Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Code function: 0_2_015DD5BC |
0_2_015DD5BC |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Code function: 0_2_055D8514 |
0_2_055D8514 |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Code function: 0_2_055D8A28 |
0_2_055D8A28 |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Code function: 0_2_055D0040 |
0_2_055D0040 |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Code function: 0_2_055D0006 |
0_2_055D0006 |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Code function: 0_2_055D8A22 |
0_2_055D8A22 |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Code function: 0_2_055D9868 |
0_2_055D9868 |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Code function: 0_2_07579180 |
0_2_07579180 |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Code function: 0_2_0757A0B8 |
0_2_0757A0B8 |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Code function: 0_2_07575AF0 |
0_2_07575AF0 |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Code function: 0_2_0757A900 |
0_2_0757A900 |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Code function: 0_2_07574920 |
0_2_07574920 |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Code function: 0_2_075769D8 |
0_2_075769D8 |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Code function: 0_2_07577700 |
0_2_07577700 |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Code function: 0_2_075776F0 |
0_2_075776F0 |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Code function: 0_2_075784D0 |
0_2_075784D0 |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Code function: 0_2_075784C3 |
0_2_075784C3 |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Code function: 0_2_075793D8 |
0_2_075793D8 |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Code function: 0_2_075793C8 |
0_2_075793C8 |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Code function: 0_2_07579170 |
0_2_07579170 |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Code function: 0_2_07575078 |
0_2_07575078 |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Code function: 0_2_075770E0 |
0_2_075770E0 |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Code function: 0_2_07575088 |
0_2_07575088 |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Code function: 0_2_0757A0A8 |
0_2_0757A0A8 |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Code function: 0_2_07578F70 |
0_2_07578F70 |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Code function: 0_2_07578F6A |
0_2_07578F6A |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Code function: 0_2_0757AE40 |
0_2_0757AE40 |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Code function: 0_2_0757AE30 |
0_2_0757AE30 |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Code function: 0_2_07578D10 |
0_2_07578D10 |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Code function: 0_2_07578D03 |
0_2_07578D03 |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Code function: 0_2_0757EC18 |
0_2_0757EC18 |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Code function: 0_2_07578B70 |
0_2_07578B70 |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Code function: 0_2_07578B62 |
0_2_07578B62 |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Code function: 0_2_07575AE1 |
0_2_07575AE1 |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Code function: 0_2_07574912 |
0_2_07574912 |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Code function: 0_2_07573918 |
0_2_07573918 |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Code function: 0_2_07577900 |
0_2_07577900 |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Code function: 0_2_07579900 |
0_2_07579900 |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Code function: 0_2_07576909 |
0_2_07576909 |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Code function: 0_2_07573908 |
0_2_07573908 |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Code function: 0_2_07576993 |
0_2_07576993 |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Code function: 0_2_07576985 |
0_2_07576985 |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Code function: 0_2_075729A2 |
0_2_075729A2 |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Code function: 0_2_075799AB |
0_2_075799AB |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Code function: 0_2_075729A8 |
0_2_075729A8 |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Code function: 0_2_075778F0 |
0_2_075778F0 |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Code function: 0_2_075798F0 |
0_2_075798F0 |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Code function: 0_2_0757A8F0 |
0_2_0757A8F0 |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Code function: 0_2_07A386B0 |
0_2_07A386B0 |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Code function: 0_2_07A33D60 |
0_2_07A33D60 |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Code function: 0_2_07A31C88 |
0_2_07A31C88 |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Code function: 0_2_07A31C78 |
0_2_07A31C78 |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Code function: 0_2_07A34270 |
0_2_07A34270 |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Code function: 0_2_07A3425F |
0_2_07A3425F |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Code function: 0_2_07A320B0 |
0_2_07A320B0 |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Code function: 0_2_07A320C0 |
0_2_07A320C0 |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Code function: 0_2_07A3180B |
0_2_07A3180B |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Code function: 0_2_07A31850 |
0_2_07A31850 |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Code function: 5_2_02C593F8 |
5_2_02C593F8 |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Code function: 5_2_02C54A60 |
5_2_02C54A60 |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Code function: 5_2_02C59BB0 |
5_2_02C59BB0 |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Code function: 5_2_02C53E48 |
5_2_02C53E48 |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Code function: 5_2_02C5CF20 |
5_2_02C5CF20 |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Code function: 5_2_02C54190 |
5_2_02C54190 |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Code function: 5_2_06262EF8 |
5_2_06262EF8 |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Code function: 5_2_06265588 |
5_2_06265588 |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Code function: 5_2_06263DE8 |
5_2_06263DE8 |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Code function: 5_2_06268A68 |
5_2_06268A68 |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Code function: 5_2_0626BBE8 |
5_2_0626BBE8 |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Code function: 5_2_06260040 |
5_2_06260040 |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Code function: 5_2_062699B8 |
5_2_062699B8 |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Code function: 5_2_06263650 |
5_2_06263650 |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Code function: 5_2_06264EA0 |
5_2_06264EA0 |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Code function: 5_2_0626F268 |
5_2_0626F268 |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Code function: 5_2_0626F180 |
5_2_0626F180 |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Code function: 5_2_06579558 |
5_2_06579558 |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Code function: 5_2_06579548 |
5_2_06579548 |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Code function: 5_2_06573158 |
5_2_06573158 |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Code function: 5_2_02C5D2D8 |
5_2_02C5D2D8 |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Section loaded: mscoree.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Section loaded: vcruntime140_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Section loaded: cryptsp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Section loaded: rsaenh.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Section loaded: cryptbase.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Section loaded: dwrite.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Section loaded: windowscodecs.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Section loaded: amsi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Section loaded: msasn1.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Section loaded: gpapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Section loaded: propsys.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Section loaded: edputil.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Section loaded: urlmon.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Section loaded: iertutil.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Section loaded: srvcli.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Section loaded: netutils.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Section loaded: windows.staterepositoryps.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Section loaded: appresolver.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Section loaded: bcp47langs.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Section loaded: slc.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Section loaded: sppc.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Section loaded: onecorecommonproxystub.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Section loaded: onecoreuapcommonproxystub.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: atl.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: mscoree.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: vcruntime140_clr0400.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: cryptsp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: rsaenh.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: cryptbase.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: msasn1.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: amsi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: gpapi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: msisip.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: wshext.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: appxsip.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: opcservices.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: secur32.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: urlmon.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: iertutil.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: srvcli.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: netutils.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: propsys.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: wininet.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: microsoft.management.infrastructure.native.unmanaged.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: mi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: miutils.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: wmidcom.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: dpapi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: wbemcomn.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Section loaded: mscoree.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Section loaded: vcruntime140_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Section loaded: cryptsp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Section loaded: rsaenh.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Section loaded: cryptbase.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Section loaded: wbemcomn.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Section loaded: amsi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Section loaded: vaultcli.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Section loaded: edputil.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Section loaded: windowscodecs.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Section loaded: rasapi32.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Section loaded: rasman.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Section loaded: rtutils.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Section loaded: mswsock.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Section loaded: winhttp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Section loaded: ondemandconnroutehelper.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Section loaded: iphlpapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Section loaded: dhcpcsvc6.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Section loaded: dhcpcsvc.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Section loaded: dnsapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Section loaded: winnsi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Section loaded: rasadhlp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Section loaded: fwpuclnt.dll |
Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: fastprox.dll |
Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: wbemcomn.dll |
Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: ncobjapi.dll |
Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: wbemcomn.dll |
Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: mpclient.dll |
Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: msasn1.dll |
Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: wmitomi.dll |
Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: mi.dll |
Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: miutils.dll |
Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: gpapi.dll |
Jump to behavior |
Source: 0.2.hesaphareketi__20241001.exe.4b5a1f0.0.raw.unpack, oM3yqP0pdOqJtt0hwo.cs |
High entropy of concatenated method names: 'Gdv6YxasrE', 'bbt6jbl4Zl', 'ahb6VN4WJe', 'GrB6lNbeAf', 'qUV6922YSR', 'wYt6cBwkQC', 'gamWHa5xZQiT4hOarQ', 'okWpYddVd96LG4v2S1', 'iaW9tS6kBOO8bOXSOd', 'IsE66JAq8f' |
Source: 0.2.hesaphareketi__20241001.exe.4b5a1f0.0.raw.unpack, jxtK5RFj1Y2g2eJ6Jh.cs |
High entropy of concatenated method names: 'IO6N618GSK', 'C0ZNS3cnN5', 'IIMN08VWhk', 'VeJNybVTRi', 'Tb0N8YFRUg', 'BTbNAv1Tbe', 'TsONsK3l3g', 'ywxiGAoq1y', 'pu1iBtwN9s', 'spjiRLZvqZ' |
Source: 0.2.hesaphareketi__20241001.exe.4b5a1f0.0.raw.unpack, xxMJ9R6aIbQ1FxVAIOn.cs |
High entropy of concatenated method names: 'C27Ne3d7Ve', 'w91NMaPoBf', 'pFmNrjkkN7', 'xL3NUMi86Q', 'oyQNm1Uf3g', 'k7yNIn1ciE', 'mnPNoRCClQ', 'XKJNbTX1pZ', 'BbWNTi85cE', 'EbtNDahjaI' |
Source: 0.2.hesaphareketi__20241001.exe.4b5a1f0.0.raw.unpack, yvnqjZuT3Mj4EaRnjM.cs |
High entropy of concatenated method names: 'EditValue', 'GetEditStyle', 'F4HpR82jn4', 'zJcpFsKgvf', 'M59pz0KFTX', 'wWOSaMMrwK', 'jTsS6cIxdH', 'SQ1Sp5fZgu', 'endSSjp6XL', 'tiDy9xyeQbAnAum0njx' |
Source: 0.2.hesaphareketi__20241001.exe.4b5a1f0.0.raw.unpack, rQMVFf4JGsgCQU071W.cs |
High entropy of concatenated method names: 'v8WEbTYsD3', 'cxOETM3Kke', 'VbMEvOWJPQ', 'vWeEtidKZC', 'vV5E27yd4A', 'FimEQW2XG8', 'F76E1s2xpM', 'A6JEJx1YqO', 'NxAEfHrmE4', 'zRIEdDmtvY' |
Source: 0.2.hesaphareketi__20241001.exe.4b5a1f0.0.raw.unpack, j2A3akwxX8ZEUCuPhW.cs |
High entropy of concatenated method names: 'AvLhB5oiZ5', 'NbchFoshMe', 'peiiacQI6a', 'domi6oqhlp', 'PmlhdYJwnQ', 'HQLhLvjj3y', 'su1h4c8BAU', 'xEEh3sBWI4', 'j5phOaqt2i', 'LbQh7FMMcl' |
Source: 0.2.hesaphareketi__20241001.exe.4b5a1f0.0.raw.unpack, lXcL7hR8MPuGRUdffj.cs |
High entropy of concatenated method names: 's9BivdlkwL', 'GgRitCkbmb', 'XZOiHqBnXQ', 'RXyi2Ey2MV', 'LA6i3Yh0uU', 'lqJiQq0qX8', 'Next', 'Next', 'Next', 'NextBytes' |
Source: 0.2.hesaphareketi__20241001.exe.4b5a1f0.0.raw.unpack, yrtDJ8zlG303A4dPlO.cs |
High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'ALVNEC8gOQ', 'XRwN9Z43Yw', 'NmUNc9563O', 'y2nNhORViA', 'CH4NiPScgb', 'YeLNNWbrY5', 'Fc1NnonUSd' |
Source: 0.2.hesaphareketi__20241001.exe.4b5a1f0.0.raw.unpack, GxasrEb6btbl4ZlyPy.cs |
High entropy of concatenated method names: 'EuP83RttDC', 'MKI8OaIgR1', 'f9387Z1ELR', 'GQe8qlEtGP', 'Wew8xtix22', 'CWn8wlsGcM', 'sD28GtnWVw', 'o5l8BXCGhr', 'daJ8R0VtlF', 'dxa8FXgBo6' |
Source: 0.2.hesaphareketi__20241001.exe.4b5a1f0.0.raw.unpack, QcccKvBOIqNEDDbfSO.cs |
High entropy of concatenated method names: 'CB1iydUHER', 'z1yi8qtpG4', 'PpCiuGPYUX', 'DTriACk9Fs', 'YLFisWLROX', 'EbKiY0F5uY', 'KlSijg1RtP', 'HupiC7LRfb', 'IIQiV8JTIg', 'HWPilGcqGd' |
Source: 0.2.hesaphareketi__20241001.exe.4b5a1f0.0.raw.unpack, kMIvxVgMnZ8X3ijAoI.cs |
High entropy of concatenated method names: 'UW2YeUJBcb', 'VVAYMCNJqi', 'M6HYrjydNa', 'FWNYU1iLD4', 'yWAYmU0HDU', 'WwmYIFfr3w', 'GNcYocupWU', 'y7QYbpj7J6', 'BUqYT8JqmW', 'CBsYDZVKcB' |
Source: 0.2.hesaphareketi__20241001.exe.4b5a1f0.0.raw.unpack, xCkofu1qgWKeqdhGVy.cs |
High entropy of concatenated method names: 'FYoYy9Lj8n', 'o5dYuNKuhd', 'j3hYskXoN7', 'cZ3sFSCSWD', 'dWiszAQM0N', 'fVvYaXfKv2', 'vHoY67CsLQ', 'bJUYpsnYeQ', 'myBYSA3ldu', 'C8fY0C9D0Y' |
Source: 0.2.hesaphareketi__20241001.exe.4b5a1f0.0.raw.unpack, vZ1DdYpttd7fpYi8k2.cs |
High entropy of concatenated method names: 'gWgrPBkwy', 'XPlUwRVLq', 'AtbITuMj9', 'imvot8Ti7', 'KhfTwQMyI', 'EC0DIYwt1', 'q3TdwSbKKiiS2sSNZ9', 'HR3QW94b2cVrXsghQt', 'wfZiEGYkZ', 'WI3nC8aZQ' |
Source: 0.2.hesaphareketi__20241001.exe.4b5a1f0.0.raw.unpack, qZS5oaThbN4WJevrBN.cs |
High entropy of concatenated method names: 'PsKuUGcJGs', 'Tm7uI8PeTJ', 'Nhiublk2KA', 'kavuT2wbD1', 'neiu9bcYjN', 'JOIuchXU8h', 'KH9uhYyRDK', 'J6IuisQo9a', 'm8cuNJHmfC', 'iBpunZxOEY' |
Source: 0.2.hesaphareketi__20241001.exe.4b5a1f0.0.raw.unpack, pMceRfjydasvB3AEin.cs |
High entropy of concatenated method names: 'EDvSKvsv6N', 'BSYSypaGai', 'Od4S8VDUgi', 'b9RSujQt9T', 'fOmSAf4kJ1', 'VvPSsiVrfU', 'rjKSY1qNgU', 'IPbSjg1ys3', 'DR8SCoH2v3', 'tQ6SVwo9ep' |
Source: 0.2.hesaphareketi__20241001.exe.4b5a1f0.0.raw.unpack, aVOQLr86BIZOs4JD1e.cs |
High entropy of concatenated method names: 'Dispose', 'xEo6RcE1hn', 'ofjptkc40Y', 'DicFF3wBv9', 'k4c6FccKvO', 'CqN6zEDDbf', 'ProcessDialogKey', 'cOCpaXcL7h', 'gMPp6uGRUd', 'NfjppYxtK5' |
Source: 0.2.hesaphareketi__20241001.exe.4b5a1f0.0.raw.unpack, DeAfCSDBU9yLGhUV22.cs |
High entropy of concatenated method names: 'FRDAmdgBCW', 'kdTAojAMPe', 'v7QuHgLoUd', 'C8iu2RpDhy', 'FFyuQTx5tY', 'NgBuZMrGn3', 'Ldku1QceXT', 'CIyuJXm5W6', 'bIqugSbYYW', 'DIiufs1CYU' |
Source: 0.2.hesaphareketi__20241001.exe.4b5a1f0.0.raw.unpack, jSRXYtvBwkQC7BKMXG.cs |
High entropy of concatenated method names: 'R5RsKuZgC9', 'bR2s8QGSBd', 'SRHsAwEpve', 'mNjsYSbm6s', 'QVWsjNGdRa', 'E2lAxfvA58', 'St7AwCF7fc', 'kiMAGTANPx', 'uejAB378SJ', 'no6AReu0IU' |
Source: 0.2.hesaphareketi__20241001.exe.4b5a1f0.0.raw.unpack, M3Tk9D7EuWvvcB5aAS.cs |
High entropy of concatenated method names: 'ToString', 'ALrcdGVykS', 'Qt2ctf4S0O', 'KnLcHGU4XW', 'Ph2c2iagvq', 'xX7cQjluuu', 'V6bcZVZ0yt', 'bBuc1pXpqj', 'yQQcJiR1O2', 'P6xcgAsq09' |
Source: 0.2.hesaphareketi__20241001.exe.4b5a1f0.0.raw.unpack, NOSfVqqeoph6EVZH5u.cs |
High entropy of concatenated method names: 'vOlhVP8XEc', 'NFJhlOywTT', 'ToString', 'ctjhyQNq4q', 'SJyh8NMT3M', 'mkyhuF1B7I', 'HZohAaLoZa', 'zIChsRum2K', 'dZihYAaoPS', 'omuhjwkY6F' |
Source: 0.2.hesaphareketi__20241001.exe.4ade3d0.4.raw.unpack, oM3yqP0pdOqJtt0hwo.cs |
High entropy of concatenated method names: 'Gdv6YxasrE', 'bbt6jbl4Zl', 'ahb6VN4WJe', 'GrB6lNbeAf', 'qUV6922YSR', 'wYt6cBwkQC', 'gamWHa5xZQiT4hOarQ', 'okWpYddVd96LG4v2S1', 'iaW9tS6kBOO8bOXSOd', 'IsE66JAq8f' |
Source: 0.2.hesaphareketi__20241001.exe.4ade3d0.4.raw.unpack, jxtK5RFj1Y2g2eJ6Jh.cs |
High entropy of concatenated method names: 'IO6N618GSK', 'C0ZNS3cnN5', 'IIMN08VWhk', 'VeJNybVTRi', 'Tb0N8YFRUg', 'BTbNAv1Tbe', 'TsONsK3l3g', 'ywxiGAoq1y', 'pu1iBtwN9s', 'spjiRLZvqZ' |
Source: 0.2.hesaphareketi__20241001.exe.4ade3d0.4.raw.unpack, xxMJ9R6aIbQ1FxVAIOn.cs |
High entropy of concatenated method names: 'C27Ne3d7Ve', 'w91NMaPoBf', 'pFmNrjkkN7', 'xL3NUMi86Q', 'oyQNm1Uf3g', 'k7yNIn1ciE', 'mnPNoRCClQ', 'XKJNbTX1pZ', 'BbWNTi85cE', 'EbtNDahjaI' |
Source: 0.2.hesaphareketi__20241001.exe.4ade3d0.4.raw.unpack, yvnqjZuT3Mj4EaRnjM.cs |
High entropy of concatenated method names: 'EditValue', 'GetEditStyle', 'F4HpR82jn4', 'zJcpFsKgvf', 'M59pz0KFTX', 'wWOSaMMrwK', 'jTsS6cIxdH', 'SQ1Sp5fZgu', 'endSSjp6XL', 'tiDy9xyeQbAnAum0njx' |
Source: 0.2.hesaphareketi__20241001.exe.4ade3d0.4.raw.unpack, rQMVFf4JGsgCQU071W.cs |
High entropy of concatenated method names: 'v8WEbTYsD3', 'cxOETM3Kke', 'VbMEvOWJPQ', 'vWeEtidKZC', 'vV5E27yd4A', 'FimEQW2XG8', 'F76E1s2xpM', 'A6JEJx1YqO', 'NxAEfHrmE4', 'zRIEdDmtvY' |
Source: 0.2.hesaphareketi__20241001.exe.4ade3d0.4.raw.unpack, j2A3akwxX8ZEUCuPhW.cs |
High entropy of concatenated method names: 'AvLhB5oiZ5', 'NbchFoshMe', 'peiiacQI6a', 'domi6oqhlp', 'PmlhdYJwnQ', 'HQLhLvjj3y', 'su1h4c8BAU', 'xEEh3sBWI4', 'j5phOaqt2i', 'LbQh7FMMcl' |
Source: 0.2.hesaphareketi__20241001.exe.4ade3d0.4.raw.unpack, lXcL7hR8MPuGRUdffj.cs |
High entropy of concatenated method names: 's9BivdlkwL', 'GgRitCkbmb', 'XZOiHqBnXQ', 'RXyi2Ey2MV', 'LA6i3Yh0uU', 'lqJiQq0qX8', 'Next', 'Next', 'Next', 'NextBytes' |
Source: 0.2.hesaphareketi__20241001.exe.4ade3d0.4.raw.unpack, yrtDJ8zlG303A4dPlO.cs |
High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'ALVNEC8gOQ', 'XRwN9Z43Yw', 'NmUNc9563O', 'y2nNhORViA', 'CH4NiPScgb', 'YeLNNWbrY5', 'Fc1NnonUSd' |
Source: 0.2.hesaphareketi__20241001.exe.4ade3d0.4.raw.unpack, GxasrEb6btbl4ZlyPy.cs |
High entropy of concatenated method names: 'EuP83RttDC', 'MKI8OaIgR1', 'f9387Z1ELR', 'GQe8qlEtGP', 'Wew8xtix22', 'CWn8wlsGcM', 'sD28GtnWVw', 'o5l8BXCGhr', 'daJ8R0VtlF', 'dxa8FXgBo6' |
Source: 0.2.hesaphareketi__20241001.exe.4ade3d0.4.raw.unpack, QcccKvBOIqNEDDbfSO.cs |
High entropy of concatenated method names: 'CB1iydUHER', 'z1yi8qtpG4', 'PpCiuGPYUX', 'DTriACk9Fs', 'YLFisWLROX', 'EbKiY0F5uY', 'KlSijg1RtP', 'HupiC7LRfb', 'IIQiV8JTIg', 'HWPilGcqGd' |
Source: 0.2.hesaphareketi__20241001.exe.4ade3d0.4.raw.unpack, kMIvxVgMnZ8X3ijAoI.cs |
High entropy of concatenated method names: 'UW2YeUJBcb', 'VVAYMCNJqi', 'M6HYrjydNa', 'FWNYU1iLD4', 'yWAYmU0HDU', 'WwmYIFfr3w', 'GNcYocupWU', 'y7QYbpj7J6', 'BUqYT8JqmW', 'CBsYDZVKcB' |
Source: 0.2.hesaphareketi__20241001.exe.4ade3d0.4.raw.unpack, xCkofu1qgWKeqdhGVy.cs |
High entropy of concatenated method names: 'FYoYy9Lj8n', 'o5dYuNKuhd', 'j3hYskXoN7', 'cZ3sFSCSWD', 'dWiszAQM0N', 'fVvYaXfKv2', 'vHoY67CsLQ', 'bJUYpsnYeQ', 'myBYSA3ldu', 'C8fY0C9D0Y' |
Source: 0.2.hesaphareketi__20241001.exe.4ade3d0.4.raw.unpack, vZ1DdYpttd7fpYi8k2.cs |
High entropy of concatenated method names: 'gWgrPBkwy', 'XPlUwRVLq', 'AtbITuMj9', 'imvot8Ti7', 'KhfTwQMyI', 'EC0DIYwt1', 'q3TdwSbKKiiS2sSNZ9', 'HR3QW94b2cVrXsghQt', 'wfZiEGYkZ', 'WI3nC8aZQ' |
Source: 0.2.hesaphareketi__20241001.exe.4ade3d0.4.raw.unpack, qZS5oaThbN4WJevrBN.cs |
High entropy of concatenated method names: 'PsKuUGcJGs', 'Tm7uI8PeTJ', 'Nhiublk2KA', 'kavuT2wbD1', 'neiu9bcYjN', 'JOIuchXU8h', 'KH9uhYyRDK', 'J6IuisQo9a', 'm8cuNJHmfC', 'iBpunZxOEY' |
Source: 0.2.hesaphareketi__20241001.exe.4ade3d0.4.raw.unpack, pMceRfjydasvB3AEin.cs |
High entropy of concatenated method names: 'EDvSKvsv6N', 'BSYSypaGai', 'Od4S8VDUgi', 'b9RSujQt9T', 'fOmSAf4kJ1', 'VvPSsiVrfU', 'rjKSY1qNgU', 'IPbSjg1ys3', 'DR8SCoH2v3', 'tQ6SVwo9ep' |
Source: 0.2.hesaphareketi__20241001.exe.4ade3d0.4.raw.unpack, aVOQLr86BIZOs4JD1e.cs |
High entropy of concatenated method names: 'Dispose', 'xEo6RcE1hn', 'ofjptkc40Y', 'DicFF3wBv9', 'k4c6FccKvO', 'CqN6zEDDbf', 'ProcessDialogKey', 'cOCpaXcL7h', 'gMPp6uGRUd', 'NfjppYxtK5' |
Source: 0.2.hesaphareketi__20241001.exe.4ade3d0.4.raw.unpack, DeAfCSDBU9yLGhUV22.cs |
High entropy of concatenated method names: 'FRDAmdgBCW', 'kdTAojAMPe', 'v7QuHgLoUd', 'C8iu2RpDhy', 'FFyuQTx5tY', 'NgBuZMrGn3', 'Ldku1QceXT', 'CIyuJXm5W6', 'bIqugSbYYW', 'DIiufs1CYU' |
Source: 0.2.hesaphareketi__20241001.exe.4ade3d0.4.raw.unpack, jSRXYtvBwkQC7BKMXG.cs |
High entropy of concatenated method names: 'R5RsKuZgC9', 'bR2s8QGSBd', 'SRHsAwEpve', 'mNjsYSbm6s', 'QVWsjNGdRa', 'E2lAxfvA58', 'St7AwCF7fc', 'kiMAGTANPx', 'uejAB378SJ', 'no6AReu0IU' |
Source: 0.2.hesaphareketi__20241001.exe.4ade3d0.4.raw.unpack, M3Tk9D7EuWvvcB5aAS.cs |
High entropy of concatenated method names: 'ToString', 'ALrcdGVykS', 'Qt2ctf4S0O', 'KnLcHGU4XW', 'Ph2c2iagvq', 'xX7cQjluuu', 'V6bcZVZ0yt', 'bBuc1pXpqj', 'yQQcJiR1O2', 'P6xcgAsq09' |
Source: 0.2.hesaphareketi__20241001.exe.4ade3d0.4.raw.unpack, NOSfVqqeoph6EVZH5u.cs |
High entropy of concatenated method names: 'vOlhVP8XEc', 'NFJhlOywTT', 'ToString', 'ctjhyQNq4q', 'SJyh8NMT3M', 'mkyhuF1B7I', 'HZohAaLoZa', 'zIChsRum2K', 'dZihYAaoPS', 'omuhjwkY6F' |
Source: 0.2.hesaphareketi__20241001.exe.a710000.6.raw.unpack, oM3yqP0pdOqJtt0hwo.cs |
High entropy of concatenated method names: 'Gdv6YxasrE', 'bbt6jbl4Zl', 'ahb6VN4WJe', 'GrB6lNbeAf', 'qUV6922YSR', 'wYt6cBwkQC', 'gamWHa5xZQiT4hOarQ', 'okWpYddVd96LG4v2S1', 'iaW9tS6kBOO8bOXSOd', 'IsE66JAq8f' |
Source: 0.2.hesaphareketi__20241001.exe.a710000.6.raw.unpack, jxtK5RFj1Y2g2eJ6Jh.cs |
High entropy of concatenated method names: 'IO6N618GSK', 'C0ZNS3cnN5', 'IIMN08VWhk', 'VeJNybVTRi', 'Tb0N8YFRUg', 'BTbNAv1Tbe', 'TsONsK3l3g', 'ywxiGAoq1y', 'pu1iBtwN9s', 'spjiRLZvqZ' |
Source: 0.2.hesaphareketi__20241001.exe.a710000.6.raw.unpack, xxMJ9R6aIbQ1FxVAIOn.cs |
High entropy of concatenated method names: 'C27Ne3d7Ve', 'w91NMaPoBf', 'pFmNrjkkN7', 'xL3NUMi86Q', 'oyQNm1Uf3g', 'k7yNIn1ciE', 'mnPNoRCClQ', 'XKJNbTX1pZ', 'BbWNTi85cE', 'EbtNDahjaI' |
Source: 0.2.hesaphareketi__20241001.exe.a710000.6.raw.unpack, yvnqjZuT3Mj4EaRnjM.cs |
High entropy of concatenated method names: 'EditValue', 'GetEditStyle', 'F4HpR82jn4', 'zJcpFsKgvf', 'M59pz0KFTX', 'wWOSaMMrwK', 'jTsS6cIxdH', 'SQ1Sp5fZgu', 'endSSjp6XL', 'tiDy9xyeQbAnAum0njx' |
Source: 0.2.hesaphareketi__20241001.exe.a710000.6.raw.unpack, rQMVFf4JGsgCQU071W.cs |
High entropy of concatenated method names: 'v8WEbTYsD3', 'cxOETM3Kke', 'VbMEvOWJPQ', 'vWeEtidKZC', 'vV5E27yd4A', 'FimEQW2XG8', 'F76E1s2xpM', 'A6JEJx1YqO', 'NxAEfHrmE4', 'zRIEdDmtvY' |
Source: 0.2.hesaphareketi__20241001.exe.a710000.6.raw.unpack, j2A3akwxX8ZEUCuPhW.cs |
High entropy of concatenated method names: 'AvLhB5oiZ5', 'NbchFoshMe', 'peiiacQI6a', 'domi6oqhlp', 'PmlhdYJwnQ', 'HQLhLvjj3y', 'su1h4c8BAU', 'xEEh3sBWI4', 'j5phOaqt2i', 'LbQh7FMMcl' |
Source: 0.2.hesaphareketi__20241001.exe.a710000.6.raw.unpack, lXcL7hR8MPuGRUdffj.cs |
High entropy of concatenated method names: 's9BivdlkwL', 'GgRitCkbmb', 'XZOiHqBnXQ', 'RXyi2Ey2MV', 'LA6i3Yh0uU', 'lqJiQq0qX8', 'Next', 'Next', 'Next', 'NextBytes' |
Source: 0.2.hesaphareketi__20241001.exe.a710000.6.raw.unpack, yrtDJ8zlG303A4dPlO.cs |
High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'ALVNEC8gOQ', 'XRwN9Z43Yw', 'NmUNc9563O', 'y2nNhORViA', 'CH4NiPScgb', 'YeLNNWbrY5', 'Fc1NnonUSd' |
Source: 0.2.hesaphareketi__20241001.exe.a710000.6.raw.unpack, GxasrEb6btbl4ZlyPy.cs |
High entropy of concatenated method names: 'EuP83RttDC', 'MKI8OaIgR1', 'f9387Z1ELR', 'GQe8qlEtGP', 'Wew8xtix22', 'CWn8wlsGcM', 'sD28GtnWVw', 'o5l8BXCGhr', 'daJ8R0VtlF', 'dxa8FXgBo6' |
Source: 0.2.hesaphareketi__20241001.exe.a710000.6.raw.unpack, QcccKvBOIqNEDDbfSO.cs |
High entropy of concatenated method names: 'CB1iydUHER', 'z1yi8qtpG4', 'PpCiuGPYUX', 'DTriACk9Fs', 'YLFisWLROX', 'EbKiY0F5uY', 'KlSijg1RtP', 'HupiC7LRfb', 'IIQiV8JTIg', 'HWPilGcqGd' |
Source: 0.2.hesaphareketi__20241001.exe.a710000.6.raw.unpack, kMIvxVgMnZ8X3ijAoI.cs |
High entropy of concatenated method names: 'UW2YeUJBcb', 'VVAYMCNJqi', 'M6HYrjydNa', 'FWNYU1iLD4', 'yWAYmU0HDU', 'WwmYIFfr3w', 'GNcYocupWU', 'y7QYbpj7J6', 'BUqYT8JqmW', 'CBsYDZVKcB' |
Source: 0.2.hesaphareketi__20241001.exe.a710000.6.raw.unpack, xCkofu1qgWKeqdhGVy.cs |
High entropy of concatenated method names: 'FYoYy9Lj8n', 'o5dYuNKuhd', 'j3hYskXoN7', 'cZ3sFSCSWD', 'dWiszAQM0N', 'fVvYaXfKv2', 'vHoY67CsLQ', 'bJUYpsnYeQ', 'myBYSA3ldu', 'C8fY0C9D0Y' |
Source: 0.2.hesaphareketi__20241001.exe.a710000.6.raw.unpack, vZ1DdYpttd7fpYi8k2.cs |
High entropy of concatenated method names: 'gWgrPBkwy', 'XPlUwRVLq', 'AtbITuMj9', 'imvot8Ti7', 'KhfTwQMyI', 'EC0DIYwt1', 'q3TdwSbKKiiS2sSNZ9', 'HR3QW94b2cVrXsghQt', 'wfZiEGYkZ', 'WI3nC8aZQ' |
Source: 0.2.hesaphareketi__20241001.exe.a710000.6.raw.unpack, qZS5oaThbN4WJevrBN.cs |
High entropy of concatenated method names: 'PsKuUGcJGs', 'Tm7uI8PeTJ', 'Nhiublk2KA', 'kavuT2wbD1', 'neiu9bcYjN', 'JOIuchXU8h', 'KH9uhYyRDK', 'J6IuisQo9a', 'm8cuNJHmfC', 'iBpunZxOEY' |
Source: 0.2.hesaphareketi__20241001.exe.a710000.6.raw.unpack, pMceRfjydasvB3AEin.cs |
High entropy of concatenated method names: 'EDvSKvsv6N', 'BSYSypaGai', 'Od4S8VDUgi', 'b9RSujQt9T', 'fOmSAf4kJ1', 'VvPSsiVrfU', 'rjKSY1qNgU', 'IPbSjg1ys3', 'DR8SCoH2v3', 'tQ6SVwo9ep' |
Source: 0.2.hesaphareketi__20241001.exe.a710000.6.raw.unpack, aVOQLr86BIZOs4JD1e.cs |
High entropy of concatenated method names: 'Dispose', 'xEo6RcE1hn', 'ofjptkc40Y', 'DicFF3wBv9', 'k4c6FccKvO', 'CqN6zEDDbf', 'ProcessDialogKey', 'cOCpaXcL7h', 'gMPp6uGRUd', 'NfjppYxtK5' |
Source: 0.2.hesaphareketi__20241001.exe.a710000.6.raw.unpack, DeAfCSDBU9yLGhUV22.cs |
High entropy of concatenated method names: 'FRDAmdgBCW', 'kdTAojAMPe', 'v7QuHgLoUd', 'C8iu2RpDhy', 'FFyuQTx5tY', 'NgBuZMrGn3', 'Ldku1QceXT', 'CIyuJXm5W6', 'bIqugSbYYW', 'DIiufs1CYU' |
Source: 0.2.hesaphareketi__20241001.exe.a710000.6.raw.unpack, jSRXYtvBwkQC7BKMXG.cs |
High entropy of concatenated method names: 'R5RsKuZgC9', 'bR2s8QGSBd', 'SRHsAwEpve', 'mNjsYSbm6s', 'QVWsjNGdRa', 'E2lAxfvA58', 'St7AwCF7fc', 'kiMAGTANPx', 'uejAB378SJ', 'no6AReu0IU' |
Source: 0.2.hesaphareketi__20241001.exe.a710000.6.raw.unpack, M3Tk9D7EuWvvcB5aAS.cs |
High entropy of concatenated method names: 'ToString', 'ALrcdGVykS', 'Qt2ctf4S0O', 'KnLcHGU4XW', 'Ph2c2iagvq', 'xX7cQjluuu', 'V6bcZVZ0yt', 'bBuc1pXpqj', 'yQQcJiR1O2', 'P6xcgAsq09' |
Source: 0.2.hesaphareketi__20241001.exe.a710000.6.raw.unpack, NOSfVqqeoph6EVZH5u.cs |
High entropy of concatenated method names: 'vOlhVP8XEc', 'NFJhlOywTT', 'ToString', 'ctjhyQNq4q', 'SJyh8NMT3M', 'mkyhuF1B7I', 'HZohAaLoZa', 'zIChsRum2K', 'dZihYAaoPS', 'omuhjwkY6F' |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Thread delayed: delay time: 922337203685477 |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Thread delayed: delay time: 922337203685477 |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Thread delayed: delay time: 922337203685477 |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Thread delayed: delay time: 1200000 |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Thread delayed: delay time: 1199828 |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Thread delayed: delay time: 1199718 |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Thread delayed: delay time: 1199592 |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Thread delayed: delay time: 1199484 |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Thread delayed: delay time: 1199375 |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Thread delayed: delay time: 1199248 |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Thread delayed: delay time: 1199140 |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Thread delayed: delay time: 1199031 |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Thread delayed: delay time: 1198894 |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Thread delayed: delay time: 1198734 |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Thread delayed: delay time: 1198504 |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Thread delayed: delay time: 1198218 |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Thread delayed: delay time: 1198020 |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Thread delayed: delay time: 1197875 |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Thread delayed: delay time: 1197765 |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Thread delayed: delay time: 1197656 |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Thread delayed: delay time: 1197546 |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Thread delayed: delay time: 1197437 |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Thread delayed: delay time: 1197328 |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Thread delayed: delay time: 1197218 |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Thread delayed: delay time: 1197109 |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Thread delayed: delay time: 1197000 |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Thread delayed: delay time: 1196890 |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Thread delayed: delay time: 1196781 |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Thread delayed: delay time: 1196672 |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Thread delayed: delay time: 1196559 |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Thread delayed: delay time: 1196453 |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Thread delayed: delay time: 1196343 |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Thread delayed: delay time: 1196234 |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Thread delayed: delay time: 1196125 |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Thread delayed: delay time: 1196015 |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Thread delayed: delay time: 1195906 |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Thread delayed: delay time: 1195797 |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Thread delayed: delay time: 1195687 |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Thread delayed: delay time: 1195578 |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Thread delayed: delay time: 1195468 |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Thread delayed: delay time: 1195359 |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Thread delayed: delay time: 1195250 |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Thread delayed: delay time: 1195140 |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Thread delayed: delay time: 1195031 |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Thread delayed: delay time: 1194922 |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Thread delayed: delay time: 1194812 |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Thread delayed: delay time: 1194703 |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Thread delayed: delay time: 1194593 |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Thread delayed: delay time: 1194484 |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Thread delayed: delay time: 1194374 |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Thread delayed: delay time: 1194265 |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Thread delayed: delay time: 1194156 |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Thread delayed: delay time: 1194047 |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Thread delayed: delay time: 1193937 |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Thread delayed: delay time: 1193827 |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Thread delayed: delay time: 1193718 |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Thread delayed: delay time: 1193609 |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe TID: 5420 |
Thread sleep time: -922337203685477s >= -30000s |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe TID: 3304 |
Thread sleep time: -7378697629483816s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe TID: 2944 |
Thread sleep time: -35048813740048126s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe TID: 2944 |
Thread sleep time: -1200000s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe TID: 2944 |
Thread sleep time: -1199828s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe TID: 2944 |
Thread sleep time: -1199718s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe TID: 2944 |
Thread sleep time: -1199592s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe TID: 2944 |
Thread sleep time: -1199484s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe TID: 2944 |
Thread sleep time: -1199375s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe TID: 2944 |
Thread sleep time: -1199248s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe TID: 2944 |
Thread sleep time: -1199140s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe TID: 2944 |
Thread sleep time: -1199031s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe TID: 2944 |
Thread sleep time: -1198894s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe TID: 2944 |
Thread sleep time: -1198734s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe TID: 2944 |
Thread sleep time: -1198504s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe TID: 2944 |
Thread sleep time: -1198218s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe TID: 2944 |
Thread sleep time: -1198020s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe TID: 2944 |
Thread sleep time: -1197875s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe TID: 2944 |
Thread sleep time: -1197765s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe TID: 2944 |
Thread sleep time: -1197656s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe TID: 2944 |
Thread sleep time: -1197546s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe TID: 2944 |
Thread sleep time: -1197437s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe TID: 2944 |
Thread sleep time: -1197328s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe TID: 2944 |
Thread sleep time: -1197218s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe TID: 2944 |
Thread sleep time: -1197109s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe TID: 2944 |
Thread sleep time: -1197000s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe TID: 2944 |
Thread sleep time: -1196890s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe TID: 2944 |
Thread sleep time: -1196781s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe TID: 2944 |
Thread sleep time: -1196672s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe TID: 2944 |
Thread sleep time: -1196559s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe TID: 2944 |
Thread sleep time: -1196453s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe TID: 2944 |
Thread sleep time: -1196343s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe TID: 2944 |
Thread sleep time: -1196234s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe TID: 2944 |
Thread sleep time: -1196125s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe TID: 2944 |
Thread sleep time: -1196015s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe TID: 2944 |
Thread sleep time: -1195906s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe TID: 2944 |
Thread sleep time: -1195797s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe TID: 2944 |
Thread sleep time: -1195687s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe TID: 2944 |
Thread sleep time: -1195578s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe TID: 2944 |
Thread sleep time: -1195468s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe TID: 2944 |
Thread sleep time: -1195359s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe TID: 2944 |
Thread sleep time: -1195250s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe TID: 2944 |
Thread sleep time: -1195140s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe TID: 2944 |
Thread sleep time: -1195031s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe TID: 2944 |
Thread sleep time: -1194922s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe TID: 2944 |
Thread sleep time: -1194812s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe TID: 2944 |
Thread sleep time: -1194703s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe TID: 2944 |
Thread sleep time: -1194593s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe TID: 2944 |
Thread sleep time: -1194484s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe TID: 2944 |
Thread sleep time: -1194374s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe TID: 2944 |
Thread sleep time: -1194265s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe TID: 2944 |
Thread sleep time: -1194156s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe TID: 2944 |
Thread sleep time: -1194047s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe TID: 2944 |
Thread sleep time: -1193937s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe TID: 2944 |
Thread sleep time: -1193827s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe TID: 2944 |
Thread sleep time: -1193718s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe TID: 2944 |
Thread sleep time: -1193609s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Thread delayed: delay time: 922337203685477 |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Thread delayed: delay time: 922337203685477 |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Thread delayed: delay time: 922337203685477 |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Thread delayed: delay time: 1200000 |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Thread delayed: delay time: 1199828 |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Thread delayed: delay time: 1199718 |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Thread delayed: delay time: 1199592 |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Thread delayed: delay time: 1199484 |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Thread delayed: delay time: 1199375 |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Thread delayed: delay time: 1199248 |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Thread delayed: delay time: 1199140 |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Thread delayed: delay time: 1199031 |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Thread delayed: delay time: 1198894 |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Thread delayed: delay time: 1198734 |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Thread delayed: delay time: 1198504 |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Thread delayed: delay time: 1198218 |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Thread delayed: delay time: 1198020 |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Thread delayed: delay time: 1197875 |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Thread delayed: delay time: 1197765 |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Thread delayed: delay time: 1197656 |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Thread delayed: delay time: 1197546 |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Thread delayed: delay time: 1197437 |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Thread delayed: delay time: 1197328 |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Thread delayed: delay time: 1197218 |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Thread delayed: delay time: 1197109 |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Thread delayed: delay time: 1197000 |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Thread delayed: delay time: 1196890 |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Thread delayed: delay time: 1196781 |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Thread delayed: delay time: 1196672 |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Thread delayed: delay time: 1196559 |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Thread delayed: delay time: 1196453 |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Thread delayed: delay time: 1196343 |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Thread delayed: delay time: 1196234 |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Thread delayed: delay time: 1196125 |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Thread delayed: delay time: 1196015 |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Thread delayed: delay time: 1195906 |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Thread delayed: delay time: 1195797 |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Thread delayed: delay time: 1195687 |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Thread delayed: delay time: 1195578 |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Thread delayed: delay time: 1195468 |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Thread delayed: delay time: 1195359 |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Thread delayed: delay time: 1195250 |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Thread delayed: delay time: 1195140 |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Thread delayed: delay time: 1195031 |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Thread delayed: delay time: 1194922 |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Thread delayed: delay time: 1194812 |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Thread delayed: delay time: 1194703 |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Thread delayed: delay time: 1194593 |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Thread delayed: delay time: 1194484 |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Thread delayed: delay time: 1194374 |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Thread delayed: delay time: 1194265 |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Thread delayed: delay time: 1194156 |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Thread delayed: delay time: 1194047 |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Thread delayed: delay time: 1193937 |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Thread delayed: delay time: 1193827 |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Thread delayed: delay time: 1193718 |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Thread delayed: delay time: 1193609 |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Queries volume information: C:\Users\user\Desktop\hesaphareketi__20241001.exe VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Queries volume information: C:\Windows\Fonts\micross.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\ VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-GroupPolicy-ClientTools-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-AppManagement-AppV-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\Microsoft.Management.Infrastructure.Native\v4.0_1.0.0.0__31bf3856ad364e35\Microsoft.Management.Infrastructure.Native.dll VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\AppvClient\Microsoft.AppV.AppVClientPowerShell.dll VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1865.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-WOW64-Package~31bf3856ad364e35~amd64~en-GB~10.0.19041.1.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\BitLocker\Microsoft.BitLocker.Structures.dll VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management\v4.0_3.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Management.dll VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Queries volume information: C:\Users\user\Desktop\hesaphareketi__20241001.exe VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Security\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Security.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareketi__20241001.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation |
Jump to behavior |