Source: 0.2.PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe.41695f0.5.unpack |
String decryptor: Cookies |
Source: 0.2.PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe.41695f0.5.unpack |
String decryptor: \Default\Login Data |
Source: 0.2.PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe.41695f0.5.unpack |
String decryptor: \Login Data |
Source: 0.2.PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe.41695f0.5.unpack |
String decryptor: //setting[@name='Password']/value |
Source: 0.2.PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe.41695f0.5.unpack |
String decryptor: Password : |
Source: 0.2.PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe.41695f0.5.unpack |
String decryptor: Software\Martin Prikryl\WinSCP 2\Sessions |
Source: 0.2.PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe.41695f0.5.unpack |
String decryptor: Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676 |
Source: 0.2.PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe.41695f0.5.unpack |
String decryptor: Software\Microsoft\Windows Messaging Subsystem\Profiles\9375CFF0413111d3B88A00104B2A6676 |
Source: 0.2.PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe.41695f0.5.unpack |
String decryptor: SMTP Email Address |
Source: 0.2.PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe.41695f0.5.unpack |
String decryptor: NNTP Email Address |
Source: 0.2.PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe.41695f0.5.unpack |
String decryptor: Email |
Source: 0.2.PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe.41695f0.5.unpack |
String decryptor: HTTPMail User Name |
Source: 0.2.PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe.41695f0.5.unpack |
String decryptor: HTTPMail Server |
Source: 0.2.PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe.41695f0.5.unpack |
String decryptor: ^([a-zA-Z0-9_\-\.]+)@([a-zA-Z0-9_\-\.]+)\.([a-zA-Z]{2,5})$ |
Source: 0.2.PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe.41695f0.5.unpack |
String decryptor: Password |
Source: 0.2.PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe.41695f0.5.unpack |
String decryptor: ^(?!:\/\/)([a-zA-Z0-9-_]+\.)[a-zA-Z0-9][a-zA-Z0-9-_]+\.[a-zA-Z]{2,11}?$ |
Source: 0.2.PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe.41695f0.5.unpack |
String decryptor: ^3[47][0-9]{13}$ |
Source: 0.2.PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe.41695f0.5.unpack |
String decryptor: ^(6541|6556)[0-9]{12}$ |
Source: 0.2.PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe.41695f0.5.unpack |
String decryptor: ^389[0-9]{11}$ |
Source: 0.2.PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe.41695f0.5.unpack |
String decryptor: ^3(?:0[0-5]|[68][0-9])[0-9]{11}$ |
Source: 0.2.PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe.41695f0.5.unpack |
String decryptor: ^63[7-9][0-9]{13}$ |
Source: 0.2.PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe.41695f0.5.unpack |
String decryptor: ^(?:2131|1800|35\\d{3})\\d{11}$ |
Source: 0.2.PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe.41695f0.5.unpack |
String decryptor: ^9[0-9]{15}$ |
Source: 0.2.PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe.41695f0.5.unpack |
String decryptor: ^(6304|6706|6709|6771)[0-9]{12,15}$ |
Source: 0.2.PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe.41695f0.5.unpack |
String decryptor: ^(5018|5020|5038|6304|6759|6761|6763)[0-9]{8,15}$ |
Source: 0.2.PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe.41695f0.5.unpack |
String decryptor: Mastercard |
Source: 0.2.PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe.41695f0.5.unpack |
String decryptor: ^(6334|6767)[0-9]{12}|(6334|6767)[0-9]{14}|(6334|6767)[0-9]{15}$ |
Source: 0.2.PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe.41695f0.5.unpack |
String decryptor: ^(62[0-9]{14,17})$ |
Source: 0.2.PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe.41695f0.5.unpack |
String decryptor: ^(4903|4905|4911|4936|6333|6759)[0-9]{12}|(4903|4905|4911|4936|6333|6759)[0-9]{14}|(4903|4905|4911|4936|6333|6759)[0-9]{15}|564182[0-9]{10}|564182[0-9]{12}|564182[0-9]{13}|633110[0-9]{10}|633110[0-9]{12}|633110[0-9]{13}$ |
Source: 0.2.PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe.41695f0.5.unpack |
String decryptor: Visa Card |
Source: 0.2.PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe.41695f0.5.unpack |
String decryptor: ^(?:4[0-9]{12}(?:[0-9]{3})?|5[1-5][0-9]{14})$ |
Source: 0.2.PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe.41695f0.5.unpack |
String decryptor: Visa Master Card |
Source: 0.2.PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe.41695f0.5.unpack |
String decryptor: mail\ |
Source: 0.2.PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe.41695f0.5.unpack |
String decryptor: Foxmail.exe |
Source: 0.2.PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe.41695f0.5.unpack |
String decryptor: \Accounts\Account.rec0 |
Source: 0.2.PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe.41695f0.5.unpack |
String decryptor: \AccCfg\Accounts.tdat |
Source: 0.2.PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe.41695f0.5.unpack |
String decryptor: EnableSignature |
Source: 0.2.PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe.41695f0.5.unpack |
String decryptor: Application : FoxMail |
Source: 0.2.PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe.41695f0.5.unpack |
String decryptor: encryptedUsername |
Source: 0.2.PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe.41695f0.5.unpack |
String decryptor: logins |
Source: 0.2.PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe.41695f0.5.unpack |
String decryptor: encryptedPassword |
Source: 0.2.PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe.41695f0.5.unpack |
String decryptor: purchase01.qualitydevlopments@gmail.com |
Source: 0.2.PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe.41695f0.5.unpack |
String decryptor: http://schemas.microsoft.com/cdo/configuration/smtpserver |
Source: 0.2.PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe.41695f0.5.unpack |
String decryptor: http://schemas.microsoft.com/cdo/configuration/smtpserverport |
Source: 0.2.PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe.41695f0.5.unpack |
String decryptor: http://schemas.microsoft.com/cdo/configuration/smtpusessl |
Source: 0.2.PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe.41695f0.5.unpack |
String decryptor: http://schemas.microsoft.com/cdo/configuration/sendusername |
Source: 0.2.PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe.41695f0.5.unpack |
String decryptor: http://schemas.microsoft.com/cdo/configuration/sendpassword |
Source: PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe, FieldNames.exe.0.dr |
String found in binary or memory: http://127.0.0.1: |
Source: PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe, 00000000.00000002.2112093538.0000000003061000.00000004.00000800.00020000.00000000.sdmp, FieldNames.exe, 00000006.00000002.2288985162.0000000002E51000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name |
Source: InstallUtil.exe, 00000002.00000002.3305635075.0000000000A97000.00000004.00000020.00020000.00000000.sdmp, InstallUtil.exe, 00000007.00000002.3305781323.0000000000CC6000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://showip.net |
Source: InstallUtil.exe, 00000007.00000002.3305781323.0000000000CC6000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://showip.net# |
Source: InstallUtil.exe, 00000002.00000002.3305635075.0000000000AC1000.00000004.00000020.00020000.00000000.sdmp, InstallUtil.exe, 00000002.00000002.3305635075.0000000000A97000.00000004.00000020.00020000.00000000.sdmp, InstallUtil.exe, 00000007.00000002.3305781323.0000000000CC6000.00000004.00000020.00020000.00000000.sdmp, InstallUtil.exe, 00000007.00000002.3305781323.0000000000C78000.00000004.00000020.00020000.00000000.sdmp, InstallUtil.exe, 00000007.00000002.3305781323.0000000000CDC000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://showip.net/ |
Source: InstallUtil.exe, 00000007.00000002.3306652645.0000000000D0F000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://showip.net/#( |
Source: InstallUtil.exe, 00000002.00000002.3306426620.0000000000AD8000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://showip.net/%Y |
Source: InstallUtil.exe, 00000002.00000002.3305635075.0000000000AC1000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://showip.net/; |
Source: InstallUtil.exe, 00000002.00000002.3305635075.0000000000A97000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://showip.net/X |
Source: InstallUtil.exe, 00000007.00000002.3305781323.0000000000CDC000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://showip.net/dF |
Source: InstallUtil.exe, 00000007.00000002.3305781323.0000000000CC6000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://showip.net/h |
Source: InstallUtil.exe, 00000002.00000002.3305635075.0000000000A97000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://showip.netF |
Source: InstallUtil.exe, 00000007.00000002.3305781323.0000000000CDC000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://showip.neta |
Source: InstallUtil.exe, 00000002.00000002.3305635075.0000000000A97000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://showip.netth |
Source: PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe, 00000000.00000002.2112093538.0000000003061000.00000004.00000800.00020000.00000000.sdmp, FieldNames.exe, 00000006.00000002.2288985162.0000000002E51000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://erkasera.com |
Source: PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe, 00000000.00000002.2112093538.0000000003061000.00000004.00000800.00020000.00000000.sdmp, FieldNames.exe, 00000006.00000002.2288985162.0000000002E51000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://erkasera.com/ruurew/Cwfuvfaf.wav |
Source: PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe, FieldNames.exe.0.dr |
String found in binary or memory: https://erkasera.com/ruurew/Cwfuvfaf.wav1B4MrP3veGRoRMM0tnPgU/Q== |
Source: InstallUtil.exe, 00000007.00000002.3306909563.0000000000D47000.00000004.00000020.00020000.00000000.sdmp, InstallUtil.exe, 00000007.00000002.3307042263.0000000000D5D000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://fundingchoicesmessages.google.com/i/pub-8790158038613050?ers=1 |
Source: PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe, 00000000.00000002.2123399550.0000000006CB0000.00000004.08000000.00040000.00000000.sdmp, PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe, 00000000.00000002.2118042555.00000000047E9000.00000004.00000800.00020000.00000000.sdmp, PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe, 00000000.00000002.2118042555.00000000045DF000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://github.com/mgravell/protobuf-net |
Source: PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe, 00000000.00000002.2123399550.0000000006CB0000.00000004.08000000.00040000.00000000.sdmp, PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe, 00000000.00000002.2118042555.00000000047E9000.00000004.00000800.00020000.00000000.sdmp, PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe, 00000000.00000002.2118042555.00000000045DF000.00000004.00000800.00020000.00000000.sdmp, FieldNames.exe, 00000006.00000002.2306805654.000000000461F000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://github.com/mgravell/protobuf-netJ |
Source: PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe, 00000000.00000002.2123399550.0000000006CB0000.00000004.08000000.00040000.00000000.sdmp, PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe, 00000000.00000002.2118042555.00000000047E9000.00000004.00000800.00020000.00000000.sdmp, PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe, 00000000.00000002.2118042555.00000000045DF000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://github.com/mgravell/protobuf-neti |
Source: PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe, 00000000.00000002.2123399550.0000000006CB0000.00000004.08000000.00040000.00000000.sdmp, PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe, 00000000.00000002.2118042555.00000000047E9000.00000004.00000800.00020000.00000000.sdmp, PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe, 00000000.00000002.2118042555.00000000045DF000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://stackoverflow.com/q/11564914/23354; |
Source: PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe, 00000000.00000002.2123399550.0000000006CB0000.00000004.08000000.00040000.00000000.sdmp, PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe, 00000000.00000002.2112093538.00000000030AC000.00000004.00000800.00020000.00000000.sdmp, PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe, 00000000.00000002.2118042555.00000000047E9000.00000004.00000800.00020000.00000000.sdmp, PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe, 00000000.00000002.2118042555.00000000045DF000.00000004.00000800.00020000.00000000.sdmp, FieldNames.exe, 00000006.00000002.2288985162.0000000002E9C000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://stackoverflow.com/q/14436606/23354 |
Source: PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe, 00000000.00000002.2123399550.0000000006CB0000.00000004.08000000.00040000.00000000.sdmp, PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe, 00000000.00000002.2118042555.00000000047E9000.00000004.00000800.00020000.00000000.sdmp, PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe, 00000000.00000002.2118042555.00000000045DF000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://stackoverflow.com/q/2152978/23354 |
Source: InstallUtil.exe, 00000002.00000002.3308084634.0000000003660000.00000004.00000020.00020000.00000000.sdmp, InstallUtil.exe, 00000002.00000002.3305635075.0000000000A97000.00000004.00000020.00020000.00000000.sdmp, InstallUtil.exe, 00000002.00000002.3306426620.0000000000AE4000.00000004.00000020.00020000.00000000.sdmp, InstallUtil.exe, 00000007.00000002.3305781323.0000000000CC6000.00000004.00000020.00020000.00000000.sdmp, InstallUtil.exe, 00000007.00000002.3306652645.0000000000D17000.00000004.00000020.00020000.00000000.sdmp, InstallUtil.exe, 00000007.00000002.3308180421.00000000038D0000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://www.googletagmanager.com/gtag/js?id=G-L6NKT5G6D7 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
WMI Queries: IWbemServices::ExecMethod - root\default : StdRegProv::enumvalues |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
WMI Queries: IWbemServices::ExecMethod - root\default : StdRegProv::getstringvalue |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
WMI Queries: IWbemServices::ExecMethod - root\default : StdRegProv::EnumKey |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
WMI Queries: IWbemServices::ExecMethod - root\default : StdRegProv::enumvalues |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
WMI Queries: IWbemServices::ExecMethod - root\default : StdRegProv::getstringvalue |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
WMI Queries: IWbemServices::ExecMethod - root\default : StdRegProv::EnumKey |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
WMI Queries: IWbemServices::ExecMethod - root\default : StdRegProv::enumvalues |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
WMI Queries: IWbemServices::ExecMethod - root\default : StdRegProv::getstringvalue |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
WMI Queries: IWbemServices::ExecMethod - root\default : StdRegProv::EnumKey |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
WMI Queries: IWbemServices::ExecMethod - root\default : StdRegProv::enumvalues |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
WMI Queries: IWbemServices::ExecMethod - root\default : StdRegProv::getstringvalue |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
WMI Queries: IWbemServices::ExecMethod - root\default : StdRegProv::EnumKey |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
WMI Queries: IWbemServices::ExecMethod - root\default : StdRegProv::enumvalues |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
WMI Queries: IWbemServices::ExecMethod - root\default : StdRegProv::getstringvalue |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
WMI Queries: IWbemServices::ExecMethod - root\default : StdRegProv::EnumKey |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
WMI Queries: IWbemServices::ExecMethod - root\default : StdRegProv::enumvalues |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
WMI Queries: IWbemServices::ExecMethod - root\default : StdRegProv::getstringvalue |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
WMI Queries: IWbemServices::ExecMethod - root\default : StdRegProv::EnumKey |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
WMI Queries: IWbemServices::ExecMethod - root\default : StdRegProv::enumvalues |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
WMI Queries: IWbemServices::ExecMethod - root\default : StdRegProv::getstringvalue |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
WMI Queries: IWbemServices::ExecMethod - root\default : StdRegProv::EnumKey |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
WMI Queries: IWbemServices::ExecMethod - root\default : StdRegProv::enumvalues |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
WMI Queries: IWbemServices::ExecMethod - root\default : StdRegProv::getstringvalue |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
WMI Queries: IWbemServices::ExecMethod - root\default : StdRegProv::EnumKey |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
WMI Queries: IWbemServices::ExecMethod - root\default : StdRegProv::enumvalues |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
WMI Queries: IWbemServices::ExecMethod - root\default : StdRegProv::getstringvalue |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
WMI Queries: IWbemServices::ExecMethod - root\default : StdRegProv::EnumKey |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
WMI Queries: IWbemServices::ExecMethod - root\default : StdRegProv::enumvalues |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
WMI Queries: IWbemServices::ExecMethod - root\default : StdRegProv::getstringvalue |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
WMI Queries: IWbemServices::ExecMethod - root\default : StdRegProv::EnumKey |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
WMI Queries: IWbemServices::ExecMethod - root\default : StdRegProv::enumvalues |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
WMI Queries: IWbemServices::ExecMethod - root\default : StdRegProv::getstringvalue |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
WMI Queries: IWbemServices::ExecMethod - root\default : StdRegProv::EnumKey |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
WMI Queries: IWbemServices::ExecMethod - root\default : StdRegProv::enumvalues |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
WMI Queries: IWbemServices::ExecMethod - root\default : StdRegProv::getstringvalue |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
WMI Queries: IWbemServices::ExecMethod - root\default : StdRegProv::EnumKey |
Source: PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe, 00000000.00000002.2123399550.0000000006CB0000.00000004.08000000.00040000.00000000.sdmp |
Binary or memory string: OriginalFilenameprotobuf-net.dllJ vs PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Source: PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe, 00000000.00000002.2112093538.00000000030AC000.00000004.00000800.00020000.00000000.sdmp |
Binary or memory string: OriginalFilename vs PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Source: PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe, 00000000.00000000.2054917962.0000000000C78000.00000002.00000001.01000000.00000003.sdmp |
Binary or memory string: OriginalFilenameNsrnqjr.exe0 vs PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Source: PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe, 00000000.00000002.2112093538.000000000342B000.00000004.00000800.00020000.00000000.sdmp |
Binary or memory string: OriginalFilenameMicrosoft.Win32.TaskScheduler.dll\ vs PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Source: PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe, 00000000.00000002.2112093538.000000000342B000.00000004.00000800.00020000.00000000.sdmp |
Binary or memory string: OriginalFilenameNsrnqjr.exe0 vs PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Source: PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe, 00000000.00000002.2118042555.000000000412F000.00000004.00000800.00020000.00000000.sdmp |
Binary or memory string: OriginalFilenamebolewort.exe vs PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Source: PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe, 00000000.00000002.2118042555.0000000004227000.00000004.00000800.00020000.00000000.sdmp |
Binary or memory string: OriginalFilenamebolewort.exe vs PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Source: PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe, 00000000.00000002.2118042555.0000000004227000.00000004.00000800.00020000.00000000.sdmp |
Binary or memory string: OriginalFilenameLwmonhiauc.dll" vs PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Source: PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe, 00000000.00000002.2118042555.0000000004068000.00000004.00000800.00020000.00000000.sdmp |
Binary or memory string: OriginalFilenameMicrosoft.Win32.TaskScheduler.dll\ vs PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Source: PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe, 00000000.00000002.2118042555.00000000047E9000.00000004.00000800.00020000.00000000.sdmp |
Binary or memory string: OriginalFilenameprotobuf-net.dllJ vs PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Source: PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe, 00000000.00000002.2118042555.00000000047E9000.00000004.00000800.00020000.00000000.sdmp |
Binary or memory string: OriginalFilenameMicrosoft.Win32.TaskScheduler.dll\ vs PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Source: PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe, 00000000.00000002.2124472344.0000000006FD0000.00000004.08000000.00040000.00000000.sdmp |
Binary or memory string: OriginalFilenameMicrosoft.Win32.TaskScheduler.dll\ vs PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Source: PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe, 00000000.00000002.2118042555.00000000045DF000.00000004.00000800.00020000.00000000.sdmp |
Binary or memory string: OriginalFilenameprotobuf-net.dllJ vs PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Source: PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe, 00000000.00000002.2111378125.000000000116E000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: OriginalFilenameclr.dllT vs PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Source: PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe, 00000000.00000002.2122259348.00000000069C0000.00000004.08000000.00040000.00000000.sdmp |
Binary or memory string: OriginalFilenameLwmonhiauc.dll" vs PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Source: PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Binary or memory string: OriginalFilenameNsrnqjr.exe0 vs PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Section loaded: mscoree.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Section loaded: vcruntime140_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Section loaded: cryptsp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Section loaded: rsaenh.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Section loaded: cryptbase.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Section loaded: iphlpapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Section loaded: dnsapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Section loaded: dhcpcsvc6.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Section loaded: dhcpcsvc.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Section loaded: winnsi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Section loaded: rasapi32.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Section loaded: rasman.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Section loaded: rtutils.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Section loaded: mswsock.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Section loaded: winhttp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Section loaded: ondemandconnroutehelper.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Section loaded: rasadhlp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Section loaded: fwpuclnt.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Section loaded: secur32.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Section loaded: schannel.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Section loaded: mskeyprotect.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Section loaded: ntasn1.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Section loaded: ncrypt.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Section loaded: ncryptsslp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Section loaded: msasn1.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Section loaded: gpapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Section loaded: amsi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Section loaded: ntmarta.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Section loaded: msvbvm60.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Section loaded: vb6zz.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Section loaded: sxs.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Section loaded: scrrun.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Section loaded: ntmarta.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Section loaded: winsqlite3.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Section loaded: vbscript.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Section loaded: wbemcomn.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Section loaded: amsi.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Section loaded: mpr.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Section loaded: wininet.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Section loaded: iertutil.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Section loaded: ondemandconnroutehelper.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Section loaded: winhttp.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Section loaded: iphlpapi.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Section loaded: mswsock.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Section loaded: winnsi.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Section loaded: urlmon.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Section loaded: srvcli.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Section loaded: netutils.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Section loaded: dnsapi.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Section loaded: rasadhlp.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Section loaded: fwpuclnt.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: sxs.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: vbscript.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: amsi.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: msasn1.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: cryptsp.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: rsaenh.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: cryptbase.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: msisip.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: wshext.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: scrobj.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: mpr.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: scrrun.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: propsys.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: edputil.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: urlmon.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: iertutil.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: srvcli.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: netutils.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: windows.staterepositoryps.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: appresolver.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: bcp47langs.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: slc.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: sppc.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: onecorecommonproxystub.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: onecoreuapcommonproxystub.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Section loaded: mscoree.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Section loaded: vcruntime140_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Section loaded: cryptsp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Section loaded: rsaenh.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Section loaded: cryptbase.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Section loaded: iphlpapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Section loaded: dnsapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Section loaded: dhcpcsvc6.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Section loaded: dhcpcsvc.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Section loaded: winnsi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Section loaded: rasapi32.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Section loaded: rasman.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Section loaded: rtutils.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Section loaded: mswsock.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Section loaded: winhttp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Section loaded: ondemandconnroutehelper.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Section loaded: rasadhlp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Section loaded: fwpuclnt.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Section loaded: secur32.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Section loaded: schannel.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Section loaded: mskeyprotect.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Section loaded: ntasn1.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Section loaded: ncrypt.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Section loaded: ncryptsslp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Section loaded: msasn1.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Section loaded: gpapi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Section loaded: amsi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Section loaded: msvbvm60.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Section loaded: vb6zz.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Section loaded: sxs.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Section loaded: scrrun.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Section loaded: ntmarta.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Section loaded: winsqlite3.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Section loaded: vbscript.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Section loaded: wbemcomn.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Section loaded: amsi.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Section loaded: mpr.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Section loaded: wininet.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Section loaded: iertutil.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Section loaded: ondemandconnroutehelper.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Section loaded: winhttp.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Section loaded: iphlpapi.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Section loaded: mswsock.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Section loaded: winnsi.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Section loaded: urlmon.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Section loaded: srvcli.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Section loaded: netutils.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Section loaded: dnsapi.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Section loaded: rasadhlp.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Section loaded: fwpuclnt.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Code function: 0_2_015E05F8 push eax; ret |
0_2_015E0602 |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Code function: 0_2_015E0588 push eax; ret |
0_2_015E0602 |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Code function: 0_2_015E0588 push eax; ret |
0_2_015E0612 |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Code function: 0_2_015E05B8 push eax; ret |
0_2_015E05F2 |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Code function: 0_2_015E0618 push eax; ret |
0_2_015E0622 |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Code function: 0_2_015E0608 push eax; ret |
0_2_015E0612 |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Code function: 6_2_013C05B8 push eax; ret |
6_2_013C05F2 |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Code function: 6_2_013C0588 push eax; ret |
6_2_013C0602 |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Code function: 6_2_013C0588 push eax; ret |
6_2_013C0612 |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Code function: 6_2_013C05F8 push eax; ret |
6_2_013C0602 |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Code function: 6_2_013C0618 push eax; ret |
6_2_013C0622 |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Code function: 6_2_013C0608 push eax; ret |
6_2_013C0612 |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Code function: 6_2_05CB55C3 push edx; retf |
6_2_05CB55CA |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Code function: 6_2_05CB55D3 push ebx; retf |
6_2_05CB55DA |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Code function: 6_2_05CB558C push edx; retf |
6_2_05CB55A2 |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Code function: 6_2_05CB55AB push eax; retf |
6_2_05CB55B6 |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Code function: 6_2_05CB55A3 push ecx; retf |
6_2_05CB55AA |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Code function: 6_2_05CB55B7 push ecx; retf |
6_2_05CB55C2 |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Code function: 6_2_05CB4C1B push 00000048h; retf |
6_2_05CB4C22 |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Code function: 6_2_05CB3FDB push ds; retf |
6_2_05CB3FE1 |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Code function: 6_2_05CB11CB push cs; retf |
6_2_05CB11D2 |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Code function: 6_2_05CB406C pushad ; retf |
6_2_05CB406D |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Code function: 6_2_05CB1ACD push ss; retf |
6_2_05CB1ACE |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Code function: 6_2_05CB1AC3 push ss; retf |
6_2_05CB1ACA |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Code function: 6_2_05CB6A2F push esp; retf |
6_2_05CB6A35 |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Code function: 6_2_05CB6A38 push 699605CBh; retf |
6_2_05CB6A3E |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Code function: 7_2_004024F2 push ds; retf |
7_2_0040250D |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Code function: 7_2_004011C5 push 25BF6CCCh; retf |
7_2_004011CA |
Source: 0.2.PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe.43ab5c8.13.raw.unpack, AssemblyLoader.cs |
High entropy of concatenated method names: 'CultureToString', 'ReadExistingAssembly', 'CopyTo', 'LoadStream', 'LoadStream', 'ReadStream', 'ReadFromEmbeddedResources', 'ResolveAssembly', 'Attach', 'mImcw49DFTBR2Kc4glt' |
Source: 0.2.PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe.43ab5c8.13.raw.unpack, OK20t2DmSFhZLKxJ1Za.cs |
High entropy of concatenated method names: 'vqkDwJJFoy', 'wdiDfG456s', 'dlCDRgE2bA', 'YWEDom5NSQ', 'lUuDa6iXa8', 'zm311aolGinfrvCjIOu', 'UWwKxqoAcZQGCAw4v7t', 'tV9GoioIABuhWMxSqth', 'G3xHp4obNpoXAlnrXg3', 'B4n61toH1VV5suyhdsF' |
Source: 0.2.PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe.43ab5c8.13.raw.unpack, MWjo8yZPThnGCd2dRnI.cs |
High entropy of concatenated method names: 'MPuZSkrj56', 'p0YZ7Y8PQI', 'TyvZNNbyoo', 'AuLZAbOt5M', 'kQcZILSfsu', 'TnTZb7gm5T', 'RlUZHuu0sf', 'WExZcU4sBs', 'NNlZ2eQj74', 'DKgZ4ml6yY' |
Source: 0.2.PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe.43ab5c8.13.raw.unpack, qg3O71FzVYe2k3vnArU.cs |
High entropy of concatenated method names: 'TxBb3JdYSH', 'sJqbvteI3w', 'BiYbEIKfkn', 'OIFb6HtJo5', 'CHRbiFE01x', 'EyQbUIf0ux', 'C6HbxBSxcs', 'bpv7Jg0Shh', 'MgObXHYWLb', 'GG6bmaR8KN' |
Source: 0.2.PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe.43ab5c8.13.raw.unpack, sI2PgIFoi615B5KFe1M.cs |
High entropy of concatenated method names: 'yIYFq3PUUE', 'mtLFV546g8', 'tZMFMnkwcm', 'rfdFWDT5V8', 'iqFFG5DkqS', 'MebFnLkBya', 'oaTFO8iwSj', 'RHsFjU9SFY', 'SbKF895fQ0', 'PFXFLFUrZ1' |
Source: 0.2.PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe.43ab5c8.13.raw.unpack, F3SOmS1RfeVd8H521qy.cs |
High entropy of concatenated method names: 'yDIx0B9KxRLPlWDAa9H', 'sRNQqK99VsPxOTvJQLY', 'MA8FFs65OY', 'aK0nDa9sKbZkFDdRABx', 'uapS7a95TTeO3EHF4ui', 'qfXcWp9pPB2bFtNTbBw', 'sPkJIK9TBdJKUrGmidE', 'mDNUjH9uZNfDLRCKLTw', 'ytDeOL9qFoo1owG0jR3', 'APj8aC9Vvsf7TDvNNne' |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe TID: 2352 |
Thread sleep time: -25825441703193356s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe TID: 2352 |
Thread sleep time: -100000s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe TID: 2612 |
Thread sleep count: 1955 > 30 |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe TID: 2612 |
Thread sleep count: 5998 > 30 |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe TID: 2352 |
Thread sleep time: -99875s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe TID: 2352 |
Thread sleep time: -99765s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe TID: 2352 |
Thread sleep time: -99651s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe TID: 2352 |
Thread sleep time: -99547s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe TID: 2352 |
Thread sleep time: -99422s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe TID: 2352 |
Thread sleep time: -99312s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe TID: 2352 |
Thread sleep time: -99203s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe TID: 2352 |
Thread sleep time: -99093s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe TID: 2352 |
Thread sleep time: -98984s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe TID: 2352 |
Thread sleep time: -98875s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe TID: 2352 |
Thread sleep time: -98761s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe TID: 2352 |
Thread sleep time: -98613s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe TID: 2352 |
Thread sleep time: -98499s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe TID: 2352 |
Thread sleep time: -98361s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe TID: 2352 |
Thread sleep time: -98178s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe TID: 2352 |
Thread sleep time: -98000s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe TID: 2352 |
Thread sleep time: -97890s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe TID: 2352 |
Thread sleep time: -97781s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe TID: 2352 |
Thread sleep time: -97667s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe TID: 2352 |
Thread sleep time: -97562s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe TID: 2352 |
Thread sleep time: -97453s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe TID: 2352 |
Thread sleep time: -97343s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe TID: 2352 |
Thread sleep time: -97234s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe TID: 2352 |
Thread sleep time: -97125s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe TID: 2352 |
Thread sleep time: -97015s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe TID: 2352 |
Thread sleep time: -96906s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe TID: 2352 |
Thread sleep time: -96796s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe TID: 2352 |
Thread sleep time: -96687s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe TID: 2352 |
Thread sleep time: -96578s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe TID: 2352 |
Thread sleep time: -96468s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe TID: 2352 |
Thread sleep time: -96359s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe TID: 2352 |
Thread sleep time: -96250s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe TID: 2352 |
Thread sleep time: -96140s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe TID: 2352 |
Thread sleep time: -96031s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe TID: 2352 |
Thread sleep time: -95919s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe TID: 2352 |
Thread sleep time: -95812s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe TID: 5944 |
Thread sleep time: -19369081277395017s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe TID: 5944 |
Thread sleep time: -100000s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe TID: 5944 |
Thread sleep time: -99860s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe TID: 4500 |
Thread sleep count: 2620 > 30 |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe TID: 4500 |
Thread sleep count: 4112 > 30 |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe TID: 5944 |
Thread sleep time: -99735s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe TID: 5944 |
Thread sleep time: -99406s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe TID: 5944 |
Thread sleep time: -99297s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe TID: 5944 |
Thread sleep time: -99188s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe TID: 5944 |
Thread sleep time: -99063s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe TID: 5944 |
Thread sleep time: -98953s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe TID: 5944 |
Thread sleep time: -98843s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe TID: 5944 |
Thread sleep time: -98734s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe TID: 5944 |
Thread sleep time: -98625s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe TID: 5944 |
Thread sleep time: -98516s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe TID: 5944 |
Thread sleep time: -98391s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe TID: 5944 |
Thread sleep time: -98281s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe TID: 5944 |
Thread sleep time: -98172s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe TID: 5944 |
Thread sleep time: -98062s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe TID: 5944 |
Thread sleep time: -97953s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe TID: 5944 |
Thread sleep time: -97844s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe TID: 5944 |
Thread sleep time: -97734s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe TID: 5944 |
Thread sleep time: -97625s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe TID: 5944 |
Thread sleep time: -97516s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe TID: 5944 |
Thread sleep time: -97403s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe TID: 5944 |
Thread sleep time: -97281s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe TID: 5944 |
Thread sleep time: -97172s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe TID: 5944 |
Thread sleep time: -97057s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe TID: 5944 |
Thread sleep time: -96891s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe TID: 5944 |
Thread sleep time: -96578s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe TID: 5944 |
Thread sleep time: -96447s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe TID: 5944 |
Thread sleep time: -96328s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe TID: 5944 |
Thread sleep time: -96219s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe TID: 5944 |
Thread sleep time: -96094s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe TID: 5944 |
Thread sleep time: -95984s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe TID: 5944 |
Thread sleep time: -95875s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe TID: 5944 |
Thread sleep time: -95766s >= -30000s |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe TID: 5944 |
Thread sleep time: -95656s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Thread delayed: delay time: 922337203685477 |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Thread delayed: delay time: 100000 |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Thread delayed: delay time: 99875 |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Thread delayed: delay time: 99765 |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Thread delayed: delay time: 99651 |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Thread delayed: delay time: 99547 |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Thread delayed: delay time: 99422 |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Thread delayed: delay time: 99312 |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Thread delayed: delay time: 99203 |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Thread delayed: delay time: 99093 |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Thread delayed: delay time: 98984 |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Thread delayed: delay time: 98875 |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Thread delayed: delay time: 98761 |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Thread delayed: delay time: 98613 |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Thread delayed: delay time: 98499 |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Thread delayed: delay time: 98361 |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Thread delayed: delay time: 98178 |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Thread delayed: delay time: 98000 |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Thread delayed: delay time: 97890 |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Thread delayed: delay time: 97781 |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Thread delayed: delay time: 97667 |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Thread delayed: delay time: 97562 |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Thread delayed: delay time: 97453 |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Thread delayed: delay time: 97343 |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Thread delayed: delay time: 97234 |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Thread delayed: delay time: 97125 |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Thread delayed: delay time: 97015 |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Thread delayed: delay time: 96906 |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Thread delayed: delay time: 96796 |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Thread delayed: delay time: 96687 |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Thread delayed: delay time: 96578 |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Thread delayed: delay time: 96468 |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Thread delayed: delay time: 96359 |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Thread delayed: delay time: 96250 |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Thread delayed: delay time: 96140 |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Thread delayed: delay time: 96031 |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Thread delayed: delay time: 95919 |
Jump to behavior |
Source: C:\Users\user\Desktop\PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe |
Thread delayed: delay time: 95812 |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Thread delayed: delay time: 922337203685477 |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Thread delayed: delay time: 100000 |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Thread delayed: delay time: 99860 |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Thread delayed: delay time: 99735 |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Thread delayed: delay time: 99406 |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Thread delayed: delay time: 99297 |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Thread delayed: delay time: 99188 |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Thread delayed: delay time: 99063 |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Thread delayed: delay time: 98953 |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Thread delayed: delay time: 98843 |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Thread delayed: delay time: 98734 |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Thread delayed: delay time: 98625 |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Thread delayed: delay time: 98516 |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Thread delayed: delay time: 98391 |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Thread delayed: delay time: 98281 |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Thread delayed: delay time: 98172 |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Thread delayed: delay time: 98062 |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Thread delayed: delay time: 97953 |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Thread delayed: delay time: 97844 |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Thread delayed: delay time: 97734 |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Thread delayed: delay time: 97625 |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Thread delayed: delay time: 97516 |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Thread delayed: delay time: 97403 |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Thread delayed: delay time: 97281 |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Thread delayed: delay time: 97172 |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Thread delayed: delay time: 97057 |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Thread delayed: delay time: 96891 |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Thread delayed: delay time: 96578 |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Thread delayed: delay time: 96447 |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Thread delayed: delay time: 96328 |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Thread delayed: delay time: 96219 |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Thread delayed: delay time: 96094 |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Thread delayed: delay time: 95984 |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Thread delayed: delay time: 95875 |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Thread delayed: delay time: 95766 |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\FieldNames.exe |
Thread delayed: delay time: 95656 |
Jump to behavior |
Source: WebData.2.dr |
Binary or memory string: Canara Transaction PasswordVMware20,11696428655x |
Source: WebData.2.dr |
Binary or memory string: discord.comVMware20,11696428655f |
Source: WebData.2.dr |
Binary or memory string: interactivebrokers.co.inVMware20,11696428655d |
Source: WebData.2.dr |
Binary or memory string: Interactive Brokers - COM.HKVMware20,11696428655 |
Source: WebData.2.dr |
Binary or memory string: global block list test formVMware20,11696428655 |
Source: WebData.2.dr |
Binary or memory string: Canara Transaction PasswordVMware20,11696428655} |
Source: InstallUtil.exe, 00000002.00000002.3305635075.0000000000A97000.00000004.00000020.00020000.00000000.sdmp, InstallUtil.exe, 00000002.00000002.3306426620.0000000000AE4000.00000004.00000020.00020000.00000000.sdmp, InstallUtil.exe, 00000007.00000002.3306652645.0000000000D17000.00000004.00000020.00020000.00000000.sdmp, InstallUtil.exe, 00000007.00000002.3305781323.0000000000CF1000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: Hyper-V RAW |
Source: wscript.exe, 00000005.00000002.2231461639.0000017F4AC12000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: \??\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\ |
Source: InstallUtil.exe, 00000007.00000002.3306652645.0000000000D17000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: Hyper-V RAWen-GBn |
Source: WebData.2.dr |
Binary or memory string: Interactive Brokers - EU East & CentralVMware20,11696428655 |
Source: WebData.2.dr |
Binary or memory string: Canara Change Transaction PasswordVMware20,11696428655^ |
Source: WebData.2.dr |
Binary or memory string: account.microsoft.com/profileVMware20,11696428655u |
Source: WebData.2.dr |
Binary or memory string: secure.bankofamerica.comVMware20,11696428655|UE |
Source: WebData.2.dr |
Binary or memory string: www.interactivebrokers.comVMware20,11696428655} |
Source: WebData.2.dr |
Binary or memory string: Interactive Brokers - GDCDYNVMware20,11696428655p |
Source: WebData.2.dr |
Binary or memory string: Interactive Brokers - EU WestVMware20,11696428655n |
Source: WebData.2.dr |
Binary or memory string: outlook.office365.comVMware20,11696428655t |
Source: WebData.2.dr |
Binary or memory string: microsoft.visualstudio.comVMware20,11696428655x |
Source: PO-Zam#U00f3wienie zakupu-8837837849-pl-.exe, 00000000.00000002.2111378125.00000000011DF000.00000004.00000020.00020000.00000000.sdmp, FieldNames.exe, 00000006.00000002.2286664528.000000000119C000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll |
Source: WebData.2.dr |
Binary or memory string: Canara Change Transaction PasswordVMware20,11696428655 |
Source: WebData.2.dr |
Binary or memory string: outlook.office.comVMware20,11696428655s |
Source: WebData.2.dr |
Binary or memory string: www.interactivebrokers.co.inVMware20,11696428655~ |
Source: WebData.2.dr |
Binary or memory string: ms.portal.azure.comVMware20,11696428655 |
Source: WebData.2.dr |
Binary or memory string: AMC password management pageVMware20,11696428655 |
Source: WebData.2.dr |
Binary or memory string: tasks.office.comVMware20,11696428655o |
Source: WebData.2.dr |
Binary or memory string: Interactive Brokers - NDCDYNVMware20,11696428655z |
Source: WebData.2.dr |
Binary or memory string: turbotax.intuit.comVMware20,11696428655t |
Source: WebData.2.dr |
Binary or memory string: interactivebrokers.comVMware20,11696428655 |
Source: WebData.2.dr |
Binary or memory string: Interactive Brokers - non-EU EuropeVMware20,11696428655 |
Source: WebData.2.dr |
Binary or memory string: dev.azure.comVMware20,11696428655j |
Source: WebData.2.dr |
Binary or memory string: netportal.hdfcbank.comVMware20,11696428655 |
Source: FieldNames.exe, 00000006.00000002.2288985162.0000000002E9C000.00000004.00000800.00020000.00000000.sdmp |
Binary or memory string: SerialNumber0VMware|VIRTUAL|A M I|XenDselect * from Win32_ComputerSystem |
Source: WebData.2.dr |
Binary or memory string: Interactive Brokers - HKVMware20,11696428655] |
Source: FieldNames.exe, 00000006.00000002.2288985162.0000000002E9C000.00000004.00000800.00020000.00000000.sdmp |
Binary or memory string: model0Microsoft|VMWare|Virtual |
Source: WebData.2.dr |
Binary or memory string: bankofamerica.comVMware20,11696428655x |
Source: WebData.2.dr |
Binary or memory string: trackpan.utiitsl.comVMware20,11696428655h |
Source: WebData.2.dr |
Binary or memory string: Test URL for global passwords blocklistVMware20,11696428655 |