropy of concatenated method names: 'JtBnBhO02j', 'U65nyAwoOv', 'TLvnhYsTAX', 'QV2nd6Rlvd', 'x63nEhrAGM', 'aI7nAXfd1I', 'K9knifqGK0', 'OjJn06toUL', 'cRknWM2buh', 'TNSnXLBpbp' |
Source: 0.2.ZcgffemBWp.exe.4254308.1.raw.unpack, o88qFSgu4m6VMRNM8P.cs | High entropy of concatenated method names: 'EditValue', 'GetEditStyle', 'dJSgIVcLwx', 's0tg4PsLgc', 'KIOgzXAJEB', 'MuuNxgorRX', 'G6FNrRP5mE', 'PtCNgbtb53', 'Af3NN4kl8k', 'y9NDUfqVik1BxlCYHC3' |
Source: 0.2.ZcgffemBWp.exe.4254308.1.raw.unpack, KkrvGjYCLl3uQQbnn9.cs | High entropy of concatenated method names: 'NJ5hv60fuK', 'qTkhU0THlu', 'mo7hD94AFm', 'd8Kh819my7', 'YIxhOypr7e', 'dAwhsyTED9', 'BYhhSmNQ1M', 'OKrhnakRF3', 'TBihPbXh9S', 'UYHhmqcJvM' |
Source: 0.2.ZcgffemBWp.exe.4254308.1.raw.unpack, gjiVYZhCPPtooM9pcg.cs | High entropy of concatenated method names: 'uRDFDPEAV', 'YZvvvRvQP', 'aBoUiOpIk', 'uVaTXoYG2', 'hkp8fxGOY', 'ThCC3PmlG', 'HLDpkDIn3nKsRatUBh', 'ls66uftl00NeFDr8mj', 'Iw6nKikxB', 'mqWmVSZxh' |
Source: 0.2.ZcgffemBWp.exe.4254308.1.raw.unpack, y7Cwv6c5ajJPop7SjO.cs | High entropy of concatenated method names: 'FLty2bUNiT', 'Abdyfkv118', 'jaAyM8h0yo', 'qjOyQc72ZS', 'djCytBGZ8C', 'rBayljC52x', 'nHByG3dPS0', 'y55yHpunnB', 'oU9yIJGJxy', 'seQy4Y1Yh6' |
Source: 0.2.ZcgffemBWp.exe.4254308.1.raw.unpack, dyU4AYbaGTu7GuQY2B.cs | High entropy of concatenated method names: 'gMJeDqp7g4', 'eIQe83pqXR', 'u7ee7bS7Pc', 'RnxepgkPmQ', 'PjPecyjhd7', 'iPOeRiSFjU', 'ewSeqgZXqO', 'n6ZeYarUQm', 'WiqeJp4p65', 'vWJej7oiAR' |
Source: 0.2.ZcgffemBWp.exe.4254308.1.raw.unpack, xEbooG4hGoYmSBC4jx.cs | High entropy of concatenated method names: 'NuZABeN9Gb', 'QP0AhHAR50', 'uHCAEbNJDy', 'jMmE47J4Kq', 'AfMEzYA6jJ', 'uiYAxJ5fsS', 'TtoArTri2H', 'zMWAgeFv7W', 'jmlANypBpL', 'n4PA5T6Rmk' |
Source: 0.2.ZcgffemBWp.exe.4254308.1.raw.unpack, NRQr7yB2nnP3x5rkFK.cs | High entropy of concatenated method names: 'UpbrAoVna6', 'lRQriunB0I', 'LpTrWG0kHm', 'qpIrXRaJPl', 'oQprOchx2F', 'WV0rsEYVaO', 'dH2FZPQjWdRxbCCpF5', 'A89B2vlaFZf5VDxOd6', 's4Zrr4o4ru', 'C2drNw3FQk' |
Source: 0.2.ZcgffemBWp.exe.4254308.1.raw.unpack, YbODDa5X6B3PDws3lJ.cs | High entropy of concatenated method names: 'gcMAKq83Kb', 'SwvAa3pGCt', 'jBeAF3dbYK', 'GidAvy8p8s', 'iiiAoGMfTe', 'sdGAUlSLQ7', 'SjYATmKfVO', 'C5iADcqyrf', 'CyYA8VxI7v', 'xWuAC9eci1' |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Queries volume information: C:\Users\user\Desktop\ZcgffemBWp.exe VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Queries volume information: C:\Windows\Fonts\micross.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\ VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-GroupPolicy-ClientTools-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-AppManagement-AppV-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\Microsoft.Management.Infrastructure.Native\v4.0_1.0.0.0__31bf3856ad364e35\Microsoft.Management.Infrastructure.Native.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\AppvClient\Microsoft.AppV.AppVClientPowerShell.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1865.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-WOW64-Package~31bf3856ad364e35~amd64~en-GB~10.0.19041.1.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\BitLocker\Microsoft.BitLocker.Structures.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management\v4.0_3.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Management.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Queries volume information: C:\Users\user\Desktop\ZcgffemBWp.exe VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\ZcgffemBWp.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation | Jump to behavior |