Source: C:\Users\user\Desktop\Quotation.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Section loaded: dwrite.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Section loaded: textshaping.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Section loaded: windowscodecs.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Section loaded: edputil.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Section loaded: windows.staterepositoryps.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Section loaded: appresolver.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Section loaded: bcp47langs.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Section loaded: slc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Section loaded: sppc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Section loaded: onecorecommonproxystub.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Section loaded: onecoreuapcommonproxystub.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: atl.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: msisip.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wshext.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: appxsip.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: opcservices.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: secur32.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: microsoft.management.infrastructure.native.unmanaged.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: mi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: miutils.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wmidcom.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: dpapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wbemcomn.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Section loaded: wbemcomn.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Section loaded: rasapi32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Section loaded: rasman.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Section loaded: rtutils.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Section loaded: dhcpcsvc6.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Section loaded: dhcpcsvc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Section loaded: dnsapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Section loaded: winnsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Section loaded: rasadhlp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Section loaded: fwpuclnt.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Section loaded: secur32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Section loaded: schannel.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Section loaded: vaultcli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Section loaded: edputil.dll | Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: fastprox.dll | Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: ncobjapi.dll | Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: wbemcomn.dll | Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: wbemcomn.dll | Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: mpclient.dll | Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: wmitomi.dll | Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: mi.dll | Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: miutils.dll | Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: miutils.dll | Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: 4.2.Quotation.exe.36ca900.2.raw.unpack, gnUSCu92R6bF7qGVZD.cs | High entropy of concatenated method names: 'RZBvgHWrZL', 'xlOvR7y92r', 'NT1vmu1aHi', 'gXFvF3uq5K', 'TafvBRPwMr', 'l5xv5AV5cU', 'eoRvrWsX6j', 'Aj0veL1KGO', 'DxGv1hZpCM', 'PaEvuMCsYg' |
Source: 4.2.Quotation.exe.36ca900.2.raw.unpack, eHT1T75IHvJ8sOUE38.cs | High entropy of concatenated method names: 'uqPEeKOPkI', 'am7EuHBoh6', 'P9jYwxEqW7', 'IL6YsGuJXR', 'cM7EDkbJ4F', 'y2PEi7xAbg', 'xgfEJr8alV', 'AHvEg7Ssvp', 'zHoEREL7AC', 'WKWEm8bM9X' |
Source: 4.2.Quotation.exe.36ca900.2.raw.unpack, LRZpgcvSu5EnCVpLXd.cs | High entropy of concatenated method names: 'Dispose', 'nTHs1YPDXJ', 'YcShngZIac', 'uBB0g0oNLZ', 'it3sueMDTU', 'tCvszwHlNA', 'ProcessDialogKey', 'Dfvhwa4LsD', 'xshhs3dIvB', 'K0PhhJJYhF' |
Source: 4.2.Quotation.exe.36ca900.2.raw.unpack, QW44ZNssmHdh1ViQKBq.cs | High entropy of concatenated method names: 'UMlMuE16JM', 'E9BMzdNXRO', 'rGhAwRq17H', 'Gw4Ask9hkv', 'oCdAhIYP8U', 'volALcxjfj', 'SRXAXUnVWi', 'S08ATEH1MK', 'YdMAtg4Hw3', 'KsdAvkMx9s' |
Source: 4.2.Quotation.exe.36ca900.2.raw.unpack, j8l8X3hGl6YEdJptKd.cs | High entropy of concatenated method names: 'aQ9bNUbPi', 'xne2YxFQw', 'gcUSLjEdW', 'm0FqZlYQj', 't6kHxmPOn', 'SmxIE5jlu', 'vtBQorYgb92uamuWtY', 'vLx0XoaIOkl1LbuvmQ', 'F60YCBCvT', 'lkaMEtehl' |
Source: 4.2.Quotation.exe.36ca900.2.raw.unpack, hSEuaEN37iorj9y7aG.cs | High entropy of concatenated method names: 'DCgC02o78d', 'IfTCZ1Jeh5', 'EsCCbnIYoY', 'Av0C26uQYx', 'k7sC8bVpvS', 'rd1CSH3WQ3', 'UiuCqnndvO', 'mMFC99o929', 'xyGCHGpXdU', 'MogCIZLFjv' |
Source: 4.2.Quotation.exe.36ca900.2.raw.unpack, bMPlLSJ9RqY9YkWwgi.cs | High entropy of concatenated method names: 'Ixm69MkUSq', 'oDL6HAd7EL', 'd77639gl9q', 'qtZ6nOfTwV', 'EnD6UD3LpM', 'Wcx6lvV3AB', 'C386OpvWv6', 'vHL6ayDFjl', 'nUe64kDd0m', 'DD26DmkAP5' |
Source: 4.2.Quotation.exe.36ca900.2.raw.unpack, WYve84rJfGTHYPDXJy.cs | High entropy of concatenated method names: 'Q87KfC9Q5J', 'tcIKEMq3ff', 'DiSKK8fJ7O', 'mprKA0VtjZ', 'rsYKob0KOb', 'OM6K7lSujQ', 'Dispose', 'AhUYtQNqQ2', 'oFfYv9yIsE', 'lbtYpomW2W' |
Source: 4.2.Quotation.exe.36ca900.2.raw.unpack, WTq2RLX5BngG5eQIvd.cs | High entropy of concatenated method names: 'BdpsCnUSCu', 'AR6sQbF7qG', 'egKsxywxRY', 'WhgsG3vRsu', 'xoasfw29H5', 'rPssjcO4fs', 'JfnmA6t9hWGbTPEyjA', 'fnkh9956AZ0UKogC56', 'IGwssDgf0e', 'M7csLN8Xsc' |
Source: 4.2.Quotation.exe.36ca900.2.raw.unpack, qn8HZVzKsW0qKGJ613.cs | High entropy of concatenated method names: 'CUBMSJRJL1', 'KfJM9WX3Td', 'r37MHf4oJk', 'v3LM3QJr3I', 'Y07Mn5Y53A', 'bmCMUOg4Rk', 'D7LMlr8SD1', 'b0tM7vgLvJ', 'x4NM0wLByi', 'dBVMZjhM4i' |
Source: 4.2.Quotation.exe.36ca900.2.raw.unpack, ocCpNTHgKywxRYehg3.cs | High entropy of concatenated method names: 'xQQp2aKZ7i', 'TqppSGNarO', 'sZxp9eByrx', 'FtYpHegpef', 'w9Epf7EH6W', 'fhRpjXqRiL', 'NwYpEpamqu', 'gEFpY4tgNR', 'dwnpKVYynT', 'Un6pMbURZQ' |
Source: 4.2.Quotation.exe.36ca900.2.raw.unpack, ReP8oDsXm93lbyEPNK3.cs | High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'gh8dKZJin4', 'AjAdM1VVUV', 'q40dAQbKZp', 'WoWddYluaU', 'S9edoywQ6Y', 'GOAdc4WRce', 'vc2d7Mo6pG' |
Source: 4.2.Quotation.exe.36ca900.2.raw.unpack, ga4LsD17sh3dIvBW0P.cs | High entropy of concatenated method names: 'euFK3AJvIK', 'gAQKn4yPFh', 'xRAKPGHQ0c', 'tO8KUbOwFD', 'CuxKlGCpuF', 'b9FKWJbYXA', 'LWBKOJwSGY', 'Nt8KadB2NL', 'CyeKNc1WHf', 'FkgK4lK80u' |
Source: 4.2.Quotation.exe.36ca900.2.raw.unpack, QJYhF1uiac9nFLm6lX.cs | High entropy of concatenated method names: 'P2DMpUgYNC', 'dQxMVICshR', 'qabMykibEk', 'e6BMC40k5D', 'f4VMKk3d0P', 'pRZMQs1X8o', 'Next', 'Next', 'Next', 'NextBytes' |
Source: 4.2.Quotation.exe.36ca900.2.raw.unpack, TXZq00FS1mocMSXYsH.cs | High entropy of concatenated method names: 'wTQExmsCwq', 'gB0EGWpg65', 'ToString', 'i2oEt6TCpb', 'c6SEvwp0Mo', 'LP6Epv9BAv', 'AfPEVXTIkk', 'xt8EyAgNmR', 'wDXECNLhmv', 'ixDEQcj4FM' |
Source: 4.2.Quotation.exe.36ca900.2.raw.unpack, gRsuFjIHd2KsS7oaw2.cs | High entropy of concatenated method names: 'tADV8SgBry', 'fGHVqAlww0', 'uoxpPYvMGy', 'WRYpUjJvcN', 'M0Lplud6J9', 'zbspW7HKfD', 'cwApOTenMY', 'rvtpaWTB8t', 'nUNpNWZ0Db', 'otyp42YsyN' |
Source: 4.2.Quotation.exe.36ca900.2.raw.unpack, Q3LnG9p2R2MHwXGks7.cs | High entropy of concatenated method names: 'EditValue', 'GetEditStyle', 's7Wh1ElIwI', 'imvhuUsQ2X', 'RAWhzTeJbq', 'HJ1Lwy2Vuj', 'jn2LsT6CEc', 'cEXLhstItM', 'DlnLLjDkI5', 'xlM3bryX8kL8xjvJrdq' |
Source: 4.2.Quotation.exe.36ca900.2.raw.unpack, DZAHqGOtiyo1Bs9Aqg.cs | High entropy of concatenated method names: 'NToCtMuJci', 'fB2CpoDlRU', 'vroCy1ZOoc', 'xpIyu7yao1', 'FDTyzTDX2X', 'ptKCw4nawu', 'T9ECsMvs0w', 'LYAChwMxxX', 'ofUCLskjDh', 'eAOCXuYNCL' |
Source: 4.2.Quotation.exe.36ca900.2.raw.unpack, m11KElQoaGTS6ScoKL.cs | High entropy of concatenated method names: 'NjOLTaPOyj', 'TL6LtheLGW', 'TY2Lv0f7MU', 'IIFLpJVUh2', 'Bx1LVmWy9l', 'PxjLyerkmU', 'KwdLCa7TP2', 'KNPLQPyPMa', 'J1HLk9RnRg', 'CD3LxwZQFt' |
Source: 4.2.Quotation.exe.36ca900.2.raw.unpack, f57wJhmT7YHopwyBIw.cs | High entropy of concatenated method names: 'ToString', 'zTWjDTwTdM', 'gb1jnHdb23', 'eoljPQaFCW', 'qtYjUG9e5W', 'zjdjlWUoqp', 'bvJjWImEVo', 'NfHjOLveVS', 'NJsja1Crx0', 'awwjNOu6Wm' |
Source: 4.2.Quotation.exe.36ca900.2.raw.unpack, FW0hhQgAOEfCCH3hhp.cs | High entropy of concatenated method names: 'mAaf44AjMT', 'cSDfiI2kd2', 'lG6fg5KQLV', 'o5qfRJLTGC', 'lRnfnpxZhA', 'KymfPpEcPv', 'CwIfUHK9aa', 'GSkflt023Q', 'TnffWHGgPV', 'zSGfO3eLlI' |
Source: 4.2.Quotation.exe.36ca900.2.raw.unpack, EH5YPs3cO4fsFQ2Gft.cs | High entropy of concatenated method names: 'dQKyTDiwwf', 'kn8yvGbmCH', 'FbWyV47XF9', 'OjSyCdeEiq', 'sjKyQEreog', 'QweVBJVIYc', 'fTAV5eoLDT', 'yoFVrSWL5s', 'l4HVea3sQ7', 'dq2V1dpHoQ' |
Source: 4.2.Quotation.exe.83a0000.5.raw.unpack, gnUSCu92R6bF7qGVZD.cs | High entropy of concatenated method names: 'RZBvgHWrZL', 'xlOvR7y92r', 'NT1vmu1aHi', 'gXFvF3uq5K', 'TafvBRPwMr', 'l5xv5AV5cU', 'eoRvrWsX6j', 'Aj0veL1KGO', 'DxGv1hZpCM', 'PaEvuMCsYg' |
Source: 4.2.Quotation.exe.83a0000.5.raw.unpack, eHT1T75IHvJ8sOUE38.cs | High entropy of concatenated method names: 'uqPEeKOPkI', 'am7EuHBoh6', 'P9jYwxEqW7', 'IL6YsGuJXR', 'cM7EDkbJ4F', 'y2PEi7xAbg', 'xgfEJr8alV', 'AHvEg7Ssvp', 'zHoEREL7AC', 'WKWEm8bM9X' |
Source: 4.2.Quotation.exe.83a0000.5.raw.unpack, LRZpgcvSu5EnCVpLXd.cs | High entropy of concatenated method names: 'Dispose', 'nTHs1YPDXJ', 'YcShngZIac', 'uBB0g0oNLZ', 'it3sueMDTU', 'tCvszwHlNA', 'ProcessDialogKey', 'Dfvhwa4LsD', 'xshhs3dIvB', 'K0PhhJJYhF' |
Source: 4.2.Quotation.exe.83a0000.5.raw.unpack, QW44ZNssmHdh1ViQKBq.cs | High entropy of concatenated method names: 'UMlMuE16JM', 'E9BMzdNXRO', 'rGhAwRq17H', 'Gw4Ask9hkv', 'oCdAhIYP8U', 'volALcxjfj', 'SRXAXUnVWi', 'S08ATEH1MK', 'YdMAtg4Hw3', 'KsdAvkMx9s' |
Source: 4.2.Quotation.exe.83a0000.5.raw.unpack, j8l8X3hGl6YEdJptKd.cs | High entropy of concatenated method names: 'aQ9bNUbPi', 'xne2YxFQw', 'gcUSLjEdW', 'm0FqZlYQj', 't6kHxmPOn', 'SmxIE5jlu', 'vtBQorYgb92uamuWtY', 'vLx0XoaIOkl1LbuvmQ', 'F60YCBCvT', 'lkaMEtehl' |
Source: 4.2.Quotation.exe.83a0000.5.raw.unpack, hSEuaEN37iorj9y7aG.cs | High entropy of concatenated method names: 'DCgC02o78d', 'IfTCZ1Jeh5', 'EsCCbnIYoY', 'Av0C26uQYx', 'k7sC8bVpvS', 'rd1CSH3WQ3', 'UiuCqnndvO', 'mMFC99o929', 'xyGCHGpXdU', 'MogCIZLFjv' |
Source: 4.2.Quotation.exe.83a0000.5.raw.unpack, bMPlLSJ9RqY9YkWwgi.cs | High entropy of concatenated method names: 'Ixm69MkUSq', 'oDL6HAd7EL', 'd77639gl9q', 'qtZ6nOfTwV', 'EnD6UD3LpM', 'Wcx6lvV3AB', 'C386OpvWv6', 'vHL6ayDFjl', 'nUe64kDd0m', 'DD26DmkAP5' |
Source: 4.2.Quotation.exe.83a0000.5.raw.unpack, WYve84rJfGTHYPDXJy.cs | High entropy of concatenated method names: 'Q87KfC9Q5J', 'tcIKEMq3ff', 'DiSKK8fJ7O', 'mprKA0VtjZ', 'rsYKob0KOb', 'OM6K7lSujQ', 'Dispose', 'AhUYtQNqQ2', 'oFfYv9yIsE', 'lbtYpomW2W' |
Source: 4.2.Quotation.exe.83a0000.5.raw.unpack, WTq2RLX5BngG5eQIvd.cs | High entropy of concatenated method names: 'BdpsCnUSCu', 'AR6sQbF7qG', 'egKsxywxRY', 'WhgsG3vRsu', 'xoasfw29H5', 'rPssjcO4fs', 'JfnmA6t9hWGbTPEyjA', 'fnkh9956AZ0UKogC56', 'IGwssDgf0e', 'M7csLN8Xsc' |
Source: 4.2.Quotation.exe.83a0000.5.raw.unpack, qn8HZVzKsW0qKGJ613.cs | High entropy of concatenated method names: 'CUBMSJRJL1', 'KfJM9WX3Td', 'r37MHf4oJk', 'v3LM3QJr3I', 'Y07Mn5Y53A', 'bmCMUOg4Rk', 'D7LMlr8SD1', 'b0tM7vgLvJ', 'x4NM0wLByi', 'dBVMZjhM4i' |
Source: 4.2.Quotation.exe.83a0000.5.raw.unpack, ocCpNTHgKywxRYehg3.cs | High entropy of concatenated method names: 'xQQp2aKZ7i', 'TqppSGNarO', 'sZxp9eByrx', 'FtYpHegpef', 'w9Epf7EH6W', 'fhRpjXqRiL', 'NwYpEpamqu', 'gEFpY4tgNR', 'dwnpKVYynT', 'Un6pMbURZQ' |
Source: 4.2.Quotation.exe.83a0000.5.raw.unpack, ReP8oDsXm93lbyEPNK3.cs | High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'gh8dKZJin4', 'AjAdM1VVUV', 'q40dAQbKZp', 'WoWddYluaU', 'S9edoywQ6Y', 'GOAdc4WRce', 'vc2d7Mo6pG' |
Source: 4.2.Quotation.exe.83a0000.5.raw.unpack, ga4LsD17sh3dIvBW0P.cs | High entropy of concatenated method names: 'euFK3AJvIK', 'gAQKn4yPFh', 'xRAKPGHQ0c', 'tO8KUbOwFD', 'CuxKlGCpuF', 'b9FKWJbYXA', 'LWBKOJwSGY', 'Nt8KadB2NL', 'CyeKNc1WHf', 'FkgK4lK80u' |
Source: 4.2.Quotation.exe.83a0000.5.raw.unpack, QJYhF1uiac9nFLm6lX.cs | High entropy of concatenated method names: 'P2DMpUgYNC', 'dQxMVICshR', 'qabMykibEk', 'e6BMC40k5D', 'f4VMKk3d0P', 'pRZMQs1X8o', 'Next', 'Next', 'Next', 'NextBytes' |
Source: 4.2.Quotation.exe.83a0000.5.raw.unpack, TXZq00FS1mocMSXYsH.cs | High entropy of concatenated method names: 'wTQExmsCwq', 'gB0EGWpg65', 'ToString', 'i2oEt6TCpb', 'c6SEvwp0Mo', 'LP6Epv9BAv', 'AfPEVXTIkk', 'xt8EyAgNmR', 'wDXECNLhmv', 'ixDEQcj4FM' |
Source: 4.2.Quotation.exe.83a0000.5.raw.unpack, gRsuFjIHd2KsS7oaw2.cs | High entropy of concatenated method names: 'tADV8SgBry', 'fGHVqAlww0', 'uoxpPYvMGy', 'WRYpUjJvcN', 'M0Lplud6J9', 'zbspW7HKfD', 'cwApOTenMY', 'rvtpaWTB8t', 'nUNpNWZ0Db', 'otyp42YsyN' |
Source: 4.2.Quotation.exe.83a0000.5.raw.unpack, Q3LnG9p2R2MHwXGks7.cs | High entropy of concatenated method names: 'EditValue', 'GetEditStyle', 's7Wh1ElIwI', 'imvhuUsQ2X', 'RAWhzTeJbq', 'HJ1Lwy2Vuj', 'jn2LsT6CEc', 'cEXLhstItM', 'DlnLLjDkI5', 'xlM3bryX8kL8xjvJrdq' |
Source: 4.2.Quotation.exe.83a0000.5.raw.unpack, DZAHqGOtiyo1Bs9Aqg.cs | High entropy of concatenated method names: 'NToCtMuJci', 'fB2CpoDlRU', 'vroCy1ZOoc', 'xpIyu7yao1', 'FDTyzTDX2X', 'ptKCw4nawu', 'T9ECsMvs0w', 'LYAChwMxxX', 'ofUCLskjDh', 'eAOCXuYNCL' |
Source: 4.2.Quotation.exe.83a0000.5.raw.unpack, m11KElQoaGTS6ScoKL.cs | High entropy of concatenated method names: 'NjOLTaPOyj', 'TL6LtheLGW', 'TY2Lv0f7MU', 'IIFLpJVUh2', 'Bx1LVmWy9l', 'PxjLyerkmU', 'KwdLCa7TP2', 'KNPLQPyPMa', 'J1HLk9RnRg', 'CD3LxwZQFt' |
Source: 4.2.Quotation.exe.83a0000.5.raw.unpack, f57wJhmT7YHopwyBIw.cs | High entropy of concatenated method names: 'ToString', 'zTWjDTwTdM', 'gb1jnHdb23', 'eoljPQaFCW', 'qtYjUG9e5W', 'zjdjlWUoqp', 'bvJjWImEVo', 'NfHjOLveVS', 'NJsja1Crx0', 'awwjNOu6Wm' |
Source: 4.2.Quotation.exe.83a0000.5.raw.unpack, FW0hhQgAOEfCCH3hhp.cs | High entropy of concatenated method names: 'mAaf44AjMT', 'cSDfiI2kd2', 'lG6fg5KQLV', 'o5qfRJLTGC', 'lRnfnpxZhA', 'KymfPpEcPv', 'CwIfUHK9aa', 'GSkflt023Q', 'TnffWHGgPV', 'zSGfO3eLlI' |
Source: 4.2.Quotation.exe.83a0000.5.raw.unpack, EH5YPs3cO4fsFQ2Gft.cs | High entropy of concatenated method names: 'dQKyTDiwwf', 'kn8yvGbmCH', 'FbWyV47XF9', 'OjSyCdeEiq', 'sjKyQEreog', 'QweVBJVIYc', 'fTAV5eoLDT', 'yoFVrSWL5s', 'l4HVea3sQ7', 'dq2V1dpHoQ' |
Source: C:\Users\user\Desktop\Quotation.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe TID: 1004 | Thread sleep time: -922337203685477s >= -30000s | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe TID: 7340 | Thread sleep time: -5534023222112862s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe TID: 7604 | Thread sleep count: 2477 > 30 | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe TID: 7604 | Thread sleep count: 7361 > 30 | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe TID: 7616 | Thread sleep count: 37 > 30 | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe TID: 7616 | Thread sleep time: -34126476536362649s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe TID: 7616 | Thread sleep time: -100000s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe TID: 7616 | Thread sleep time: -99890s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe TID: 7616 | Thread sleep time: -99781s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe TID: 7616 | Thread sleep time: -99672s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe TID: 7616 | Thread sleep time: -99563s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe TID: 7616 | Thread sleep time: -99453s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe TID: 7616 | Thread sleep time: -99344s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe TID: 7616 | Thread sleep time: -99234s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe TID: 7616 | Thread sleep time: -99125s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe TID: 7616 | Thread sleep time: -99015s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe TID: 7616 | Thread sleep time: -98906s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe TID: 7616 | Thread sleep time: -98797s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe TID: 7616 | Thread sleep time: -98687s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe TID: 7616 | Thread sleep time: -98578s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe TID: 7616 | Thread sleep time: -98469s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe TID: 7616 | Thread sleep time: -98359s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe TID: 7616 | Thread sleep time: -98250s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe TID: 7616 | Thread sleep time: -98139s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe TID: 7616 | Thread sleep time: -98031s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe TID: 7616 | Thread sleep time: -97914s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe TID: 7616 | Thread sleep time: -97812s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe TID: 7616 | Thread sleep time: -97703s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe TID: 7616 | Thread sleep time: -97435s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe TID: 7616 | Thread sleep time: -97272s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe TID: 7616 | Thread sleep time: -97126s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe TID: 7616 | Thread sleep time: -96719s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe TID: 7616 | Thread sleep time: -96406s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe TID: 7616 | Thread sleep time: -96176s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe TID: 7616 | Thread sleep time: -96047s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe TID: 7616 | Thread sleep time: -95937s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe TID: 7616 | Thread sleep time: -95827s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe TID: 7616 | Thread sleep time: -95718s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe TID: 7616 | Thread sleep time: -95609s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe TID: 7616 | Thread sleep time: -95500s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe TID: 7616 | Thread sleep time: -95391s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe TID: 7616 | Thread sleep time: -95266s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe TID: 7616 | Thread sleep time: -95155s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe TID: 7616 | Thread sleep time: -95047s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe TID: 7616 | Thread sleep time: -94937s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe TID: 7616 | Thread sleep time: -94828s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe TID: 7616 | Thread sleep time: -94719s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe TID: 7616 | Thread sleep time: -94609s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe TID: 7616 | Thread sleep time: -94499s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe TID: 7616 | Thread sleep time: -94390s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe TID: 7616 | Thread sleep time: -94281s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe TID: 7616 | Thread sleep time: -94172s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe TID: 7616 | Thread sleep time: -94062s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe TID: 7616 | Thread sleep time: -93950s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe TID: 7616 | Thread sleep time: -93844s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe TID: 7616 | Thread sleep time: -93733s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe TID: 7616 | Thread sleep time: -93617s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Thread delayed: delay time: 100000 | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Thread delayed: delay time: 99890 | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Thread delayed: delay time: 99781 | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Thread delayed: delay time: 99672 | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Thread delayed: delay time: 99563 | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Thread delayed: delay time: 99453 | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Thread delayed: delay time: 99344 | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Thread delayed: delay time: 99234 | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Thread delayed: delay time: 99125 | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Thread delayed: delay time: 99015 | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Thread delayed: delay time: 98906 | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Thread delayed: delay time: 98797 | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Thread delayed: delay time: 98687 | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Thread delayed: delay time: 98578 | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Thread delayed: delay time: 98469 | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Thread delayed: delay time: 98359 | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Thread delayed: delay time: 98250 | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Thread delayed: delay time: 98139 | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Thread delayed: delay time: 98031 | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Thread delayed: delay time: 97914 | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Thread delayed: delay time: 97812 | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Thread delayed: delay time: 97703 | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Thread delayed: delay time: 97435 | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Thread delayed: delay time: 97272 | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Thread delayed: delay time: 97126 | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Thread delayed: delay time: 96719 | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Thread delayed: delay time: 96406 | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Thread delayed: delay time: 96176 | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Thread delayed: delay time: 96047 | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Thread delayed: delay time: 95937 | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Thread delayed: delay time: 95827 | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Thread delayed: delay time: 95718 | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Thread delayed: delay time: 95609 | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Thread delayed: delay time: 95500 | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Thread delayed: delay time: 95391 | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Thread delayed: delay time: 95266 | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Thread delayed: delay time: 95155 | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Thread delayed: delay time: 95047 | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Thread delayed: delay time: 94937 | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Thread delayed: delay time: 94828 | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Thread delayed: delay time: 94719 | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Thread delayed: delay time: 94609 | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Thread delayed: delay time: 94499 | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Thread delayed: delay time: 94390 | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Thread delayed: delay time: 94281 | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Thread delayed: delay time: 94172 | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Thread delayed: delay time: 94062 | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Thread delayed: delay time: 93950 | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Thread delayed: delay time: 93844 | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Thread delayed: delay time: 93733 | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Thread delayed: delay time: 93617 | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Queries volume information: C:\Users\user\Desktop\Quotation.exe VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Queries volume information: C:\Windows\Fonts\GOTHIC.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Queries volume information: C:\Windows\Fonts\GOTHICI.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Queries volume information: C:\Windows\Fonts\GOTHICB.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Queries volume information: C:\Windows\Fonts\GOTHICBI.TTF VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\ VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-GroupPolicy-ClientTools-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-AppManagement-AppV-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\Microsoft.Management.Infrastructure.Native\v4.0_1.0.0.0__31bf3856ad364e35\Microsoft.Management.Infrastructure.Native.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\AppvClient\Microsoft.AppV.AppVClientPowerShell.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1865.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-WOW64-Package~31bf3856ad364e35~amd64~en-GB~10.0.19041.1.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\BitLocker\Microsoft.BitLocker.Structures.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management\v4.0_3.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Management.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Queries volume information: C:\Users\user\Desktop\Quotation.exe VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Security\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Security.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Quotation.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation | Jump to behavior |