Source: C:\Users\user\Desktop\hesaphareket.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Section loaded: dwrite.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Section loaded: windowscodecs.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Section loaded: edputil.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Section loaded: windows.staterepositoryps.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Section loaded: appresolver.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Section loaded: bcp47langs.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Section loaded: slc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Section loaded: sppc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Section loaded: onecorecommonproxystub.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Section loaded: onecoreuapcommonproxystub.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: atl.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: msisip.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wshext.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: appxsip.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: opcservices.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: secur32.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: microsoft.management.infrastructure.native.unmanaged.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: mi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: miutils.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wmidcom.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: dpapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wbemcomn.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Section loaded: wbemcomn.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Section loaded: vaultcli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Section loaded: rasapi32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Section loaded: rasman.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Section loaded: rtutils.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Section loaded: dhcpcsvc6.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Section loaded: dhcpcsvc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Section loaded: dnsapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Section loaded: winnsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Section loaded: rasadhlp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Section loaded: fwpuclnt.dll | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Section loaded: edputil.dll | Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: fastprox.dll | Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: ncobjapi.dll | Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: wbemcomn.dll | Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: wbemcomn.dll | Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: mpclient.dll | Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: wmitomi.dll | Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: mi.dll | Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: miutils.dll | Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: miutils.dll | Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: 0.2.hesaphareket.exe.3867b70.1.raw.unpack, DB0rNXPAoLV4WyNjdF.cs | High entropy of concatenated method names: 'EditValue', 'GetEditStyle', 'Btx9rWtq5b', 'uk39cmRRUK', 'nVq9zCv56U', 'LhcEoH7eWo', 'VDbEl4vON2', 'Q1OE9ahaST', 'P8AEED9J2P', 'Th6iW7dHfFQ6X7FOrT1' |
Source: 0.2.hesaphareket.exe.3867b70.1.raw.unpack, W6NSRHll0U5bw9XC3tb.cs | High entropy of concatenated method names: 'LHTZcPLMbY', 'YT6ZzHsRVl', 'WILdoL70ZS', 'vp2dlVI7lK', 'cWLd9J2e7Z', 'zFpdEYVYkx', 'BwJdF02pI2', 'f6qd0Yo2CR', 'WgkdbJ50Ie', 'EqkdpdRWoK' |
Source: 0.2.hesaphareket.exe.3867b70.1.raw.unpack, mOIpKGlo1GpcENTKgBe.cs | High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'GM5ZXgwT8a', 'fCsZffsj7E', 'g8mZ4R0GMB', 'YcIZeapJEL', 'GaCZWrRB3W', 'w5WZKryDVk', 'Q5PZHKI12j' |
Source: 0.2.hesaphareket.exe.3867b70.1.raw.unpack, U5httJGmuF5DPKTAnl.cs | High entropy of concatenated method names: 'WODpeODi3m', 'GU8pWccfKI', 'apepK3ZAWY', 'GclpHrqgKp', 'FGCpUYRnmL', 'tpIp8ovbEr', 'lcKpiIp4fD', 'buCpkHPPDM', 'hYiprDfCyQ', 'MLGpcFOgmI' |
Source: 0.2.hesaphareket.exe.3867b70.1.raw.unpack, RLmREhrq916NQ96X43.cs | High entropy of concatenated method names: 'EHQ1Sxwyti', 'Xga12LXQfU', 'U121N6YEQG', 'B8G1Qh1yH1', 'QUu1q9YoU5', 'Cde15S03Wo', 'Sfv1V00Agu', 'GIx1O5w1nW', 'VVs1DPEU4G', 'mmN17HELdn' |
Source: 0.2.hesaphareket.exe.3867b70.1.raw.unpack, lexLvIJdiNy80Kiycs.cs | High entropy of concatenated method names: 'EWWPBpBiCK', 'Hk8PydWYOm', 'mWoPG0mI62', 'NHKPJtTT9m', 'VI7PnSMCtY', 'rlMPuoBInv', 'Ya6PwSLbbs', 'zd2PIC8V70', 'b5OP1eN3UF', 'qHxPZxbwkP' |
Source: 0.2.hesaphareket.exe.3867b70.1.raw.unpack, aeCmgZzr3lXS43K00w.cs | High entropy of concatenated method names: 'xckZyDXYyE', 'DyWZG6Mvsu', 'puYZJpgQxs', 'IdEZSDsMwh', 'k3NZ29vhln', 'EKVZQy3SqN', 'FyAZqixl5F', 'dXsZa94APC', 'X2ZZCpaORR', 'fdhZYv6asd' |
Source: 0.2.hesaphareket.exe.3867b70.1.raw.unpack, Xdi37dj88nmLQeMQpH.cs | High entropy of concatenated method names: 'MtvE0N5Uva', 'dPsEbaNTHk', 'j8mEpuSoav', 'x5mEPiWnjc', 'SttEtgqnFw', 'pkCE6QwIfe', 'NhNELQ5kc4', 'MRGEjRuQWx', 'MQYE3V4rXg', 'j3mETGE6WI' |
Source: 0.2.hesaphareket.exe.3867b70.1.raw.unpack, ieSK5kStrek0doClXM.cs | High entropy of concatenated method names: 'uWQ60t4aX5', 'Kst6pS8WTS', 'RvU6tFa134', 'EQX6LjqvX2', 'WaV6jpo3wX', 'oohtUKCr8N', 'oCIt8YHeot', 'CyNtiZFkEO', 'z26tk66smp', 'jdJtrAI7BE' |
Source: 0.2.hesaphareket.exe.3867b70.1.raw.unpack, jcgak2caNw4QSExh2A.cs | High entropy of concatenated method names: 'MyLZPiu4sj', 'M0rZtTVits', 'NwlZ6wuld5', 'HyBZLTsctw', 'aOZZ1SEAQE', 'quGZjPlNBC', 'Next', 'Next', 'Next', 'NextBytes' |
Source: 0.2.hesaphareket.exe.3867b70.1.raw.unpack, p05yAfxmLTNU99P8HE.cs | High entropy of concatenated method names: 'He0tm93yN4', 'KxntAQlgIe', 'mT1PN91UAd', 'ELmPQSAsDj', 'rJcPq9XBrE', 'U4GP5VnYBe', 'Mp8PVWqfeg', 'fstPOWhkM1', 'J3CPDaUpnl', 'T9bP7rba57' |
Source: 0.2.hesaphareket.exe.3867b70.1.raw.unpack, mOLxEjDHWYc8XOHddC.cs | High entropy of concatenated method names: 'yd9LCR8u1n', 'U1cLYEpKjY', 'zAyLgVFVd2', 'RkwLBrvS1W', 'TGJLmUihiN', 'eqfLyMprRc', 'gKcLAnXMZa', 'SXdLG5KSjJ', 'B89LJ0PGoI', 'BHmLxfYVLU' |
Source: 0.2.hesaphareket.exe.3867b70.1.raw.unpack, hjyEGc4iSUQJitRU4D.cs | High entropy of concatenated method names: 'hEohGFWLcN', 'TEuhJPQGQ5', 'WWohSIhZit', 'uPkh2qFAi8', 'isjhQiZQTY', 'rpHhqXXaaK', 'JiGhVyilRt', 'tGGhOJTOYq', 'rCbh7Ulimm', 'jAphXfmpak' |
Source: 0.2.hesaphareket.exe.3867b70.1.raw.unpack, SlnkX0H8ePrsk99m6e.cs | High entropy of concatenated method names: 'NG5wTXIC85', 'FBXwvQBpDc', 'ToString', 'w4uwbey0gE', 'EZlwpqQXuY', 'Sj2wP3bmof', 'qlbwtKWbM7', 'Y1Zw6bta4Q', 'clSwLgsdHr', 'RRUwjchwIp' |
Source: 0.2.hesaphareket.exe.3867b70.1.raw.unpack, ibdPOaiOutWPyPGkXx.cs | High entropy of concatenated method names: 'OKV1nk4AnC', 'nHY1wiAMmF', 'f7o113tFhg', 'cZL1dkG9cI', 'wI01sowF27', 'S571axP4Bu', 'Dispose', 'DcdIbSkpup', 'xHeIptMuaX', 'Wa0IPHpr2o' |
Source: 0.2.hesaphareket.exe.3867b70.1.raw.unpack, hDpkvMpdbBM5WBbgWJ.cs | High entropy of concatenated method names: 'Dispose', 'hWPlryPGkX', 'EwI92jJoDR', 'zWWNV9QVqo', 'F4plcP3BnE', 'RaTlz0phgO', 'ProcessDialogKey', 'pbe9oLmREh', 'J919l6NQ96', 'O4399Lcgak' |
Source: 0.2.hesaphareket.exe.3867b70.1.raw.unpack, fXVa8kFOIcYK3XNYlr.cs | High entropy of concatenated method names: 'HqUlL5httJ', 'BuFlj5DPKT', 'qdilTNy80K', 'Vyclvsu05y', 'bP8lnHE6eS', 'S5klutrek0', 'DgqkD1NxNqBfkUtTIa', 'rmDoFBmw3a6ero2pC3', 'E9HllxmuOj', 'VP7lENrISR' |
Source: 0.2.hesaphareket.exe.3867b70.1.raw.unpack, TJDjG497EqNjuMFx6Z.cs | High entropy of concatenated method names: 'u3UgKC4yB', 'YlqBxendn', 'Tu0ybaZt0', 'US0AR1lmQ', 'WK3JQNcv9', 'nYwxcukjr', 'qSBeSl7BZjVK8weRGs', 'suxM4FpgqBCmf8p6hc', 'ISfsPv4GoKOnR7gMrQ', 'vSIIZ4ETe' |
Source: 0.2.hesaphareket.exe.3867b70.1.raw.unpack, Oxe9Fwe6IFE8xU8ZF3.cs | High entropy of concatenated method names: 'aaQn7AefGP', 'YqHnfZPywl', 'JXKneBAPRi', 'MAlnWLAchr', 'mRLn2VKa0T', 'OMCnNCCo3V', 'KbxnQygTqc', 'Cfxnq8hU3l', 'FlJn5db8A1', 'LREnV8Vt6x' |
Source: 0.2.hesaphareket.exe.3867b70.1.raw.unpack, uvYZ8UlFZYq1wXdFnMx.cs | High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'Lu0M1Flf3i', 'vMdMZPKKkW', 'hLjMdAaFYk', 'gtJMMRYbjp', 'fZcMsUjIKA', 'WPmMRPuJZy', 'WItMaiMF0P' |
Source: 0.2.hesaphareket.exe.7460000.4.raw.unpack, DB0rNXPAoLV4WyNjdF.cs | High entropy of concatenated method names: 'EditValue', 'GetEditStyle', 'Btx9rWtq5b', 'uk39cmRRUK', 'nVq9zCv56U', 'LhcEoH7eWo', 'VDbEl4vON2', 'Q1OE9ahaST', 'P8AEED9J2P', 'Th6iW7dHfFQ6X7FOrT1' |
Source: 0.2.hesaphareket.exe.7460000.4.raw.unpack, W6NSRHll0U5bw9XC3tb.cs | High entropy of concatenated method names: 'LHTZcPLMbY', 'YT6ZzHsRVl', 'WILdoL70ZS', 'vp2dlVI7lK', 'cWLd9J2e7Z', 'zFpdEYVYkx', 'BwJdF02pI2', 'f6qd0Yo2CR', 'WgkdbJ50Ie', 'EqkdpdRWoK' |
Source: 0.2.hesaphareket.exe.7460000.4.raw.unpack, mOIpKGlo1GpcENTKgBe.cs | High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'GM5ZXgwT8a', 'fCsZffsj7E', 'g8mZ4R0GMB', 'YcIZeapJEL', 'GaCZWrRB3W', 'w5WZKryDVk', 'Q5PZHKI12j' |
Source: 0.2.hesaphareket.exe.7460000.4.raw.unpack, U5httJGmuF5DPKTAnl.cs | High entropy of concatenated method names: 'WODpeODi3m', 'GU8pWccfKI', 'apepK3ZAWY', 'GclpHrqgKp', 'FGCpUYRnmL', 'tpIp8ovbEr', 'lcKpiIp4fD', 'buCpkHPPDM', 'hYiprDfCyQ', 'MLGpcFOgmI' |
Source: 0.2.hesaphareket.exe.7460000.4.raw.unpack, RLmREhrq916NQ96X43.cs | High entropy of concatenated method names: 'EHQ1Sxwyti', 'Xga12LXQfU', 'U121N6YEQG', 'B8G1Qh1yH1', 'QUu1q9YoU5', 'Cde15S03Wo', 'Sfv1V00Agu', 'GIx1O5w1nW', 'VVs1DPEU4G', 'mmN17HELdn' |
Source: 0.2.hesaphareket.exe.7460000.4.raw.unpack, lexLvIJdiNy80Kiycs.cs | High entropy of concatenated method names: 'EWWPBpBiCK', 'Hk8PydWYOm', 'mWoPG0mI62', 'NHKPJtTT9m', 'VI7PnSMCtY', 'rlMPuoBInv', 'Ya6PwSLbbs', 'zd2PIC8V70', 'b5OP1eN3UF', 'qHxPZxbwkP' |
Source: 0.2.hesaphareket.exe.7460000.4.raw.unpack, aeCmgZzr3lXS43K00w.cs | High entropy of concatenated method names: 'xckZyDXYyE', 'DyWZG6Mvsu', 'puYZJpgQxs', 'IdEZSDsMwh', 'k3NZ29vhln', 'EKVZQy3SqN', 'FyAZqixl5F', 'dXsZa94APC', 'X2ZZCpaORR', 'fdhZYv6asd' |
Source: 0.2.hesaphareket.exe.7460000.4.raw.unpack, Xdi37dj88nmLQeMQpH.cs | High entropy of concatenated method names: 'MtvE0N5Uva', 'dPsEbaNTHk', 'j8mEpuSoav', 'x5mEPiWnjc', 'SttEtgqnFw', 'pkCE6QwIfe', 'NhNELQ5kc4', 'MRGEjRuQWx', 'MQYE3V4rXg', 'j3mETGE6WI' |
Source: 0.2.hesaphareket.exe.7460000.4.raw.unpack, ieSK5kStrek0doClXM.cs | High entropy of concatenated method names: 'uWQ60t4aX5', 'Kst6pS8WTS', 'RvU6tFa134', 'EQX6LjqvX2', 'WaV6jpo3wX', 'oohtUKCr8N', 'oCIt8YHeot', 'CyNtiZFkEO', 'z26tk66smp', 'jdJtrAI7BE' |
Source: 0.2.hesaphareket.exe.7460000.4.raw.unpack, jcgak2caNw4QSExh2A.cs | High entropy of concatenated method names: 'MyLZPiu4sj', 'M0rZtTVits', 'NwlZ6wuld5', 'HyBZLTsctw', 'aOZZ1SEAQE', 'quGZjPlNBC', 'Next', 'Next', 'Next', 'NextBytes' |
Source: 0.2.hesaphareket.exe.7460000.4.raw.unpack, p05yAfxmLTNU99P8HE.cs | High entropy of concatenated method names: 'He0tm93yN4', 'KxntAQlgIe', 'mT1PN91UAd', 'ELmPQSAsDj', 'rJcPq9XBrE', 'U4GP5VnYBe', 'Mp8PVWqfeg', 'fstPOWhkM1', 'J3CPDaUpnl', 'T9bP7rba57' |
Source: 0.2.hesaphareket.exe.7460000.4.raw.unpack, mOLxEjDHWYc8XOHddC.cs | High entropy of concatenated method names: 'yd9LCR8u1n', 'U1cLYEpKjY', 'zAyLgVFVd2', 'RkwLBrvS1W', 'TGJLmUihiN', 'eqfLyMprRc', 'gKcLAnXMZa', 'SXdLG5KSjJ', 'B89LJ0PGoI', 'BHmLxfYVLU' |
Source: 0.2.hesaphareket.exe.7460000.4.raw.unpack, hjyEGc4iSUQJitRU4D.cs | High entropy of concatenated method names: 'hEohGFWLcN', 'TEuhJPQGQ5', 'WWohSIhZit', 'uPkh2qFAi8', 'isjhQiZQTY', 'rpHhqXXaaK', 'JiGhVyilRt', 'tGGhOJTOYq', 'rCbh7Ulimm', 'jAphXfmpak' |
Source: 0.2.hesaphareket.exe.7460000.4.raw.unpack, SlnkX0H8ePrsk99m6e.cs | High entropy of concatenated method names: 'NG5wTXIC85', 'FBXwvQBpDc', 'ToString', 'w4uwbey0gE', 'EZlwpqQXuY', 'Sj2wP3bmof', 'qlbwtKWbM7', 'Y1Zw6bta4Q', 'clSwLgsdHr', 'RRUwjchwIp' |
Source: 0.2.hesaphareket.exe.7460000.4.raw.unpack, ibdPOaiOutWPyPGkXx.cs | High entropy of concatenated method names: 'OKV1nk4AnC', 'nHY1wiAMmF', 'f7o113tFhg', 'cZL1dkG9cI', 'wI01sowF27', 'S571axP4Bu', 'Dispose', 'DcdIbSkpup', 'xHeIptMuaX', 'Wa0IPHpr2o' |
Source: 0.2.hesaphareket.exe.7460000.4.raw.unpack, hDpkvMpdbBM5WBbgWJ.cs | High entropy of concatenated method names: 'Dispose', 'hWPlryPGkX', 'EwI92jJoDR', 'zWWNV9QVqo', 'F4plcP3BnE', 'RaTlz0phgO', 'ProcessDialogKey', 'pbe9oLmREh', 'J919l6NQ96', 'O4399Lcgak' |
Source: 0.2.hesaphareket.exe.7460000.4.raw.unpack, fXVa8kFOIcYK3XNYlr.cs | High entropy of concatenated method names: 'HqUlL5httJ', 'BuFlj5DPKT', 'qdilTNy80K', 'Vyclvsu05y', 'bP8lnHE6eS', 'S5klutrek0', 'DgqkD1NxNqBfkUtTIa', 'rmDoFBmw3a6ero2pC3', 'E9HllxmuOj', 'VP7lENrISR' |
Source: 0.2.hesaphareket.exe.7460000.4.raw.unpack, TJDjG497EqNjuMFx6Z.cs | High entropy of concatenated method names: 'u3UgKC4yB', 'YlqBxendn', 'Tu0ybaZt0', 'US0AR1lmQ', 'WK3JQNcv9', 'nYwxcukjr', 'qSBeSl7BZjVK8weRGs', 'suxM4FpgqBCmf8p6hc', 'ISfsPv4GoKOnR7gMrQ', 'vSIIZ4ETe' |
Source: 0.2.hesaphareket.exe.7460000.4.raw.unpack, Oxe9Fwe6IFE8xU8ZF3.cs | High entropy of concatenated method names: 'aaQn7AefGP', 'YqHnfZPywl', 'JXKneBAPRi', 'MAlnWLAchr', 'mRLn2VKa0T', 'OMCnNCCo3V', 'KbxnQygTqc', 'Cfxnq8hU3l', 'FlJn5db8A1', 'LREnV8Vt6x' |
Source: 0.2.hesaphareket.exe.7460000.4.raw.unpack, uvYZ8UlFZYq1wXdFnMx.cs | High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'Lu0M1Flf3i', 'vMdMZPKKkW', 'hLjMdAaFYk', 'gtJMMRYbjp', 'fZcMsUjIKA', 'WPmMRPuJZy', 'WItMaiMF0P' |
Source: C:\Users\user\Desktop\hesaphareket.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Thread delayed: delay time: 1200000 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Thread delayed: delay time: 1199875 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Thread delayed: delay time: 1199766 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Thread delayed: delay time: 1199641 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Thread delayed: delay time: 1199516 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Thread delayed: delay time: 1199406 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Thread delayed: delay time: 1199297 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Thread delayed: delay time: 1199188 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Thread delayed: delay time: 1199063 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Thread delayed: delay time: 1198952 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Thread delayed: delay time: 1198828 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Thread delayed: delay time: 1198719 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Thread delayed: delay time: 1198609 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Thread delayed: delay time: 1198498 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Thread delayed: delay time: 1198390 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Thread delayed: delay time: 1198281 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Thread delayed: delay time: 1198147 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Thread delayed: delay time: 1198004 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Thread delayed: delay time: 1197844 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Thread delayed: delay time: 1197734 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Thread delayed: delay time: 1197610 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Thread delayed: delay time: 1197485 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Thread delayed: delay time: 1197375 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Thread delayed: delay time: 1197235 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Thread delayed: delay time: 1197125 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Thread delayed: delay time: 1197016 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Thread delayed: delay time: 1196906 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Thread delayed: delay time: 1196797 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Thread delayed: delay time: 1196688 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Thread delayed: delay time: 1196578 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Thread delayed: delay time: 1196465 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Thread delayed: delay time: 1196359 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Thread delayed: delay time: 1196250 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Thread delayed: delay time: 1196141 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Thread delayed: delay time: 1196016 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Thread delayed: delay time: 1195906 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Thread delayed: delay time: 1195797 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Thread delayed: delay time: 1195687 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Thread delayed: delay time: 1195578 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Thread delayed: delay time: 1195465 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Thread delayed: delay time: 1195360 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Thread delayed: delay time: 1195249 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Thread delayed: delay time: 1195141 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Thread delayed: delay time: 1195016 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Thread delayed: delay time: 1194891 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Thread delayed: delay time: 1194781 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Thread delayed: delay time: 1194672 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Thread delayed: delay time: 1194562 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Thread delayed: delay time: 1194449 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Thread delayed: delay time: 1194344 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Thread delayed: delay time: 1194234 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe TID: 5472 | Thread sleep time: -922337203685477s >= -30000s | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe TID: 7372 | Thread sleep time: -8301034833169293s >= -30000s | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe TID: 7344 | Thread sleep time: -922337203685477s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe TID: 7572 | Thread sleep count: 39 > 30 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe TID: 7572 | Thread sleep time: -35971150943733603s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe TID: 7572 | Thread sleep time: -1200000s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe TID: 7576 | Thread sleep count: 1761 > 30 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe TID: 7572 | Thread sleep time: -1199875s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe TID: 7576 | Thread sleep count: 8084 > 30 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe TID: 7572 | Thread sleep time: -1199766s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe TID: 7572 | Thread sleep time: -1199641s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe TID: 7572 | Thread sleep time: -1199516s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe TID: 7572 | Thread sleep time: -1199406s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe TID: 7572 | Thread sleep time: -1199297s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe TID: 7572 | Thread sleep time: -1199188s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe TID: 7572 | Thread sleep time: -1199063s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe TID: 7572 | Thread sleep time: -1198952s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe TID: 7572 | Thread sleep time: -1198828s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe TID: 7572 | Thread sleep time: -1198719s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe TID: 7572 | Thread sleep time: -1198609s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe TID: 7572 | Thread sleep time: -1198498s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe TID: 7572 | Thread sleep time: -1198390s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe TID: 7572 | Thread sleep time: -1198281s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe TID: 7572 | Thread sleep time: -1198147s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe TID: 7572 | Thread sleep time: -1198004s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe TID: 7572 | Thread sleep time: -1197844s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe TID: 7572 | Thread sleep time: -1197734s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe TID: 7572 | Thread sleep time: -1197610s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe TID: 7572 | Thread sleep time: -1197485s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe TID: 7572 | Thread sleep time: -1197375s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe TID: 7572 | Thread sleep time: -1197235s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe TID: 7572 | Thread sleep time: -1197125s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe TID: 7572 | Thread sleep time: -1197016s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe TID: 7572 | Thread sleep time: -1196906s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe TID: 7572 | Thread sleep time: -1196797s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe TID: 7572 | Thread sleep time: -1196688s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe TID: 7572 | Thread sleep time: -1196578s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe TID: 7572 | Thread sleep time: -1196465s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe TID: 7572 | Thread sleep time: -1196359s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe TID: 7572 | Thread sleep time: -1196250s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe TID: 7572 | Thread sleep time: -1196141s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe TID: 7572 | Thread sleep time: -1196016s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe TID: 7572 | Thread sleep time: -1195906s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe TID: 7572 | Thread sleep time: -1195797s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe TID: 7572 | Thread sleep time: -1195687s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe TID: 7572 | Thread sleep time: -1195578s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe TID: 7572 | Thread sleep time: -1195465s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe TID: 7572 | Thread sleep time: -1195360s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe TID: 7572 | Thread sleep time: -1195249s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe TID: 7572 | Thread sleep time: -1195141s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe TID: 7572 | Thread sleep time: -1195016s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe TID: 7572 | Thread sleep time: -1194891s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe TID: 7572 | Thread sleep time: -1194781s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe TID: 7572 | Thread sleep time: -1194672s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe TID: 7572 | Thread sleep time: -1194562s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe TID: 7572 | Thread sleep time: -1194449s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe TID: 7572 | Thread sleep time: -1194344s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe TID: 7572 | Thread sleep time: -1194234s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Thread delayed: delay time: 1200000 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Thread delayed: delay time: 1199875 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Thread delayed: delay time: 1199766 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Thread delayed: delay time: 1199641 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Thread delayed: delay time: 1199516 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Thread delayed: delay time: 1199406 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Thread delayed: delay time: 1199297 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Thread delayed: delay time: 1199188 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Thread delayed: delay time: 1199063 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Thread delayed: delay time: 1198952 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Thread delayed: delay time: 1198828 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Thread delayed: delay time: 1198719 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Thread delayed: delay time: 1198609 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Thread delayed: delay time: 1198498 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Thread delayed: delay time: 1198390 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Thread delayed: delay time: 1198281 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Thread delayed: delay time: 1198147 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Thread delayed: delay time: 1198004 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Thread delayed: delay time: 1197844 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Thread delayed: delay time: 1197734 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Thread delayed: delay time: 1197610 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Thread delayed: delay time: 1197485 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Thread delayed: delay time: 1197375 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Thread delayed: delay time: 1197235 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Thread delayed: delay time: 1197125 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Thread delayed: delay time: 1197016 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Thread delayed: delay time: 1196906 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Thread delayed: delay time: 1196797 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Thread delayed: delay time: 1196688 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Thread delayed: delay time: 1196578 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Thread delayed: delay time: 1196465 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Thread delayed: delay time: 1196359 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Thread delayed: delay time: 1196250 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Thread delayed: delay time: 1196141 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Thread delayed: delay time: 1196016 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Thread delayed: delay time: 1195906 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Thread delayed: delay time: 1195797 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Thread delayed: delay time: 1195687 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Thread delayed: delay time: 1195578 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Thread delayed: delay time: 1195465 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Thread delayed: delay time: 1195360 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Thread delayed: delay time: 1195249 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Thread delayed: delay time: 1195141 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Thread delayed: delay time: 1195016 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Thread delayed: delay time: 1194891 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Thread delayed: delay time: 1194781 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Thread delayed: delay time: 1194672 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Thread delayed: delay time: 1194562 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Thread delayed: delay time: 1194449 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Thread delayed: delay time: 1194344 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Thread delayed: delay time: 1194234 | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Queries volume information: C:\Users\user\Desktop\hesaphareket.exe VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Queries volume information: C:\Windows\Fonts\micross.ttf VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\ VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-GroupPolicy-ClientTools-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-AppManagement-AppV-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\Microsoft.Management.Infrastructure.Native\v4.0_1.0.0.0__31bf3856ad364e35\Microsoft.Management.Infrastructure.Native.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\AppvClient\Microsoft.AppV.AppVClientPowerShell.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1865.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-WOW64-Package~31bf3856ad364e35~amd64~en-GB~10.0.19041.1.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\BitLocker\Microsoft.BitLocker.Structures.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management\v4.0_3.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Management.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Queries volume information: C:\Users\user\Desktop\hesaphareket.exe VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Security\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Security.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\hesaphareket.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation | Jump to behavior |