Source: 2Lzx7LMDWV.exe, 00000000.00000002.1720387451.0000000003E3B000.00000004.00000800.00020000.00000000.sdmp, 2Lzx7LMDWV.exe, 00000004.00000002.4143678149.0000000000402000.00000040.00000400.00020000.00000000.sdmp |
String found in binary or memory: http://51.38.247.67:8081/_send_.php?LCapplication/x-www-form-urlencoded |
Source: 2Lzx7LMDWV.exe, 00000000.00000002.1720387451.0000000003E3B000.00000004.00000800.00020000.00000000.sdmp, 2Lzx7LMDWV.exe, 00000004.00000002.4143678149.0000000000402000.00000040.00000400.00020000.00000000.sdmp, 2Lzx7LMDWV.exe, 00000004.00000002.4145541161.0000000002EA1000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://aborters.duckdns.org:8081 |
Source: 2Lzx7LMDWV.exe, 00000000.00000002.1720387451.0000000003E3B000.00000004.00000800.00020000.00000000.sdmp, 2Lzx7LMDWV.exe, 00000004.00000002.4143678149.0000000000402000.00000040.00000400.00020000.00000000.sdmp, 2Lzx7LMDWV.exe, 00000004.00000002.4145541161.0000000002EA1000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://anotherarmy.dns.army:8081 |
Source: 2Lzx7LMDWV.exe, 00000004.00000002.4145541161.0000000002EA1000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://checkip.dyndns.org |
Source: 2Lzx7LMDWV.exe, 00000004.00000002.4145541161.0000000002EA1000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://checkip.dyndns.org/ |
Source: 2Lzx7LMDWV.exe, 00000000.00000002.1720387451.0000000003E3B000.00000004.00000800.00020000.00000000.sdmp, 2Lzx7LMDWV.exe, 00000004.00000002.4143678149.0000000000402000.00000040.00000400.00020000.00000000.sdmp |
String found in binary or memory: http://checkip.dyndns.org/q |
Source: 2Lzx7LMDWV.exe, 00000000.00000002.1719951463.0000000002841000.00000004.00000800.00020000.00000000.sdmp, 2Lzx7LMDWV.exe, 00000004.00000002.4145541161.0000000002EA1000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name |
Source: 2Lzx7LMDWV.exe, 00000000.00000002.1720387451.0000000003E3B000.00000004.00000800.00020000.00000000.sdmp, 2Lzx7LMDWV.exe, 00000004.00000002.4143678149.0000000000402000.00000040.00000400.00020000.00000000.sdmp, 2Lzx7LMDWV.exe, 00000004.00000002.4145541161.0000000002EA1000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://varders.kozow.com:8081 |
Source: 2Lzx7LMDWV.exe, 00000000.00000002.1723554229.0000000006822000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://www.apache.org/licenses/LICENSE-2.0 |
Source: 2Lzx7LMDWV.exe, 00000000.00000002.1723554229.0000000006822000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://www.carterandcone.coml |
Source: 2Lzx7LMDWV.exe, 00000000.00000002.1723554229.0000000006822000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://www.fontbureau.com |
Source: 2Lzx7LMDWV.exe, 00000000.00000002.1723554229.0000000006822000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://www.fontbureau.com/designers |
Source: 2Lzx7LMDWV.exe, 00000000.00000002.1723554229.0000000006822000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://www.fontbureau.com/designers/? |
Source: 2Lzx7LMDWV.exe, 00000000.00000002.1723554229.0000000006822000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://www.fontbureau.com/designers/cabarga.htmlN |
Source: 2Lzx7LMDWV.exe, 00000000.00000002.1723554229.0000000006822000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://www.fontbureau.com/designers/frere-user.html |
Source: 2Lzx7LMDWV.exe, 00000000.00000002.1723554229.0000000006822000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://www.fontbureau.com/designers8 |
Source: 2Lzx7LMDWV.exe, 00000000.00000002.1723554229.0000000006822000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://www.fontbureau.com/designers? |
Source: 2Lzx7LMDWV.exe, 00000000.00000002.1723554229.0000000006822000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://www.fontbureau.com/designersG |
Source: 2Lzx7LMDWV.exe, 00000000.00000002.1723554229.0000000006822000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://www.fonts.com |
Source: 2Lzx7LMDWV.exe, 00000000.00000002.1723554229.0000000006822000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://www.founder.com.cn/cn |
Source: 2Lzx7LMDWV.exe, 00000000.00000002.1723554229.0000000006822000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://www.founder.com.cn/cn/bThe |
Source: 2Lzx7LMDWV.exe, 00000000.00000002.1723554229.0000000006822000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://www.founder.com.cn/cn/cThe |
Source: 2Lzx7LMDWV.exe, 00000000.00000002.1723554229.0000000006822000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://www.galapagosdesign.com/DPlease |
Source: 2Lzx7LMDWV.exe, 00000000.00000002.1723554229.0000000006822000.00000004.00000800.00020000.00000000.sdmp, 2Lzx7LMDWV.exe, 00000000.00000002.1723442716.0000000005719000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://www.galapagosdesign.com/staff/dennis.htm |
Source: 2Lzx7LMDWV.exe, 00000000.00000002.1723554229.0000000006822000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://www.goodfont.co.kr |
Source: 2Lzx7LMDWV.exe, 00000000.00000002.1723554229.0000000006822000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://www.jiyu-kobo.co.jp/ |
Source: 2Lzx7LMDWV.exe, 00000000.00000002.1723554229.0000000006822000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://www.sajatypeworks.com |
Source: 2Lzx7LMDWV.exe, 00000000.00000002.1723475118.0000000005754000.00000004.00000020.00020000.00000000.sdmp, 2Lzx7LMDWV.exe, 00000000.00000002.1723554229.0000000006822000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://www.sakkal.com |
Source: 2Lzx7LMDWV.exe, 00000000.00000002.1723554229.0000000006822000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://www.sandoll.co.kr |
Source: 2Lzx7LMDWV.exe, 00000000.00000002.1723554229.0000000006822000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://www.tiro.com |
Source: 2Lzx7LMDWV.exe, 00000000.00000002.1723554229.0000000006822000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://www.typography.netD |
Source: 2Lzx7LMDWV.exe, 00000000.00000002.1723554229.0000000006822000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://www.urwpp.deDPlease |
Source: 2Lzx7LMDWV.exe, 00000000.00000002.1723554229.0000000006822000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://www.zhongyicts.com.cn |
Source: 2Lzx7LMDWV.exe, 00000004.00000002.4145541161.0000000002F8A000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://api.telegram.org |
Source: 2Lzx7LMDWV.exe, 00000000.00000002.1720387451.0000000003E3B000.00000004.00000800.00020000.00000000.sdmp, 2Lzx7LMDWV.exe, 00000004.00000002.4145541161.0000000002F8A000.00000004.00000800.00020000.00000000.sdmp, 2Lzx7LMDWV.exe, 00000004.00000002.4143678149.0000000000402000.00000040.00000400.00020000.00000000.sdmp |
String found in binary or memory: https://api.telegram.org/bot |
Source: 2Lzx7LMDWV.exe, 00000004.00000002.4145541161.0000000002F8A000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://api.telegram.org/bot/sendMessage?chat_id=&text= |
Source: 2Lzx7LMDWV.exe, 00000004.00000002.4145541161.0000000002F8A000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://api.telegram.org/bot/sendMessage?chat_id=&text=%20%0D%0A%0D%0APC%20Name:965543%0D%0ADate%20a |
Source: 2Lzx7LMDWV.exe, 00000004.00000002.4145541161.0000000003067000.00000004.00000800.00020000.00000000.sdmp, 2Lzx7LMDWV.exe, 00000004.00000002.4145541161.0000000003058000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://chrome.google.com/webstore?hl=en |
Source: 2Lzx7LMDWV.exe, 00000004.00000002.4145541161.0000000003062000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://chrome.google.com/webstore?hl=enlB |
Source: 2Lzx7LMDWV.exe, 00000004.00000002.4145541161.0000000002EF2000.00000004.00000800.00020000.00000000.sdmp, 2Lzx7LMDWV.exe, 00000004.00000002.4145541161.0000000002F8A000.00000004.00000800.00020000.00000000.sdmp, 2Lzx7LMDWV.exe, 00000004.00000002.4145541161.0000000002F62000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://reallyfreegeoip.org |
Source: 2Lzx7LMDWV.exe, 00000000.00000002.1720387451.0000000003E3B000.00000004.00000800.00020000.00000000.sdmp, 2Lzx7LMDWV.exe, 00000004.00000002.4145541161.0000000002EF2000.00000004.00000800.00020000.00000000.sdmp, 2Lzx7LMDWV.exe, 00000004.00000002.4143678149.0000000000402000.00000040.00000400.00020000.00000000.sdmp |
String found in binary or memory: https://reallyfreegeoip.org/xml/ |
Source: 2Lzx7LMDWV.exe, 00000004.00000002.4145541161.0000000002F62000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://reallyfreegeoip.org/xml/173.254.250.82 |
Source: 2Lzx7LMDWV.exe, 00000004.00000002.4145541161.0000000002F1C000.00000004.00000800.00020000.00000000.sdmp, 2Lzx7LMDWV.exe, 00000004.00000002.4145541161.0000000002F8A000.00000004.00000800.00020000.00000000.sdmp, 2Lzx7LMDWV.exe, 00000004.00000002.4145541161.0000000002F62000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://reallyfreegeoip.org/xml/173.254.250.82$ |
Source: 2Lzx7LMDWV.exe, 00000004.00000002.4148303554.0000000003FF7000.00000004.00000800.00020000.00000000.sdmp, 2Lzx7LMDWV.exe, 00000004.00000002.4145541161.0000000002FAD000.00000004.00000800.00020000.00000000.sdmp, 2Lzx7LMDWV.exe, 00000004.00000002.4148303554.000000000424A000.00000004.00000800.00020000.00000000.sdmp, 2Lzx7LMDWV.exe, 00000004.00000002.4148303554.0000000004126000.00000004.00000800.00020000.00000000.sdmp, 2Lzx7LMDWV.exe, 00000004.00000002.4148303554.0000000003FD0000.00000004.00000800.00020000.00000000.sdmp, 2Lzx7LMDWV.exe, 00000004.00000002.4148303554.0000000003F82000.00000004.00000800.00020000.00000000.sdmp, 2Lzx7LMDWV.exe, 00000004.00000002.4148303554.0000000004174000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://support.office.com/article/7D48285B-20E8-4B9B-91AD-216E34163BAD?wt.mc_id=EnterPK2016 |
Source: 2Lzx7LMDWV.exe, 00000004.00000002.4148303554.000000000412E000.00000004.00000800.00020000.00000000.sdmp, 2Lzx7LMDWV.exe, 00000004.00000002.4148303554.0000000004225000.00000004.00000800.00020000.00000000.sdmp, 2Lzx7LMDWV.exe, 00000004.00000002.4148303554.0000000003FD2000.00000004.00000800.00020000.00000000.sdmp, 2Lzx7LMDWV.exe, 00000004.00000002.4148303554.0000000003F8A000.00000004.00000800.00020000.00000000.sdmp, 2Lzx7LMDWV.exe, 00000004.00000002.4148303554.0000000003F5D000.00000004.00000800.00020000.00000000.sdmp, 2Lzx7LMDWV.exe, 00000004.00000002.4148303554.0000000004101000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://support.office.com/article/7D48285B-20E8-4B9B-91AD-216E34163BAD?wt.mc_id=EnterPK2016Examples |
Source: 2Lzx7LMDWV.exe, 00000004.00000002.4148303554.0000000003FF7000.00000004.00000800.00020000.00000000.sdmp, 2Lzx7LMDWV.exe, 00000004.00000002.4145541161.0000000002FAD000.00000004.00000800.00020000.00000000.sdmp, 2Lzx7LMDWV.exe, 00000004.00000002.4148303554.000000000424A000.00000004.00000800.00020000.00000000.sdmp, 2Lzx7LMDWV.exe, 00000004.00000002.4148303554.0000000004126000.00000004.00000800.00020000.00000000.sdmp, 2Lzx7LMDWV.exe, 00000004.00000002.4148303554.0000000003FD0000.00000004.00000800.00020000.00000000.sdmp, 2Lzx7LMDWV.exe, 00000004.00000002.4148303554.0000000003F82000.00000004.00000800.00020000.00000000.sdmp, 2Lzx7LMDWV.exe, 00000004.00000002.4148303554.0000000004174000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://support.office.com/article/94ba2e0b-638e-4a92-8857-2cb5ac1d8e17 |
Source: 2Lzx7LMDWV.exe, 00000004.00000002.4148303554.000000000412E000.00000004.00000800.00020000.00000000.sdmp, 2Lzx7LMDWV.exe, 00000004.00000002.4148303554.0000000004225000.00000004.00000800.00020000.00000000.sdmp, 2Lzx7LMDWV.exe, 00000004.00000002.4148303554.0000000003FD2000.00000004.00000800.00020000.00000000.sdmp, 2Lzx7LMDWV.exe, 00000004.00000002.4148303554.0000000003F8A000.00000004.00000800.00020000.00000000.sdmp, 2Lzx7LMDWV.exe, 00000004.00000002.4148303554.0000000003F5D000.00000004.00000800.00020000.00000000.sdmp, 2Lzx7LMDWV.exe, 00000004.00000002.4148303554.0000000004101000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://support.office.com/article/94ba2e0b-638e-4a92-8857-2cb5ac1d8e17Install |
Source: 2Lzx7LMDWV.exe, 00000004.00000002.4145541161.0000000003098000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://www.office.com/ |
Source: 2Lzx7LMDWV.exe, 00000004.00000002.4145541161.0000000003093000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://www.office.com/lB |
Source: 0.2.2Lzx7LMDWV.exe.416f0e0.0.unpack, type: UNPACKEDPE |
Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: 0.2.2Lzx7LMDWV.exe.416f0e0.0.unpack, type: UNPACKEDPE |
Matched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/ |
Source: 0.2.2Lzx7LMDWV.exe.416f0e0.0.unpack, type: UNPACKEDPE |
Matched rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook author = ditekSHen, description = Detects executables with potential process hoocking |
Source: 4.2.2Lzx7LMDWV.exe.400000.0.unpack, type: UNPACKEDPE |
Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: 4.2.2Lzx7LMDWV.exe.400000.0.unpack, type: UNPACKEDPE |
Matched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/ |
Source: 4.2.2Lzx7LMDWV.exe.400000.0.unpack, type: UNPACKEDPE |
Matched rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook author = ditekSHen, description = Detects executables with potential process hoocking |
Source: 0.2.2Lzx7LMDWV.exe.416f0e0.0.raw.unpack, type: UNPACKEDPE |
Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: 0.2.2Lzx7LMDWV.exe.416f0e0.0.raw.unpack, type: UNPACKEDPE |
Matched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/ |
Source: 0.2.2Lzx7LMDWV.exe.416f0e0.0.raw.unpack, type: UNPACKEDPE |
Matched rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook author = ditekSHen, description = Detects executables with potential process hoocking |
Source: 0.2.2Lzx7LMDWV.exe.40ea4c0.1.raw.unpack, type: UNPACKEDPE |
Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: 0.2.2Lzx7LMDWV.exe.40ea4c0.1.raw.unpack, type: UNPACKEDPE |
Matched rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook author = ditekSHen, description = Detects executables with potential process hoocking |
Source: 0.2.2Lzx7LMDWV.exe.40658a0.2.raw.unpack, type: UNPACKEDPE |
Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: 0.2.2Lzx7LMDWV.exe.40658a0.2.raw.unpack, type: UNPACKEDPE |
Matched rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook author = ditekSHen, description = Detects executables with potential process hoocking |
Source: 00000004.00000002.4143678149.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY |
Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: 00000000.00000002.1720387451.0000000003E3B000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY |
Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: Process Memory Space: 2Lzx7LMDWV.exe PID: 7416, type: MEMORYSTR |
Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: Process Memory Space: 2Lzx7LMDWV.exe PID: 7620, type: MEMORYSTR |
Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Section loaded: mscoree.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Section loaded: vcruntime140_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Section loaded: cryptsp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Section loaded: rsaenh.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Section loaded: cryptbase.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Section loaded: dwrite.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Section loaded: windowscodecs.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Section loaded: amsi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Section loaded: msasn1.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Section loaded: gpapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Section loaded: textshaping.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Section loaded: iconcodecservice.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Section loaded: propsys.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Section loaded: edputil.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Section loaded: urlmon.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Section loaded: iertutil.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Section loaded: srvcli.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Section loaded: netutils.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Section loaded: windows.staterepositoryps.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Section loaded: appresolver.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Section loaded: bcp47langs.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Section loaded: slc.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Section loaded: sppc.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Section loaded: onecorecommonproxystub.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Section loaded: onecoreuapcommonproxystub.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: atl.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: mscoree.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: vcruntime140_clr0400.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: cryptsp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: rsaenh.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: cryptbase.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: msasn1.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: amsi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: gpapi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: msisip.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: wshext.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: appxsip.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: opcservices.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: secur32.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: urlmon.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: iertutil.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: srvcli.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: netutils.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: propsys.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: wininet.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: microsoft.management.infrastructure.native.unmanaged.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: mi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: miutils.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: wmidcom.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: dpapi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: wbemcomn.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Section loaded: mscoree.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Section loaded: vcruntime140_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Section loaded: cryptsp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Section loaded: rsaenh.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Section loaded: cryptbase.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Section loaded: rasapi32.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Section loaded: rasman.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Section loaded: rtutils.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Section loaded: mswsock.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Section loaded: winhttp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Section loaded: ondemandconnroutehelper.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Section loaded: iphlpapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Section loaded: dhcpcsvc6.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Section loaded: dhcpcsvc.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Section loaded: dnsapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Section loaded: winnsi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Section loaded: rasadhlp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Section loaded: fwpuclnt.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Section loaded: secur32.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Section loaded: schannel.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Section loaded: mskeyprotect.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Section loaded: ntasn1.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Section loaded: ncrypt.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Section loaded: ncryptsslp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Section loaded: msasn1.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Section loaded: gpapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Section loaded: dpapi.dll |
Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: fastprox.dll |
Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: ncobjapi.dll |
Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: wbemcomn.dll |
Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: wbemcomn.dll |
Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: mpclient.dll |
Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: msasn1.dll |
Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: wmitomi.dll |
Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: mi.dll |
Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: miutils.dll |
Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: miutils.dll |
Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: gpapi.dll |
Jump to behavior |
Source: 0.2.2Lzx7LMDWV.exe.40658a0.2.raw.unpack, RG4OeI2NURbtawJEbD.cs |
High entropy of concatenated method names: 'Dispose', 'RAIXVEDtmG', 'ISJMG8vAcE', 'mx6eengVF2', 'fEVXwtVyMM', 'd18XzHxI77', 'ProcessDialogKey', 'kGDM2sRoKY', 'DTcMXygxcJ', 'JqsMMjHsq7' |
Source: 0.2.2Lzx7LMDWV.exe.40658a0.2.raw.unpack, PU2K7iMImyQ5xnsaku.cs |
High entropy of concatenated method names: 'FtGL8R9Jwp', 'nPcLKLHeYH', 'dPBLgnQDgO', 'oVnLUvV8A1', 'A0NLbNHIsg', 'hSCLhEXiHh', 'e3LLBxpmir', 'QZiLZ4LLyx', 'I2ZLCIewPH', 'dlCLJUH7MX' |
Source: 0.2.2Lzx7LMDWV.exe.40658a0.2.raw.unpack, ioZCGEwUTGxy9yeG7B.cs |
High entropy of concatenated method names: 'hw4agdcyk0', 'HeAaU06mKk', 'D8DaTdSjb6', 'KmDaGiXB52', 'sxgaFkXUDc', 'hTIa0NUHy8', 'rQRapjiKoo', 'Q2LaSMpfW4', 'pTValpD4LJ', 'fqaaOadrCn' |
Source: 0.2.2Lzx7LMDWV.exe.40658a0.2.raw.unpack, Vb64uVH5tiNGkhXK8B.cs |
High entropy of concatenated method names: 'OuZ4kqpgUq', 'ifq4vk1yvr', 'Eqc4IwGRiJ', 'dLX4Wu9dYF', 'tRv4xVxXRv', 'tj64RVqVws', 'rbr4uN9nje', 'mCd4outRLi', 'wPg4V9cJZO', 'fAh4wcwesh' |
Source: 0.2.2Lzx7LMDWV.exe.40658a0.2.raw.unpack, ub9TFKZ0KZBZAlepeNS.cs |
High entropy of concatenated method names: 'QgBC74fow8', 'XwaCQE2LR8', 'ANVC1wmFwp', 'WqbC8eBF8q', 'pb3Cym9gET', 'wdkCK4OFkW', 'DlkCHVeYPJ', 'cZZCg2s3uo', 'tlcCUBLxAA', 'WyaCNwmCkP' |
Source: 0.2.2Lzx7LMDWV.exe.40658a0.2.raw.unpack, FNNZlUA2fX44yxwCTC.cs |
High entropy of concatenated method names: 'OI667tX2gb', 'mQF6QdKVcP', 'zOY617Thhj', 'XPE68AHGY9', 'k696yr5LLy', 'Yu86KHef4K', 'Opf6Hoc64D', 'Laq6gGvnQC', 'C976UD01aZ', 'f5A6Nm329r' |
Source: 0.2.2Lzx7LMDWV.exe.40658a0.2.raw.unpack, skUgunmROyEbe7NqEg.cs |
High entropy of concatenated method names: 'ToString', 'oaShOwPCfU', 'yoqhGqnabE', 'JCehEVouDT', 'gvwhFytXss', 'eqHh0U9el8', 'QBPhifD6yX', 'ykwhpVywsv', 'dqxhST6IeI', 'GsKhrp5Pck' |
Source: 0.2.2Lzx7LMDWV.exe.40658a0.2.raw.unpack, BL5KvL1Mly7E0axwHr.cs |
High entropy of concatenated method names: 'gSY5qXZ5wr', 'zxd547lugL', 'nDl5nu02lL', 'aPI56osVY8', 'rXs5dpEFhX', 'SwSnxcCq9R', 'yQJnR0cOIe', 'Qwtnufjwtc', 'gu4noU1nye', 'SfsnVVQuAR' |
Source: 0.2.2Lzx7LMDWV.exe.40658a0.2.raw.unpack, Br21BY9k0865n8am9b.cs |
High entropy of concatenated method names: 'ONfbl9ZxHV', 'D7Vb3sTfcE', 'dxLbkrLwJM', 'If7bvxuYw7', 'rQubGnGeNR', 'mC1bEf5X2B', 'vekbFNbB1e', 'v9Fb05idQI', 'l5MbiGLicD', 'lbJbp14uQI' |
Source: 0.2.2Lzx7LMDWV.exe.40658a0.2.raw.unpack, IKdPTdIkXKcVF8CKvD.cs |
High entropy of concatenated method names: 'Xb3CX1Jywd', 'ga7CjEGokC', 'cEaCsXqn6n', 'dPFCYT9VNO', 'puAC4swHBG', 'XLRCnCTUdJ', 'nK2C5b3HL4', 'X9BZuokR3a', 'PYrZoIhtLv', 'mPjZV5qDUM' |
Source: 0.2.2Lzx7LMDWV.exe.40658a0.2.raw.unpack, lnWl7rZivkLoetqva2s.cs |
High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'twiJkaIXqT', 'Lq4JvsNhdc', 'SAhJIbUTD8', 'ipOJWwgKPe', 'toKJxJWJsZ', 'kXKJR0jDpl', 'SgyJuHYSjf' |
Source: 0.2.2Lzx7LMDWV.exe.40658a0.2.raw.unpack, sxHYhIdakXuHtwS78C.cs |
High entropy of concatenated method names: 'VBAX6OYr9U', 'jpyXdiB756', 'MhZXANExTg', 'hi2Xt3IgcG', 'K0bXbgn4RX', 'wTLXh12ILJ', 'c2GvPNybI9MjfmrF82', 'Kc5g0lK9Xsr528Tdpc', 'mygXXv0yKM', 'H2lXjO60pX' |
Source: 0.2.2Lzx7LMDWV.exe.40658a0.2.raw.unpack, BmHy4FcGOEpCWi3opG.cs |
High entropy of concatenated method names: 'XDbBoLFuHb', 'VIfBwPTmSX', 'msuZ2C0mmW', 'RxrZXWWBwr', 'dUVBO9VbBw', 'lVpB3xK9KF', 'tAFBm94XBv', 'kPVBk4vqpE', 'Po5Bv0rHgD', 'YR4BIvBJYm' |
Source: 0.2.2Lzx7LMDWV.exe.40658a0.2.raw.unpack, YNg0qF31LCM9VasJ1b.cs |
High entropy of concatenated method names: 'ck6ZYN9qql', 'Wg9Z4T81mC', 'EXnZL7KWEE', 'hEIZn0xU0P', 'U33Z5Mvtyh', 'DqPZ6SrYLW', 'g3nZdS7DNp', 'lgrZDoaTLv', 'CdeZA6wyrW', 'TUIZtabu32' |
Source: 0.2.2Lzx7LMDWV.exe.40658a0.2.raw.unpack, worj6AsQG0OlAGbUlY.cs |
High entropy of concatenated method names: 'Q1Rjqs1W2R', 'JEmjYSWQkI', 'ErCj4pogEr', 'mUAjLVLmAY', 'XkPjnTqBHJ', 'KFdj5Zmf2B', 'z8Pj6VtDfb', 'Nntjdw3bmy', 'crtjDZuYL0', 'QpijA65tjP' |
Source: 0.2.2Lzx7LMDWV.exe.40658a0.2.raw.unpack, h4fTbjFOWOq7K34SS5.cs |
High entropy of concatenated method names: 'EditValue', 'GetEditStyle', 'Vr1MVWv4tQ', 'FJFMwgjmtZ', 'HRYMz11y3o', 'YGwj2SnNui', 'vtdjXim8lU', 'Rm6jMO512L', 'S6AjjYcwO1', 'FJaGg1O5Xxec2sKjy2t' |
Source: 0.2.2Lzx7LMDWV.exe.40658a0.2.raw.unpack, yp1tsyEObext7lkyx3.cs |
High entropy of concatenated method names: 'KyZiEK0Yjjliklopo6k', 'r31XCM0IOVbXEG390ac', 'tmc5ZdNveE', 'L3E5CoF8Ms', 'wDa5J7759A', 'FTjgyP0xlxK4d1YiQP5', 'kOtvS10pRiVnH2FFD78' |
Source: 0.2.2Lzx7LMDWV.exe.40658a0.2.raw.unpack, oyvNR2ndbC84tyB6uE.cs |
High entropy of concatenated method names: 'wvGZTNeiuA', 'FLOZG6P8sS', 'p1vZEprKp3', 'fClZFR8HRE', 'TNeZkIVTr9', 'EjnZ0Kxcxy', 'Next', 'Next', 'Next', 'NextBytes' |
Source: 0.2.2Lzx7LMDWV.exe.40658a0.2.raw.unpack, cZtByPOtB9yaXbKTlg.cs |
High entropy of concatenated method names: 'Kuv1P3Qm8', 'qQ080a8cF', 'xAlKuALGM', 'nxqHDmdIy', 'cOoU33I7X', 'RUUNP7Xb4', 'd93kS6TTvGgSmH35dK', 'GAj0943jA9Cb1yalpL', 'lxNZIGUZd', 'jrmJiqICL' |
Source: 0.2.2Lzx7LMDWV.exe.40658a0.2.raw.unpack, jfgXAuzAsBxPqqT6RK.cs |
High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'grGCayLsLP', 'zDjCbHCmUN', 'agYChfqw3q', 'gDRCBmOGVc', 'waLCZ0t8fU', 'nk5CCyBD5S', 'H6eCJvplJo' |
Source: 0.2.2Lzx7LMDWV.exe.40658a0.2.raw.unpack, JXEQsFl5YEPSdgfNX9.cs |
High entropy of concatenated method names: 'HKw6YMyS3E', 'dl06L0o8a8', 'Gqk65OStyr', 'KQl5w5eHwn', 'z1U5zipn1k', 'lcu627PmLN', 'udf6XM7E9V', 'MQn6MEG2T1', 'JpN6jOhQ85', 'BFP6sCq4kW' |
Source: 0.2.2Lzx7LMDWV.exe.6d00000.4.raw.unpack, RG4OeI2NURbtawJEbD.cs |
High entropy of concatenated method names: 'Dispose', 'RAIXVEDtmG', 'ISJMG8vAcE', 'mx6eengVF2', 'fEVXwtVyMM', 'd18XzHxI77', 'ProcessDialogKey', 'kGDM2sRoKY', 'DTcMXygxcJ', 'JqsMMjHsq7' |
Source: 0.2.2Lzx7LMDWV.exe.6d00000.4.raw.unpack, PU2K7iMImyQ5xnsaku.cs |
High entropy of concatenated method names: 'FtGL8R9Jwp', 'nPcLKLHeYH', 'dPBLgnQDgO', 'oVnLUvV8A1', 'A0NLbNHIsg', 'hSCLhEXiHh', 'e3LLBxpmir', 'QZiLZ4LLyx', 'I2ZLCIewPH', 'dlCLJUH7MX' |
Source: 0.2.2Lzx7LMDWV.exe.6d00000.4.raw.unpack, ioZCGEwUTGxy9yeG7B.cs |
High entropy of concatenated method names: 'hw4agdcyk0', 'HeAaU06mKk', 'D8DaTdSjb6', 'KmDaGiXB52', 'sxgaFkXUDc', 'hTIa0NUHy8', 'rQRapjiKoo', 'Q2LaSMpfW4', 'pTValpD4LJ', 'fqaaOadrCn' |
Source: 0.2.2Lzx7LMDWV.exe.6d00000.4.raw.unpack, Vb64uVH5tiNGkhXK8B.cs |
High entropy of concatenated method names: 'OuZ4kqpgUq', 'ifq4vk1yvr', 'Eqc4IwGRiJ', 'dLX4Wu9dYF', 'tRv4xVxXRv', 'tj64RVqVws', 'rbr4uN9nje', 'mCd4outRLi', 'wPg4V9cJZO', 'fAh4wcwesh' |
Source: 0.2.2Lzx7LMDWV.exe.6d00000.4.raw.unpack, ub9TFKZ0KZBZAlepeNS.cs |
High entropy of concatenated method names: 'QgBC74fow8', 'XwaCQE2LR8', 'ANVC1wmFwp', 'WqbC8eBF8q', 'pb3Cym9gET', 'wdkCK4OFkW', 'DlkCHVeYPJ', 'cZZCg2s3uo', 'tlcCUBLxAA', 'WyaCNwmCkP' |
Source: 0.2.2Lzx7LMDWV.exe.6d00000.4.raw.unpack, FNNZlUA2fX44yxwCTC.cs |
High entropy of concatenated method names: 'OI667tX2gb', 'mQF6QdKVcP', 'zOY617Thhj', 'XPE68AHGY9', 'k696yr5LLy', 'Yu86KHef4K', 'Opf6Hoc64D', 'Laq6gGvnQC', 'C976UD01aZ', 'f5A6Nm329r' |
Source: 0.2.2Lzx7LMDWV.exe.6d00000.4.raw.unpack, skUgunmROyEbe7NqEg.cs |
High entropy of concatenated method names: 'ToString', 'oaShOwPCfU', 'yoqhGqnabE', 'JCehEVouDT', 'gvwhFytXss', 'eqHh0U9el8', 'QBPhifD6yX', 'ykwhpVywsv', 'dqxhST6IeI', 'GsKhrp5Pck' |
Source: 0.2.2Lzx7LMDWV.exe.6d00000.4.raw.unpack, BL5KvL1Mly7E0axwHr.cs |
High entropy of concatenated method names: 'gSY5qXZ5wr', 'zxd547lugL', 'nDl5nu02lL', 'aPI56osVY8', 'rXs5dpEFhX', 'SwSnxcCq9R', 'yQJnR0cOIe', 'Qwtnufjwtc', 'gu4noU1nye', 'SfsnVVQuAR' |
Source: 0.2.2Lzx7LMDWV.exe.6d00000.4.raw.unpack, Br21BY9k0865n8am9b.cs |
High entropy of concatenated method names: 'ONfbl9ZxHV', 'D7Vb3sTfcE', 'dxLbkrLwJM', 'If7bvxuYw7', 'rQubGnGeNR', 'mC1bEf5X2B', 'vekbFNbB1e', 'v9Fb05idQI', 'l5MbiGLicD', 'lbJbp14uQI' |
Source: 0.2.2Lzx7LMDWV.exe.6d00000.4.raw.unpack, IKdPTdIkXKcVF8CKvD.cs |
High entropy of concatenated method names: 'Xb3CX1Jywd', 'ga7CjEGokC', 'cEaCsXqn6n', 'dPFCYT9VNO', 'puAC4swHBG', 'XLRCnCTUdJ', 'nK2C5b3HL4', 'X9BZuokR3a', 'PYrZoIhtLv', 'mPjZV5qDUM' |
Source: 0.2.2Lzx7LMDWV.exe.6d00000.4.raw.unpack, lnWl7rZivkLoetqva2s.cs |
High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'twiJkaIXqT', 'Lq4JvsNhdc', 'SAhJIbUTD8', 'ipOJWwgKPe', 'toKJxJWJsZ', 'kXKJR0jDpl', 'SgyJuHYSjf' |
Source: 0.2.2Lzx7LMDWV.exe.6d00000.4.raw.unpack, sxHYhIdakXuHtwS78C.cs |
High entropy of concatenated method names: 'VBAX6OYr9U', 'jpyXdiB756', 'MhZXANExTg', 'hi2Xt3IgcG', 'K0bXbgn4RX', 'wTLXh12ILJ', 'c2GvPNybI9MjfmrF82', 'Kc5g0lK9Xsr528Tdpc', 'mygXXv0yKM', 'H2lXjO60pX' |
Source: 0.2.2Lzx7LMDWV.exe.6d00000.4.raw.unpack, BmHy4FcGOEpCWi3opG.cs |
High entropy of concatenated method names: 'XDbBoLFuHb', 'VIfBwPTmSX', 'msuZ2C0mmW', 'RxrZXWWBwr', 'dUVBO9VbBw', 'lVpB3xK9KF', 'tAFBm94XBv', 'kPVBk4vqpE', 'Po5Bv0rHgD', 'YR4BIvBJYm' |
Source: 0.2.2Lzx7LMDWV.exe.6d00000.4.raw.unpack, YNg0qF31LCM9VasJ1b.cs |
High entropy of concatenated method names: 'ck6ZYN9qql', 'Wg9Z4T81mC', 'EXnZL7KWEE', 'hEIZn0xU0P', 'U33Z5Mvtyh', 'DqPZ6SrYLW', 'g3nZdS7DNp', 'lgrZDoaTLv', 'CdeZA6wyrW', 'TUIZtabu32' |
Source: 0.2.2Lzx7LMDWV.exe.6d00000.4.raw.unpack, worj6AsQG0OlAGbUlY.cs |
High entropy of concatenated method names: 'Q1Rjqs1W2R', 'JEmjYSWQkI', 'ErCj4pogEr', 'mUAjLVLmAY', 'XkPjnTqBHJ', 'KFdj5Zmf2B', 'z8Pj6VtDfb', 'Nntjdw3bmy', 'crtjDZuYL0', 'QpijA65tjP' |
Source: 0.2.2Lzx7LMDWV.exe.6d00000.4.raw.unpack, h4fTbjFOWOq7K34SS5.cs |
High entropy of concatenated method names: 'EditValue', 'GetEditStyle', 'Vr1MVWv4tQ', 'FJFMwgjmtZ', 'HRYMz11y3o', 'YGwj2SnNui', 'vtdjXim8lU', 'Rm6jMO512L', 'S6AjjYcwO1', 'FJaGg1O5Xxec2sKjy2t' |
Source: 0.2.2Lzx7LMDWV.exe.6d00000.4.raw.unpack, yp1tsyEObext7lkyx3.cs |
High entropy of concatenated method names: 'KyZiEK0Yjjliklopo6k', 'r31XCM0IOVbXEG390ac', 'tmc5ZdNveE', 'L3E5CoF8Ms', 'wDa5J7759A', 'FTjgyP0xlxK4d1YiQP5', 'kOtvS10pRiVnH2FFD78' |
Source: 0.2.2Lzx7LMDWV.exe.6d00000.4.raw.unpack, oyvNR2ndbC84tyB6uE.cs |
High entropy of concatenated method names: 'wvGZTNeiuA', 'FLOZG6P8sS', 'p1vZEprKp3', 'fClZFR8HRE', 'TNeZkIVTr9', 'EjnZ0Kxcxy', 'Next', 'Next', 'Next', 'NextBytes' |
Source: 0.2.2Lzx7LMDWV.exe.6d00000.4.raw.unpack, cZtByPOtB9yaXbKTlg.cs |
High entropy of concatenated method names: 'Kuv1P3Qm8', 'qQ080a8cF', 'xAlKuALGM', 'nxqHDmdIy', 'cOoU33I7X', 'RUUNP7Xb4', 'd93kS6TTvGgSmH35dK', 'GAj0943jA9Cb1yalpL', 'lxNZIGUZd', 'jrmJiqICL' |
Source: 0.2.2Lzx7LMDWV.exe.6d00000.4.raw.unpack, jfgXAuzAsBxPqqT6RK.cs |
High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'grGCayLsLP', 'zDjCbHCmUN', 'agYChfqw3q', 'gDRCBmOGVc', 'waLCZ0t8fU', 'nk5CCyBD5S', 'H6eCJvplJo' |
Source: 0.2.2Lzx7LMDWV.exe.6d00000.4.raw.unpack, JXEQsFl5YEPSdgfNX9.cs |
High entropy of concatenated method names: 'HKw6YMyS3E', 'dl06L0o8a8', 'Gqk65OStyr', 'KQl5w5eHwn', 'z1U5zipn1k', 'lcu627PmLN', 'udf6XM7E9V', 'MQn6MEG2T1', 'JpN6jOhQ85', 'BFP6sCq4kW' |
Source: 0.2.2Lzx7LMDWV.exe.40ea4c0.1.raw.unpack, RG4OeI2NURbtawJEbD.cs |
High entropy of concatenated method names: 'Dispose', 'RAIXVEDtmG', 'ISJMG8vAcE', 'mx6eengVF2', 'fEVXwtVyMM', 'd18XzHxI77', 'ProcessDialogKey', 'kGDM2sRoKY', 'DTcMXygxcJ', 'JqsMMjHsq7' |
Source: 0.2.2Lzx7LMDWV.exe.40ea4c0.1.raw.unpack, PU2K7iMImyQ5xnsaku.cs |
High entropy of concatenated method names: 'FtGL8R9Jwp', 'nPcLKLHeYH', 'dPBLgnQDgO', 'oVnLUvV8A1', 'A0NLbNHIsg', 'hSCLhEXiHh', 'e3LLBxpmir', 'QZiLZ4LLyx', 'I2ZLCIewPH', 'dlCLJUH7MX' |
Source: 0.2.2Lzx7LMDWV.exe.40ea4c0.1.raw.unpack, ioZCGEwUTGxy9yeG7B.cs |
High entropy of concatenated method names: 'hw4agdcyk0', 'HeAaU06mKk', 'D8DaTdSjb6', 'KmDaGiXB52', 'sxgaFkXUDc', 'hTIa0NUHy8', 'rQRapjiKoo', 'Q2LaSMpfW4', 'pTValpD4LJ', 'fqaaOadrCn' |
Source: 0.2.2Lzx7LMDWV.exe.40ea4c0.1.raw.unpack, Vb64uVH5tiNGkhXK8B.cs |
High entropy of concatenated method names: 'OuZ4kqpgUq', 'ifq4vk1yvr', 'Eqc4IwGRiJ', 'dLX4Wu9dYF', 'tRv4xVxXRv', 'tj64RVqVws', 'rbr4uN9nje', 'mCd4outRLi', 'wPg4V9cJZO', 'fAh4wcwesh' |
Source: 0.2.2Lzx7LMDWV.exe.40ea4c0.1.raw.unpack, ub9TFKZ0KZBZAlepeNS.cs |
High entropy of concatenated method names: 'QgBC74fow8', 'XwaCQE2LR8', 'ANVC1wmFwp', 'WqbC8eBF8q', 'pb3Cym9gET', 'wdkCK4OFkW', 'DlkCHVeYPJ', 'cZZCg2s3uo', 'tlcCUBLxAA', 'WyaCNwmCkP' |
Source: 0.2.2Lzx7LMDWV.exe.40ea4c0.1.raw.unpack, FNNZlUA2fX44yxwCTC.cs |
High entropy of concatenated method names: 'OI667tX2gb', 'mQF6QdKVcP', 'zOY617Thhj', 'XPE68AHGY9', 'k696yr5LLy', 'Yu86KHef4K', 'Opf6Hoc64D', 'Laq6gGvnQC', 'C976UD01aZ', 'f5A6Nm329r' |
Source: 0.2.2Lzx7LMDWV.exe.40ea4c0.1.raw.unpack, skUgunmROyEbe7NqEg.cs |
High entropy of concatenated method names: 'ToString', 'oaShOwPCfU', 'yoqhGqnabE', 'JCehEVouDT', 'gvwhFytXss', 'eqHh0U9el8', 'QBPhifD6yX', 'ykwhpVywsv', 'dqxhST6IeI', 'GsKhrp5Pck' |
Source: 0.2.2Lzx7LMDWV.exe.40ea4c0.1.raw.unpack, BL5KvL1Mly7E0axwHr.cs |
High entropy of concatenated method names: 'gSY5qXZ5wr', 'zxd547lugL', 'nDl5nu02lL', 'aPI56osVY8', 'rXs5dpEFhX', 'SwSnxcCq9R', 'yQJnR0cOIe', 'Qwtnufjwtc', 'gu4noU1nye', 'SfsnVVQuAR' |
Source: 0.2.2Lzx7LMDWV.exe.40ea4c0.1.raw.unpack, Br21BY9k0865n8am9b.cs |
High entropy of concatenated method names: 'ONfbl9ZxHV', 'D7Vb3sTfcE', 'dxLbkrLwJM', 'If7bvxuYw7', 'rQubGnGeNR', 'mC1bEf5X2B', 'vekbFNbB1e', 'v9Fb05idQI', 'l5MbiGLicD', 'lbJbp14uQI' |
Source: 0.2.2Lzx7LMDWV.exe.40ea4c0.1.raw.unpack, IKdPTdIkXKcVF8CKvD.cs |
High entropy of concatenated method names: 'Xb3CX1Jywd', 'ga7CjEGokC', 'cEaCsXqn6n', 'dPFCYT9VNO', 'puAC4swHBG', 'XLRCnCTUdJ', 'nK2C5b3HL4', 'X9BZuokR3a', 'PYrZoIhtLv', 'mPjZV5qDUM' |
Source: 0.2.2Lzx7LMDWV.exe.40ea4c0.1.raw.unpack, lnWl7rZivkLoetqva2s.cs |
High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'twiJkaIXqT', 'Lq4JvsNhdc', 'SAhJIbUTD8', 'ipOJWwgKPe', 'toKJxJWJsZ', 'kXKJR0jDpl', 'SgyJuHYSjf' |
Source: 0.2.2Lzx7LMDWV.exe.40ea4c0.1.raw.unpack, sxHYhIdakXuHtwS78C.cs |
High entropy of concatenated method names: 'VBAX6OYr9U', 'jpyXdiB756', 'MhZXANExTg', 'hi2Xt3IgcG', 'K0bXbgn4RX', 'wTLXh12ILJ', 'c2GvPNybI9MjfmrF82', 'Kc5g0lK9Xsr528Tdpc', 'mygXXv0yKM', 'H2lXjO60pX' |
Source: 0.2.2Lzx7LMDWV.exe.40ea4c0.1.raw.unpack, BmHy4FcGOEpCWi3opG.cs |
High entropy of concatenated method names: 'XDbBoLFuHb', 'VIfBwPTmSX', 'msuZ2C0mmW', 'RxrZXWWBwr', 'dUVBO9VbBw', 'lVpB3xK9KF', 'tAFBm94XBv', 'kPVBk4vqpE', 'Po5Bv0rHgD', 'YR4BIvBJYm' |
Source: 0.2.2Lzx7LMDWV.exe.40ea4c0.1.raw.unpack, YNg0qF31LCM9VasJ1b.cs |
High entropy of concatenated method names: 'ck6ZYN9qql', 'Wg9Z4T81mC', 'EXnZL7KWEE', 'hEIZn0xU0P', 'U33Z5Mvtyh', 'DqPZ6SrYLW', 'g3nZdS7DNp', 'lgrZDoaTLv', 'CdeZA6wyrW', 'TUIZtabu32' |
Source: 0.2.2Lzx7LMDWV.exe.40ea4c0.1.raw.unpack, worj6AsQG0OlAGbUlY.cs |
High entropy of concatenated method names: 'Q1Rjqs1W2R', 'JEmjYSWQkI', 'ErCj4pogEr', 'mUAjLVLmAY', 'XkPjnTqBHJ', 'KFdj5Zmf2B', 'z8Pj6VtDfb', 'Nntjdw3bmy', 'crtjDZuYL0', 'QpijA65tjP' |
Source: 0.2.2Lzx7LMDWV.exe.40ea4c0.1.raw.unpack, h4fTbjFOWOq7K34SS5.cs |
High entropy of concatenated method names: 'EditValue', 'GetEditStyle', 'Vr1MVWv4tQ', 'FJFMwgjmtZ', 'HRYMz11y3o', 'YGwj2SnNui', 'vtdjXim8lU', 'Rm6jMO512L', 'S6AjjYcwO1', 'FJaGg1O5Xxec2sKjy2t' |
Source: 0.2.2Lzx7LMDWV.exe.40ea4c0.1.raw.unpack, yp1tsyEObext7lkyx3.cs |
High entropy of concatenated method names: 'KyZiEK0Yjjliklopo6k', 'r31XCM0IOVbXEG390ac', 'tmc5ZdNveE', 'L3E5CoF8Ms', 'wDa5J7759A', 'FTjgyP0xlxK4d1YiQP5', 'kOtvS10pRiVnH2FFD78' |
Source: 0.2.2Lzx7LMDWV.exe.40ea4c0.1.raw.unpack, oyvNR2ndbC84tyB6uE.cs |
High entropy of concatenated method names: 'wvGZTNeiuA', 'FLOZG6P8sS', 'p1vZEprKp3', 'fClZFR8HRE', 'TNeZkIVTr9', 'EjnZ0Kxcxy', 'Next', 'Next', 'Next', 'NextBytes' |
Source: 0.2.2Lzx7LMDWV.exe.40ea4c0.1.raw.unpack, cZtByPOtB9yaXbKTlg.cs |
High entropy of concatenated method names: 'Kuv1P3Qm8', 'qQ080a8cF', 'xAlKuALGM', 'nxqHDmdIy', 'cOoU33I7X', 'RUUNP7Xb4', 'd93kS6TTvGgSmH35dK', 'GAj0943jA9Cb1yalpL', 'lxNZIGUZd', 'jrmJiqICL' |
Source: 0.2.2Lzx7LMDWV.exe.40ea4c0.1.raw.unpack, jfgXAuzAsBxPqqT6RK.cs |
High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'grGCayLsLP', 'zDjCbHCmUN', 'agYChfqw3q', 'gDRCBmOGVc', 'waLCZ0t8fU', 'nk5CCyBD5S', 'H6eCJvplJo' |
Source: 0.2.2Lzx7LMDWV.exe.40ea4c0.1.raw.unpack, JXEQsFl5YEPSdgfNX9.cs |
High entropy of concatenated method names: 'HKw6YMyS3E', 'dl06L0o8a8', 'Gqk65OStyr', 'KQl5w5eHwn', 'z1U5zipn1k', 'lcu627PmLN', 'udf6XM7E9V', 'MQn6MEG2T1', 'JpN6jOhQ85', 'BFP6sCq4kW' |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Thread delayed: delay time: 922337203685477 |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Thread delayed: delay time: 922337203685477 |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Thread delayed: delay time: 922337203685477 |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Thread delayed: delay time: 600000 |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Thread delayed: delay time: 599890 |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Thread delayed: delay time: 599781 |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Thread delayed: delay time: 599672 |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Thread delayed: delay time: 599562 |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Thread delayed: delay time: 599453 |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Thread delayed: delay time: 599343 |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Thread delayed: delay time: 599234 |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Thread delayed: delay time: 599125 |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Thread delayed: delay time: 599015 |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Thread delayed: delay time: 598906 |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Thread delayed: delay time: 598796 |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Thread delayed: delay time: 598651 |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Thread delayed: delay time: 598544 |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Thread delayed: delay time: 598393 |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Thread delayed: delay time: 598266 |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Thread delayed: delay time: 598156 |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Thread delayed: delay time: 598047 |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Thread delayed: delay time: 597937 |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Thread delayed: delay time: 597828 |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Thread delayed: delay time: 597719 |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Thread delayed: delay time: 597594 |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Thread delayed: delay time: 597484 |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Thread delayed: delay time: 597375 |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Thread delayed: delay time: 597265 |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Thread delayed: delay time: 597156 |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Thread delayed: delay time: 597047 |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Thread delayed: delay time: 596937 |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Thread delayed: delay time: 596828 |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Thread delayed: delay time: 596719 |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Thread delayed: delay time: 596609 |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Thread delayed: delay time: 596500 |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Thread delayed: delay time: 596390 |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Thread delayed: delay time: 596281 |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Thread delayed: delay time: 596170 |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Thread delayed: delay time: 596040 |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Thread delayed: delay time: 595917 |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Thread delayed: delay time: 595783 |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Thread delayed: delay time: 595656 |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Thread delayed: delay time: 595547 |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Thread delayed: delay time: 595437 |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Thread delayed: delay time: 595328 |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Thread delayed: delay time: 595219 |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Thread delayed: delay time: 595109 |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Thread delayed: delay time: 595000 |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Thread delayed: delay time: 594891 |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Thread delayed: delay time: 594781 |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Thread delayed: delay time: 594668 |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Thread delayed: delay time: 594562 |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Thread delayed: delay time: 594453 |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Thread delayed: delay time: 594344 |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Thread delayed: delay time: 594219 |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe TID: 7436 |
Thread sleep time: -922337203685477s >= -30000s |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe TID: 7784 |
Thread sleep time: -4611686018427385s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe TID: 7916 |
Thread sleep count: 36 > 30 |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe TID: 7916 |
Thread sleep time: -33204139332677172s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe TID: 7916 |
Thread sleep time: -600000s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe TID: 7920 |
Thread sleep count: 1975 > 30 |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe TID: 7916 |
Thread sleep time: -599890s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe TID: 7920 |
Thread sleep count: 7858 > 30 |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe TID: 7916 |
Thread sleep time: -599781s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe TID: 7916 |
Thread sleep time: -599672s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe TID: 7916 |
Thread sleep time: -599562s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe TID: 7916 |
Thread sleep time: -599453s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe TID: 7916 |
Thread sleep time: -599343s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe TID: 7916 |
Thread sleep time: -599234s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe TID: 7916 |
Thread sleep time: -599125s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe TID: 7916 |
Thread sleep time: -599015s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe TID: 7916 |
Thread sleep time: -598906s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe TID: 7916 |
Thread sleep time: -598796s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe TID: 7916 |
Thread sleep time: -598651s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe TID: 7916 |
Thread sleep time: -598544s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe TID: 7916 |
Thread sleep time: -598393s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe TID: 7916 |
Thread sleep time: -598266s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe TID: 7916 |
Thread sleep time: -598156s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe TID: 7916 |
Thread sleep time: -598047s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe TID: 7916 |
Thread sleep time: -597937s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe TID: 7916 |
Thread sleep time: -597828s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe TID: 7916 |
Thread sleep time: -597719s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe TID: 7916 |
Thread sleep time: -597594s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe TID: 7916 |
Thread sleep time: -597484s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe TID: 7916 |
Thread sleep time: -597375s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe TID: 7916 |
Thread sleep time: -597265s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe TID: 7916 |
Thread sleep time: -597156s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe TID: 7916 |
Thread sleep time: -597047s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe TID: 7916 |
Thread sleep time: -596937s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe TID: 7916 |
Thread sleep time: -596828s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe TID: 7916 |
Thread sleep time: -596719s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe TID: 7916 |
Thread sleep time: -596609s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe TID: 7916 |
Thread sleep time: -596500s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe TID: 7916 |
Thread sleep time: -596390s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe TID: 7916 |
Thread sleep time: -596281s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe TID: 7916 |
Thread sleep time: -596170s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe TID: 7916 |
Thread sleep time: -596040s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe TID: 7916 |
Thread sleep time: -595917s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe TID: 7916 |
Thread sleep time: -595783s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe TID: 7916 |
Thread sleep time: -595656s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe TID: 7916 |
Thread sleep time: -595547s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe TID: 7916 |
Thread sleep time: -595437s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe TID: 7916 |
Thread sleep time: -595328s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe TID: 7916 |
Thread sleep time: -595219s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe TID: 7916 |
Thread sleep time: -595109s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe TID: 7916 |
Thread sleep time: -595000s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe TID: 7916 |
Thread sleep time: -594891s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe TID: 7916 |
Thread sleep time: -594781s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe TID: 7916 |
Thread sleep time: -594668s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe TID: 7916 |
Thread sleep time: -594562s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe TID: 7916 |
Thread sleep time: -594453s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe TID: 7916 |
Thread sleep time: -594344s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe TID: 7916 |
Thread sleep time: -594219s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Thread delayed: delay time: 922337203685477 |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Thread delayed: delay time: 922337203685477 |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Thread delayed: delay time: 922337203685477 |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Thread delayed: delay time: 600000 |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Thread delayed: delay time: 599890 |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Thread delayed: delay time: 599781 |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Thread delayed: delay time: 599672 |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Thread delayed: delay time: 599562 |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Thread delayed: delay time: 599453 |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Thread delayed: delay time: 599343 |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Thread delayed: delay time: 599234 |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Thread delayed: delay time: 599125 |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Thread delayed: delay time: 599015 |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Thread delayed: delay time: 598906 |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Thread delayed: delay time: 598796 |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Thread delayed: delay time: 598651 |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Thread delayed: delay time: 598544 |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Thread delayed: delay time: 598393 |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Thread delayed: delay time: 598266 |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Thread delayed: delay time: 598156 |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Thread delayed: delay time: 598047 |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Thread delayed: delay time: 597937 |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Thread delayed: delay time: 597828 |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Thread delayed: delay time: 597719 |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Thread delayed: delay time: 597594 |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Thread delayed: delay time: 597484 |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Thread delayed: delay time: 597375 |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Thread delayed: delay time: 597265 |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Thread delayed: delay time: 597156 |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Thread delayed: delay time: 597047 |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Thread delayed: delay time: 596937 |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Thread delayed: delay time: 596828 |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Thread delayed: delay time: 596719 |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Thread delayed: delay time: 596609 |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Thread delayed: delay time: 596500 |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Thread delayed: delay time: 596390 |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Thread delayed: delay time: 596281 |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Thread delayed: delay time: 596170 |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Thread delayed: delay time: 596040 |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Thread delayed: delay time: 595917 |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Thread delayed: delay time: 595783 |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Thread delayed: delay time: 595656 |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Thread delayed: delay time: 595547 |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Thread delayed: delay time: 595437 |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Thread delayed: delay time: 595328 |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Thread delayed: delay time: 595219 |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Thread delayed: delay time: 595109 |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Thread delayed: delay time: 595000 |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Thread delayed: delay time: 594891 |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Thread delayed: delay time: 594781 |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Thread delayed: delay time: 594668 |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Thread delayed: delay time: 594562 |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Thread delayed: delay time: 594453 |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Thread delayed: delay time: 594344 |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Thread delayed: delay time: 594219 |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Users\user\Desktop\2Lzx7LMDWV.exe VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\calibrii.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\calibrili.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\calibrib.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\calibriz.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\cambria.ttc VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\cambriai.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\cambriab.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\cambriaz.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\cambria.ttc VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\Candara.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\Candaral.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\Candarai.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\Candarali.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\Candarab.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\Candaraz.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\comic.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\comici.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\comicbd.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\comicz.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\constan.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\constani.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\constanb.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\constanz.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\corbel.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\corbell.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\corbeli.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\corbelli.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\corbelb.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\corbelz.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\cour.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\couri.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\courbd.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\courbi.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\ebrima.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\ebrimabd.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\FRADM.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\framdit.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\FRADMIT.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\FRAMDCN.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\FRADMCN.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\Gabriola.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\gadugi.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\gadugib.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\georgia.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\georgiai.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\georgiab.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\georgiaz.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\impact.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\Inkfree.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\javatext.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\LeelawUI.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\LeelUIsl.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\LeelaUIb.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\lucon.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\l_10646.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\malgun.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\malgunsl.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\malgunbd.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\himalaya.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\msjh.ttc VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\msjhl.ttc VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\msjhbd.ttc VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\msjh.ttc VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\msjhbd.ttc VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\ntailu.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\ntailub.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\phagspa.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\phagspab.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\micross.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\taile.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\taileb.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\msyh.ttc VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\msyhl.ttc VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\msyhbd.ttc VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\msyh.ttc VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\msyhl.ttc VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\mingliub.ttc VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\mingliub.ttc VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\mingliub.ttc VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\monbaiti.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\msgothic.ttc VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\msgothic.ttc VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\mvboli.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\mmrtext.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\mmrtextb.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\Nirmala.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\NirmalaS.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\NirmalaB.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\pala.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\palai.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\palab.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\palabi.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\segoepr.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\segoeprb.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\segoesc.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\segoescb.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\seguihis.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\simsun.ttc VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\simsunb.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\Sitka.ttc VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\SitkaI.ttc VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\SitkaB.ttc VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\SitkaZ.ttc VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\Sitka.ttc VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\sylfaen.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\symbol.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\tahoma.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\timesi.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\timesbi.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\trebuc.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\trebucit.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\trebucbd.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\trebucbi.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\verdana.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\verdanai.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\verdanab.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\verdanaz.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\webdings.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\wingding.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\YuGothR.ttc VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\YuGothM.ttc VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\YuGothL.ttc VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\YuGothB.ttc VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\YuGothM.ttc VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\YuGothR.ttc VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\holomdl2.ttf VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\AGENCYR.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\AGENCYB.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\ARLRDBD.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\BAUHS93.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\BOD_R.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\BOD_B.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\BOD_CR.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\BOD_PSTC.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\BOOKOSB.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\BOOKOSBI.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\BRADHITC.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\BRITANIC.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\BRLNSR.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\BRLNSB.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\BROADW.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\BSSYM7.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\CALIFR.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\CALIFI.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\CALIFB.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\CALISTI.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\CASTELAR.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\CENSCBK.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\CENTAUR.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\CHILLER.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\COLONNA.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\COPRGTL.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\DUBAI-MEDIUM.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\FORTE.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\FRABKIT.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\FREESCPT.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\FRSCRIPT.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\FTLTLT.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\GARABD.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\GIGI.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\GIL_____.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\GILB____.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\GOUDOS.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\IMPRISHA.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\JUICE___.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\LEELAWAD.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\LSANSD.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\LTYPEB.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\MAIAN.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\MTCORSVA.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\PALSCRI.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\PER_____.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\RAVIE.TTF VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Fonts\micross.ttf VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\ VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-GroupPolicy-ClientTools-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-AppManagement-AppV-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\Microsoft.Management.Infrastructure.Native\v4.0_1.0.0.0__31bf3856ad364e35\Microsoft.Management.Infrastructure.Native.dll VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\AppvClient\Microsoft.AppV.AppVClientPowerShell.dll VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1865.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-WOW64-Package~31bf3856ad364e35~amd64~en-GB~10.0.19041.1.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\BitLocker\Microsoft.BitLocker.Structures.dll VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management\v4.0_3.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Management.dll VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Users\user\Desktop\2Lzx7LMDWV.exe VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.Extensions\v4.0_4.0.0.0__31bf3856ad364e35\System.Web.Extensions.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Security\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Security.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\2Lzx7LMDWV.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation |
Jump to behavior |