Source: C:\Users\user\Desktop\proforma invoice.exe | Code function: 0_2_00AD2530 | 0_2_00AD2530 |
Source: C:\Users\user\Desktop\proforma invoice.exe | Code function: 0_2_00AD0871 | 0_2_00AD0871 |
Source: C:\Users\user\Desktop\proforma invoice.exe | Code function: 0_2_00AD1360 | 0_2_00AD1360 |
Source: C:\Users\user\Desktop\proforma invoice.exe | Code function: 0_2_00AD34B8 | 0_2_00AD34B8 |
Source: C:\Users\user\Desktop\proforma invoice.exe | Code function: 0_2_00AD1B89 | 0_2_00AD1B89 |
Source: C:\Users\user\Desktop\proforma invoice.exe | Code function: 0_2_00AD9B84 | 0_2_00AD9B84 |
Source: C:\Users\user\Desktop\proforma invoice.exe | Code function: 0_2_00AD9CF8 | 0_2_00AD9CF8 |
Source: C:\Users\user\Desktop\proforma invoice.exe | Code function: 0_2_00AD43BB | 0_2_00AD43BB |
Source: C:\Users\user\Desktop\proforma invoice.exe | Code function: 0_2_00AD43C0 | 0_2_00AD43C0 |
Source: C:\Users\user\Desktop\proforma invoice.exe | Code function: 0_2_00ADA330 | 0_2_00ADA330 |
Source: C:\Users\user\Desktop\proforma invoice.exe | Code function: 0_2_00AD4F18 | 0_2_00AD4F18 |
Source: C:\Users\user\Desktop\proforma invoice.exe | Code function: 0_2_00AD4F14 | 0_2_00AD4F14 |
Source: C:\Users\user\Desktop\proforma invoice.exe | Code function: 0_2_00AD33A8 | 0_2_00AD33A8 |
Source: C:\Users\user\Desktop\proforma invoice.exe | Code function: 0_2_00AD5588 | 0_2_00AD5588 |
Source: C:\Users\user\Desktop\proforma invoice.exe | Code function: 0_2_00AD57E0 | 0_2_00AD57E0 |
Source: C:\Users\user\Desktop\proforma invoice.exe | Code function: 0_2_00AD57D1 | 0_2_00AD57D1 |
Source: C:\Users\user\Desktop\proforma invoice.exe | Code function: 0_2_00AD5A40 | 0_2_00AD5A40 |
Source: C:\Users\user\Desktop\proforma invoice.exe | Code function: 0_2_00AD9CE8 | 0_2_00AD9CE8 |
Source: C:\Users\user\Desktop\proforma invoice.exe | Code function: 0_2_09460370 | 0_2_09460370 |
Source: C:\Users\user\Desktop\proforma invoice.exe | Code function: 0_2_09463810 | 0_2_09463810 |
Source: C:\Users\user\Desktop\proforma invoice.exe | Code function: 0_2_09464080 | 0_2_09464080 |
Source: C:\Users\user\Desktop\proforma invoice.exe | Code function: 0_2_09460360 | 0_2_09460360 |
Source: C:\Users\user\Desktop\proforma invoice.exe | Code function: 0_2_094633D8 | 0_2_094633D8 |
Source: C:\Users\user\Desktop\proforma invoice.exe | Code function: 0_2_094633AA | 0_2_094633AA |
Source: C:\Users\user\Desktop\proforma invoice.exe | Code function: 0_2_09463C48 | 0_2_09463C48 |
Source: C:\Users\user\Desktop\proforma invoice.exe | Code function: 0_2_094654E8 | 0_2_094654E8 |
Source: C:\Users\user\Desktop\proforma invoice.exe | Code function: 9_2_015B3690 | 9_2_015B3690 |
Source: C:\Users\user\Desktop\proforma invoice.exe | Code function: 9_2_015B2970 | 9_2_015B2970 |
Source: C:\Users\user\Desktop\proforma invoice.exe | Code function: 9_2_015B2960 | 9_2_015B2960 |
Source: C:\Users\user\Desktop\proforma invoice.exe | Code function: 9_2_05E3D1C8 | 9_2_05E3D1C8 |
Source: C:\Users\user\Desktop\proforma invoice.exe | Code function: 9_2_05E37018 | 9_2_05E37018 |
Source: C:\Users\user\Desktop\proforma invoice.exe | Code function: 9_2_05E34658 | 9_2_05E34658 |
Source: C:\Users\user\Desktop\proforma invoice.exe | Code function: 9_2_05E34310 | 9_2_05E34310 |
Source: C:\Users\user\Desktop\proforma invoice.exe | Code function: 9_2_05E34F28 | 9_2_05E34F28 |
Source: C:\Users\user\Desktop\proforma invoice.exe | Code function: 9_2_072387E8 | 9_2_072387E8 |
Source: C:\Users\user\Desktop\proforma invoice.exe | Code function: 9_2_0723B3D0 | 9_2_0723B3D0 |
Source: C:\Users\user\Desktop\proforma invoice.exe | Code function: 9_2_072332E0 | 9_2_072332E0 |
Source: C:\Users\user\Desktop\proforma invoice.exe | Code function: 9_2_072359C0 | 9_2_072359C0 |
Source: C:\Users\user\Desktop\proforma invoice.exe | Code function: 9_2_07230040 | 9_2_07230040 |
Source: C:\Users\user\Desktop\proforma invoice.exe | Code function: 9_2_07239C48 | 9_2_07239C48 |
Source: C:\Users\user\Desktop\proforma invoice.exe | Code function: 9_2_0723E888 | 9_2_0723E888 |
Source: C:\Users\user\Desktop\proforma invoice.exe | Code function: 9_2_07230006 | 9_2_07230006 |
Source: C:\Users\user\Desktop\proforma invoice.exe | Code function: 9_2_0723ACF0 | 9_2_0723ACF0 |
Source: C:\Users\user\Desktop\proforma invoice.exe | Code function: 9_2_05E30040 | 9_2_05E30040 |
Source: C:\Users\user\Desktop\proforma invoice.exe | Code function: 9_2_05E30007 | 9_2_05E30007 |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Code function: 10_2_01542530 | 10_2_01542530 |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Code function: 10_2_01540871 | 10_2_01540871 |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Code function: 10_2_01541360 | 10_2_01541360 |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Code function: 10_2_015434B8 | 10_2_015434B8 |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Code function: 10_2_01549B84 | 10_2_01549B84 |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Code function: 10_2_01541B8A | 10_2_01541B8A |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Code function: 10_2_01549CF8 | 10_2_01549CF8 |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Code function: 10_2_0154A33F | 10_2_0154A33F |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Code function: 10_2_015443C0 | 10_2_015443C0 |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Code function: 10_2_015443B0 | 10_2_015443B0 |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Code function: 10_2_01544F18 | 10_2_01544F18 |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Code function: 10_2_01544F08 | 10_2_01544F08 |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Code function: 10_2_015433A8 | 10_2_015433A8 |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Code function: 10_2_015412D2 | 10_2_015412D2 |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Code function: 10_2_0154557A | 10_2_0154557A |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Code function: 10_2_01545588 | 10_2_01545588 |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Code function: 10_2_015457D1 | 10_2_015457D1 |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Code function: 10_2_015457E0 | 10_2_015457E0 |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Code function: 10_2_01545A40 | 10_2_01545A40 |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Code function: 10_2_01545A30 | 10_2_01545A30 |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Code function: 10_2_01549CE8 | 10_2_01549CE8 |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Code function: 10_2_0A370370 | 10_2_0A370370 |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Code function: 10_2_0A370360 | 10_2_0A370360 |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Code function: 10_2_0A3733D8 | 10_2_0A3733D8 |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Code function: 10_2_0A373810 | 10_2_0A373810 |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Code function: 10_2_0A374080 | 10_2_0A374080 |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Code function: 10_2_0A373C48 | 10_2_0A373C48 |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Code function: 10_2_0A3754E8 | 10_2_0A3754E8 |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Code function: 10_2_0A37ADF8 | 10_2_0A37ADF8 |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Code function: 10_2_0A521C20 | 10_2_0A521C20 |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Code function: 10_2_0A522118 | 10_2_0A522118 |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Code function: 10_2_0A521C00 | 10_2_0A521C00 |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Code function: 14_2_02B23690 | 14_2_02B23690 |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Code function: 14_2_02B22970 | 14_2_02B22970 |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Code function: 14_2_02B22960 | 14_2_02B22960 |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Code function: 14_2_062D4310 | 14_2_062D4310 |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Code function: 14_2_062D7018 | 14_2_062D7018 |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Code function: 14_2_062DD1C8 | 14_2_062DD1C8 |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Code function: 14_2_062D4F28 | 14_2_062D4F28 |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Code function: 14_2_062D4658 | 14_2_062D4658 |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Code function: 14_2_06C287E8 | 14_2_06C287E8 |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Code function: 14_2_06C29C48 | 14_2_06C29C48 |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Code function: 14_2_06C205D6 | 14_2_06C205D6 |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Code function: 14_2_06C2B3D0 | 14_2_06C2B3D0 |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Code function: 14_2_06C2E888 | 14_2_06C2E888 |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Code function: 14_2_06C2ACF0 | 14_2_06C2ACF0 |
Source: C:\Users\user\Desktop\proforma invoice.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Section loaded: windowscodecs.dll | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Section loaded: dwrite.dll | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Section loaded: iconcodecservice.dll | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Section loaded: edputil.dll | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Section loaded: windows.staterepositoryps.dll | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Section loaded: virtdisk.dll | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Section loaded: fltlib.dll | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Section loaded: appresolver.dll | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Section loaded: bcp47langs.dll | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Section loaded: slc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Section loaded: sppc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Section loaded: onecorecommonproxystub.dll | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Section loaded: onecoreuapcommonproxystub.dll | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: atl.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: msisip.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wshext.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: appxsip.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: opcservices.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: secur32.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: virtdisk.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: fltlib.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: atl.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: msisip.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wshext.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: appxsip.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: opcservices.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: secur32.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: virtdisk.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: fltlib.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: microsoft.management.infrastructure.native.unmanaged.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: mi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: miutils.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wmidcom.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: dpapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wbemcomn.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\schtasks.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\schtasks.exe | Section loaded: taskschd.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\schtasks.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Section loaded: wbemcomn.dll | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Section loaded: rasapi32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Section loaded: rasman.dll | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Section loaded: rtutils.dll | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Section loaded: dhcpcsvc6.dll | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Section loaded: dhcpcsvc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Section loaded: dnsapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Section loaded: winnsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Section loaded: rasadhlp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Section loaded: fwpuclnt.dll | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Section loaded: secur32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Section loaded: schannel.dll | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Section loaded: mskeyprotect.dll | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Section loaded: ntasn1.dll | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Section loaded: ncrypt.dll | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Section loaded: ncryptsslp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Section loaded: vaultcli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Section loaded: windowscodecs.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Section loaded: dwrite.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Section loaded: iconcodecservice.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Section loaded: edputil.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Section loaded: windows.staterepositoryps.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Section loaded: virtdisk.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Section loaded: fltlib.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Section loaded: appresolver.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Section loaded: bcp47langs.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Section loaded: slc.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Section loaded: sppc.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Section loaded: onecorecommonproxystub.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Section loaded: onecoreuapcommonproxystub.dll | Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: fastprox.dll | |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: ncobjapi.dll | |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: wbemcomn.dll | |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: wbemcomn.dll | |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: mpclient.dll | |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: userenv.dll | |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: version.dll | |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: msasn1.dll | |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: wmitomi.dll | |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: mi.dll | |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: miutils.dll | |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: miutils.dll | |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: gpapi.dll | |
Source: C:\Windows\SysWOW64\schtasks.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\SysWOW64\schtasks.exe | Section loaded: taskschd.dll | |
Source: C:\Windows\SysWOW64\schtasks.exe | Section loaded: sspicli.dll | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Section loaded: mscoree.dll | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Section loaded: version.dll | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Section loaded: vcruntime140_clr0400.dll | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Section loaded: uxtheme.dll | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Section loaded: windows.storage.dll | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Section loaded: wldp.dll | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Section loaded: profapi.dll | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Section loaded: cryptsp.dll | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Section loaded: rsaenh.dll | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Section loaded: cryptbase.dll | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Section loaded: wbemcomn.dll | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Section loaded: amsi.dll | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Section loaded: userenv.dll | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Section loaded: sspicli.dll | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Section loaded: rasapi32.dll | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Section loaded: rasman.dll | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Section loaded: rtutils.dll | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Section loaded: mswsock.dll | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Section loaded: winhttp.dll | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Section loaded: ondemandconnroutehelper.dll | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Section loaded: iphlpapi.dll | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Section loaded: dhcpcsvc6.dll | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Section loaded: dhcpcsvc.dll | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Section loaded: dnsapi.dll | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Section loaded: winnsi.dll | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Section loaded: rasadhlp.dll | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Section loaded: fwpuclnt.dll | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Section loaded: secur32.dll | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Section loaded: schannel.dll | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Section loaded: mskeyprotect.dll | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Section loaded: ntasn1.dll | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Section loaded: ncrypt.dll | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Section loaded: ncryptsslp.dll | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Section loaded: msasn1.dll | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Section loaded: gpapi.dll | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Section loaded: vaultcli.dll | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Section loaded: wintypes.dll | |
Source: 0.2.proforma invoice.exe.42f1a78.1.raw.unpack, WiHmOQGBiauFOXCSRe.cs | High entropy of concatenated method names: 'huuQBRM76y', 'BkfQcPJOeR', 'pZuQ4gymnm', 'OGvQT38mqx', 'YcZQphG3SU', 'zOE4OaUmEC', 'Oxj4mkgNM4', 'IUw4jQvMWd', 'vVZ41df6e7', 'ruR4ZYHjNP' |
Source: 0.2.proforma invoice.exe.42f1a78.1.raw.unpack, PyOApGje3N2O4YRLJq.cs | High entropy of concatenated method names: 'v58WiqxZpW', 'S6MWJN2Keb', 'zaaWWQNX4Q', 'TQcWuWUuGk', 'QfnWoHyagD', 'fX8WIysnMq', 'Dispose', 'FpbVUHCJE8', 'gVfVcBA9rY', 'BnaVMKKTE5' |
Source: 0.2.proforma invoice.exe.42f1a78.1.raw.unpack, vVbLP0DwljmXtWWceF.cs | High entropy of concatenated method names: 'gFJFMZ153v', 'nXvF4Q7OYg', 'DuiFQsQhpq', 'Y2rFTo07s8', 'kNyFWw0lal', 'XsOFpDS8mI', 'Next', 'Next', 'Next', 'NextBytes' |
Source: 0.2.proforma invoice.exe.42f1a78.1.raw.unpack, Rq0BwamMBeOLUYY5aR.cs | High entropy of concatenated method names: 'b2aJ1IrynY', 'PTbJDSakn0', 'BRUVfZsACg', 'WjHVgJnrcN', 'ggnJHJW9LJ', 'PZfJ9dsZik', 'pZgJvoMpfx', 'NJnJtF8c7t', 'AcFJ5j3iSF', 'g8kJStnKxe' |
Source: 0.2.proforma invoice.exe.42f1a78.1.raw.unpack, sfw71jgg3t49MjXGUgn.cs | High entropy of concatenated method names: 'R8wFD7a2qZ', 'uGgFzl7Txb', 'j1Zufqs2oo', 'cNKugxNCtU', 'OERur8fRWT', 'p9DuYkDOUN', 'Jgoun56KhE', 'lkcuBclZVu', 'iNOuUm6WUP', 'ONiuciBxnM' |
Source: 0.2.proforma invoice.exe.42f1a78.1.raw.unpack, mfjQw5qpQAlqUAiSkP.cs | High entropy of concatenated method names: 'vjectVphMe', 'RZEc5BKtLu', 'HnNcSnRlfA', 'JK9cXMCiQ8', 't4dcOAmybs', 'zoqcmCMUfB', 'SQVcjCRlPV', 'Mh5c1ViRsc', 'St6cZNHjvi', 'RTZcDJKlj4' |
Source: 0.2.proforma invoice.exe.42f1a78.1.raw.unpack, KCe7psr6YgQ0YnUNYD.cs | High entropy of concatenated method names: 'gmJsdCXUD', 'WkMlJKWen', 'n73dicphk', 'wUWRAaryA', 'ucG7iskxH', 'mvJLjYJDk', 'eK00QUAeoM5aQ7Cd4H', 'vv4sMINhKQJCuHKonv', 'EdsVwFdcD', 'qAOFUfqTQ' |
Source: 0.2.proforma invoice.exe.42f1a78.1.raw.unpack, jA2dlspLgAa2OFDOi4.cs | High entropy of concatenated method names: 'hGLYBbvBFT', 'UUhYU0O2H4', 'xWSYcJDbbH', 'AHpYMrEqln', 'AwCY48046Y', 'iwLYQtGmRe', 'NPqYTOocTh', 'RKfYpMWUIy', 'n53Y6qo7Bk', 'Lh7YwQCx3Q' |
Source: 0.2.proforma invoice.exe.42f1a78.1.raw.unpack, HsB6cEhmL1Dnenbik0.cs | High entropy of concatenated method names: 'iH1TeFwC5S', 'xlFTE54dFb', 'PtxTsgOeAj', 'KCnTlasA3M', 'SdCTAFtE21', 'dkMTdgynPe', 'lj6TRW3LLD', 'X8dTqLYHLd', 'vAsT7fpqth', 'gb4TL178HV' |
Source: 0.2.proforma invoice.exe.42f1a78.1.raw.unpack, R6wLMqt5jEb2YGGg9e.cs | High entropy of concatenated method names: 'GRbiPT49Da', 'Cj4i9taUKW', 'd2jitwVJDU', 'QSHi5EjkPZ', 'addiaTjPbN', 'AEXikZrvF5', 'ymRi8tPP4C', 'wOji2h95oX', 'RvWixTHh7l', 'MJ0iKwjKAg' |
Source: 0.2.proforma invoice.exe.42f1a78.1.raw.unpack, uqFF1RzSdGFrHl5b4x.cs | High entropy of concatenated method names: 'OMmFdCmYN4', 'PNKFqtkV7v', 'FCyF70VFq3', 'Jr0FGXZxAg', 'cPNFaC7VQC', 'aEGF8poMdE', 'q6KF2kAOfs', 't1pFIUoC7V', 'JOFFeJl5QZ', 'n2wFEudfUK' |
Source: 0.2.proforma invoice.exe.42f1a78.1.raw.unpack, VUNrkTXdX06dje6RkF.cs | High entropy of concatenated method names: 'afvJw09PYa', 'dVnJyQFW9s', 'ToString', 'KxuJUCfky6', 'HxAJc2nKkm', 'FsQJMgCpFZ', 'YHmJ4rp1dg', 'bFHJQISASA', 'yjLJTI7PHk', 'up8JpHZQam' |
Source: 0.2.proforma invoice.exe.42f1a78.1.raw.unpack, eKx1LZviwh9iXuwZd9.cs | High entropy of concatenated method names: 'IWMNqEKv1S', 'XBEN7mEyBe', 'wbuNGsxdY3', 'AA4NacHHQn', 'CpZN849UE9', 'scoN2AHH8a', 'nD7NKZx1V5', 'EBgN3ZoWQN', 'IfcNP9uI53', 'EfyNHAAWBl' |
Source: 0.2.proforma invoice.exe.42f1a78.1.raw.unpack, syJphlcTajaUCfV0FF.cs | High entropy of concatenated method names: 'Dispose', 'o2OgZ4YRLJ', 'werraI3qGK', 'Vn7EDJgkMW', 'DfRgDlGX0c', 'xEOgzuOU63', 'ProcessDialogKey', 'OTqrfBVYhh', 'hagrgQF8t2', 'DLxrroVbLP' |
Source: 0.2.proforma invoice.exe.42f1a78.1.raw.unpack, sBAJnnnSn1gmI7iGZs.cs | High entropy of concatenated method names: 'vTygTfjQw5', 'kQAgplqUAi', 'poQgwGU4bb', 'pvCgyPfLNj', 'Gsrgi1ojiH', 'VOQg0BiauF', 'u7lo5UUBwV5WPQSGYp', 'VUaBvKf4B36YI99wcL', 'HegggeAaGk', 'ajXgYUk6eF' |
Source: 0.2.proforma invoice.exe.42f1a78.1.raw.unpack, nSt0wLKSpDoHL65hAM.cs | High entropy of concatenated method names: 'kf9TUt6qJb', 'dEhTM3ntPg', 'DP9TQXxtkG', 'dhoQD56ZD1', 'pUSQz9guBa', 'ObkTfQwQdy', 'ueyTgigWcu', 'IthTrwFKcw', 'HPwTYyvdYA', 'TD6TnG9HWi' |
Source: 0.2.proforma invoice.exe.42f1a78.1.raw.unpack, YAC4Z07oQGU4bb0vCP.cs | High entropy of concatenated method names: 'yvMMlTfH9j', 'NWeMdMNaOt', 'jqvMqcZ8RB', 'HEtM79QLkg', 'moYMi55LPx', 'OLcM0JTxie', 'x1oMJwDyDT', 'yKAMVDbWU3', 'fRxMWs8bdx', 'xEdMFxo3gW' |
Source: 0.2.proforma invoice.exe.42f1a78.1.raw.unpack, icgbEF8LHdvAJJNCZN.cs | High entropy of concatenated method names: 'j1fQIUNn0f', 'AlqQeimjtI', 'xVmQsPB0tl', 'g12QljmIZO', 'jhqQd1XopS', 'yMaQRnfD7e', 'wuIQ7tO5k6', 'EvYQLiywYW', 'VXkC8HMQrSnXDQoNWFt', 'A4WOskM8E3RCfxTIBT3' |
Source: 0.2.proforma invoice.exe.42f1a78.1.raw.unpack, DBVYhhZ4agQF8t2qLx.cs | High entropy of concatenated method names: 'zZTWG8F2PP', 'VKoWaJlAPy', 'i31Wk5ZP0k', 'qtqW8f6BPa', 'Fn5W2oUOnK', 'n5CWxIPHo5', 'vZ7WKQCByS', 'MLyW33sV6R', 'kd8WheLstB', 'RouWPxUC5g' |
Source: 0.2.proforma invoice.exe.93d0000.4.raw.unpack, WiHmOQGBiauFOXCSRe.cs | High entropy of concatenated method names: 'huuQBRM76y', 'BkfQcPJOeR', 'pZuQ4gymnm', 'OGvQT38mqx', 'YcZQphG3SU', 'zOE4OaUmEC', 'Oxj4mkgNM4', 'IUw4jQvMWd', 'vVZ41df6e7', 'ruR4ZYHjNP' |
Source: 0.2.proforma invoice.exe.93d0000.4.raw.unpack, PyOApGje3N2O4YRLJq.cs | High entropy of concatenated method names: 'v58WiqxZpW', 'S6MWJN2Keb', 'zaaWWQNX4Q', 'TQcWuWUuGk', 'QfnWoHyagD', 'fX8WIysnMq', 'Dispose', 'FpbVUHCJE8', 'gVfVcBA9rY', 'BnaVMKKTE5' |
Source: 0.2.proforma invoice.exe.93d0000.4.raw.unpack, vVbLP0DwljmXtWWceF.cs | High entropy of concatenated method names: 'gFJFMZ153v', 'nXvF4Q7OYg', 'DuiFQsQhpq', 'Y2rFTo07s8', 'kNyFWw0lal', 'XsOFpDS8mI', 'Next', 'Next', 'Next', 'NextBytes' |
Source: 0.2.proforma invoice.exe.93d0000.4.raw.unpack, Rq0BwamMBeOLUYY5aR.cs | High entropy of concatenated method names: 'b2aJ1IrynY', 'PTbJDSakn0', 'BRUVfZsACg', 'WjHVgJnrcN', 'ggnJHJW9LJ', 'PZfJ9dsZik', 'pZgJvoMpfx', 'NJnJtF8c7t', 'AcFJ5j3iSF', 'g8kJStnKxe' |
Source: 0.2.proforma invoice.exe.93d0000.4.raw.unpack, sfw71jgg3t49MjXGUgn.cs | High entropy of concatenated method names: 'R8wFD7a2qZ', 'uGgFzl7Txb', 'j1Zufqs2oo', 'cNKugxNCtU', 'OERur8fRWT', 'p9DuYkDOUN', 'Jgoun56KhE', 'lkcuBclZVu', 'iNOuUm6WUP', 'ONiuciBxnM' |
Source: 0.2.proforma invoice.exe.93d0000.4.raw.unpack, mfjQw5qpQAlqUAiSkP.cs | High entropy of concatenated method names: 'vjectVphMe', 'RZEc5BKtLu', 'HnNcSnRlfA', 'JK9cXMCiQ8', 't4dcOAmybs', 'zoqcmCMUfB', 'SQVcjCRlPV', 'Mh5c1ViRsc', 'St6cZNHjvi', 'RTZcDJKlj4' |
Source: 0.2.proforma invoice.exe.93d0000.4.raw.unpack, KCe7psr6YgQ0YnUNYD.cs | High entropy of concatenated method names: 'gmJsdCXUD', 'WkMlJKWen', 'n73dicphk', 'wUWRAaryA', 'ucG7iskxH', 'mvJLjYJDk', 'eK00QUAeoM5aQ7Cd4H', 'vv4sMINhKQJCuHKonv', 'EdsVwFdcD', 'qAOFUfqTQ' |
Source: 0.2.proforma invoice.exe.93d0000.4.raw.unpack, jA2dlspLgAa2OFDOi4.cs | High entropy of concatenated method names: 'hGLYBbvBFT', 'UUhYU0O2H4', 'xWSYcJDbbH', 'AHpYMrEqln', 'AwCY48046Y', 'iwLYQtGmRe', 'NPqYTOocTh', 'RKfYpMWUIy', 'n53Y6qo7Bk', 'Lh7YwQCx3Q' |
Source: 0.2.proforma invoice.exe.93d0000.4.raw.unpack, HsB6cEhmL1Dnenbik0.cs | High entropy of concatenated method names: 'iH1TeFwC5S', 'xlFTE54dFb', 'PtxTsgOeAj', 'KCnTlasA3M', 'SdCTAFtE21', 'dkMTdgynPe', 'lj6TRW3LLD', 'X8dTqLYHLd', 'vAsT7fpqth', 'gb4TL178HV' |
Source: 0.2.proforma invoice.exe.93d0000.4.raw.unpack, R6wLMqt5jEb2YGGg9e.cs | High entropy of concatenated method names: 'GRbiPT49Da', 'Cj4i9taUKW', 'd2jitwVJDU', 'QSHi5EjkPZ', 'addiaTjPbN', 'AEXikZrvF5', 'ymRi8tPP4C', 'wOji2h95oX', 'RvWixTHh7l', 'MJ0iKwjKAg' |
Source: 0.2.proforma invoice.exe.93d0000.4.raw.unpack, uqFF1RzSdGFrHl5b4x.cs | High entropy of concatenated method names: 'OMmFdCmYN4', 'PNKFqtkV7v', 'FCyF70VFq3', 'Jr0FGXZxAg', 'cPNFaC7VQC', 'aEGF8poMdE', 'q6KF2kAOfs', 't1pFIUoC7V', 'JOFFeJl5QZ', 'n2wFEudfUK' |
Source: 0.2.proforma invoice.exe.93d0000.4.raw.unpack, VUNrkTXdX06dje6RkF.cs | High entropy of concatenated method names: 'afvJw09PYa', 'dVnJyQFW9s', 'ToString', 'KxuJUCfky6', 'HxAJc2nKkm', 'FsQJMgCpFZ', 'YHmJ4rp1dg', 'bFHJQISASA', 'yjLJTI7PHk', 'up8JpHZQam' |
Source: 0.2.proforma invoice.exe.93d0000.4.raw.unpack, eKx1LZviwh9iXuwZd9.cs | High entropy of concatenated method names: 'IWMNqEKv1S', 'XBEN7mEyBe', 'wbuNGsxdY3', 'AA4NacHHQn', 'CpZN849UE9', 'scoN2AHH8a', 'nD7NKZx1V5', 'EBgN3ZoWQN', 'IfcNP9uI53', 'EfyNHAAWBl' |
Source: 0.2.proforma invoice.exe.93d0000.4.raw.unpack, syJphlcTajaUCfV0FF.cs | High entropy of concatenated method names: 'Dispose', 'o2OgZ4YRLJ', 'werraI3qGK', 'Vn7EDJgkMW', 'DfRgDlGX0c', 'xEOgzuOU63', 'ProcessDialogKey', 'OTqrfBVYhh', 'hagrgQF8t2', 'DLxrroVbLP' |
Source: 0.2.proforma invoice.exe.93d0000.4.raw.unpack, sBAJnnnSn1gmI7iGZs.cs | High entropy of concatenated method names: 'vTygTfjQw5', 'kQAgplqUAi', 'poQgwGU4bb', 'pvCgyPfLNj', 'Gsrgi1ojiH', 'VOQg0BiauF', 'u7lo5UUBwV5WPQSGYp', 'VUaBvKf4B36YI99wcL', 'HegggeAaGk', 'ajXgYUk6eF' |
Source: 0.2.proforma invoice.exe.93d0000.4.raw.unpack, nSt0wLKSpDoHL65hAM.cs | High entropy of concatenated method names: 'kf9TUt6qJb', 'dEhTM3ntPg', 'DP9TQXxtkG', 'dhoQD56ZD1', 'pUSQz9guBa', 'ObkTfQwQdy', 'ueyTgigWcu', 'IthTrwFKcw', 'HPwTYyvdYA', 'TD6TnG9HWi' |
Source: 0.2.proforma invoice.exe.93d0000.4.raw.unpack, YAC4Z07oQGU4bb0vCP.cs | High entropy of concatenated method names: 'yvMMlTfH9j', 'NWeMdMNaOt', 'jqvMqcZ8RB', 'HEtM79QLkg', 'moYMi55LPx', 'OLcM0JTxie', 'x1oMJwDyDT', 'yKAMVDbWU3', 'fRxMWs8bdx', 'xEdMFxo3gW' |
Source: 0.2.proforma invoice.exe.93d0000.4.raw.unpack, icgbEF8LHdvAJJNCZN.cs | High entropy of concatenated method names: 'j1fQIUNn0f', 'AlqQeimjtI', 'xVmQsPB0tl', 'g12QljmIZO', 'jhqQd1XopS', 'yMaQRnfD7e', 'wuIQ7tO5k6', 'EvYQLiywYW', 'VXkC8HMQrSnXDQoNWFt', 'A4WOskM8E3RCfxTIBT3' |
Source: 0.2.proforma invoice.exe.93d0000.4.raw.unpack, DBVYhhZ4agQF8t2qLx.cs | High entropy of concatenated method names: 'zZTWG8F2PP', 'VKoWaJlAPy', 'i31Wk5ZP0k', 'qtqW8f6BPa', 'Fn5W2oUOnK', 'n5CWxIPHo5', 'vZ7WKQCByS', 'MLyW33sV6R', 'kd8WheLstB', 'RouWPxUC5g' |
Source: 0.2.proforma invoice.exe.4370698.0.raw.unpack, WiHmOQGBiauFOXCSRe.cs | High entropy of concatenated method names: 'huuQBRM76y', 'BkfQcPJOeR', 'pZuQ4gymnm', 'OGvQT38mqx', 'YcZQphG3SU', 'zOE4OaUmEC', 'Oxj4mkgNM4', 'IUw4jQvMWd', 'vVZ41df6e7', 'ruR4ZYHjNP' |
Source: 0.2.proforma invoice.exe.4370698.0.raw.unpack, PyOApGje3N2O4YRLJq.cs | High entropy of concatenated method names: 'v58WiqxZpW', 'S6MWJN2Keb', 'zaaWWQNX4Q', 'TQcWuWUuGk', 'QfnWoHyagD', 'fX8WIysnMq', 'Dispose', 'FpbVUHCJE8', 'gVfVcBA9rY', 'BnaVMKKTE5' |
Source: 0.2.proforma invoice.exe.4370698.0.raw.unpack, vVbLP0DwljmXtWWceF.cs | High entropy of concatenated method names: 'gFJFMZ153v', 'nXvF4Q7OYg', 'DuiFQsQhpq', 'Y2rFTo07s8', 'kNyFWw0lal', 'XsOFpDS8mI', 'Next', 'Next', 'Next', 'NextBytes' |
Source: 0.2.proforma invoice.exe.4370698.0.raw.unpack, Rq0BwamMBeOLUYY5aR.cs | High entropy of concatenated method names: 'b2aJ1IrynY', 'PTbJDSakn0', 'BRUVfZsACg', 'WjHVgJnrcN', 'ggnJHJW9LJ', 'PZfJ9dsZik', 'pZgJvoMpfx', 'NJnJtF8c7t', 'AcFJ5j3iSF', 'g8kJStnKxe' |
Source: 0.2.proforma invoice.exe.4370698.0.raw.unpack, sfw71jgg3t49MjXGUgn.cs | High entropy of concatenated method names: 'R8wFD7a2qZ', 'uGgFzl7Txb', 'j1Zufqs2oo', 'cNKugxNCtU', 'OERur8fRWT', 'p9DuYkDOUN', 'Jgoun56KhE', 'lkcuBclZVu', 'iNOuUm6WUP', 'ONiuciBxnM' |
Source: 0.2.proforma invoice.exe.4370698.0.raw.unpack, mfjQw5qpQAlqUAiSkP.cs | High entropy of concatenated method names: 'vjectVphMe', 'RZEc5BKtLu', 'HnNcSnRlfA', 'JK9cXMCiQ8', 't4dcOAmybs', 'zoqcmCMUfB', 'SQVcjCRlPV', 'Mh5c1ViRsc', 'St6cZNHjvi', 'RTZcDJKlj4' |
Source: 0.2.proforma invoice.exe.4370698.0.raw.unpack, KCe7psr6YgQ0YnUNYD.cs | High entropy of concatenated method names: 'gmJsdCXUD', 'WkMlJKWen', 'n73dicphk', 'wUWRAaryA', 'ucG7iskxH', 'mvJLjYJDk', 'eK00QUAeoM5aQ7Cd4H', 'vv4sMINhKQJCuHKonv', 'EdsVwFdcD', 'qAOFUfqTQ' |
Source: 0.2.proforma invoice.exe.4370698.0.raw.unpack, jA2dlspLgAa2OFDOi4.cs | High entropy of concatenated method names: 'hGLYBbvBFT', 'UUhYU0O2H4', 'xWSYcJDbbH', 'AHpYMrEqln', 'AwCY48046Y', 'iwLYQtGmRe', 'NPqYTOocTh', 'RKfYpMWUIy', 'n53Y6qo7Bk', 'Lh7YwQCx3Q' |
Source: 0.2.proforma invoice.exe.4370698.0.raw.unpack, HsB6cEhmL1Dnenbik0.cs | High entropy of concatenated method names: 'iH1TeFwC5S', 'xlFTE54dFb', 'PtxTsgOeAj', 'KCnTlasA3M', 'SdCTAFtE21', 'dkMTdgynPe', 'lj6TRW3LLD', 'X8dTqLYHLd', 'vAsT7fpqth', 'gb4TL178HV' |
Source: 0.2.proforma invoice.exe.4370698.0.raw.unpack, R6wLMqt5jEb2YGGg9e.cs | High entropy of concatenated method names: 'GRbiPT49Da', 'Cj4i9taUKW', 'd2jitwVJDU', 'QSHi5EjkPZ', 'addiaTjPbN', 'AEXikZrvF5', 'ymRi8tPP4C', 'wOji2h95oX', 'RvWixTHh7l', 'MJ0iKwjKAg' |
Source: 0.2.proforma invoice.exe.4370698.0.raw.unpack, uqFF1RzSdGFrHl5b4x.cs | High entropy of concatenated method names: 'OMmFdCmYN4', 'PNKFqtkV7v', 'FCyF70VFq3', 'Jr0FGXZxAg', 'cPNFaC7VQC', 'aEGF8poMdE', 'q6KF2kAOfs', 't1pFIUoC7V', 'JOFFeJl5QZ', 'n2wFEudfUK' |
Source: 0.2.proforma invoice.exe.4370698.0.raw.unpack, VUNrkTXdX06dje6RkF.cs | High entropy of concatenated method names: 'afvJw09PYa', 'dVnJyQFW9s', 'ToString', 'KxuJUCfky6', 'HxAJc2nKkm', 'FsQJMgCpFZ', 'YHmJ4rp1dg', 'bFHJQISASA', 'yjLJTI7PHk', 'up8JpHZQam' |
Source: 0.2.proforma invoice.exe.4370698.0.raw.unpack, eKx1LZviwh9iXuwZd9.cs | High entropy of concatenated method names: 'IWMNqEKv1S', 'XBEN7mEyBe', 'wbuNGsxdY3', 'AA4NacHHQn', 'CpZN849UE9', 'scoN2AHH8a', 'nD7NKZx1V5', 'EBgN3ZoWQN', 'IfcNP9uI53', 'EfyNHAAWBl' |
Source: 0.2.proforma invoice.exe.4370698.0.raw.unpack, syJphlcTajaUCfV0FF.cs | High entropy of concatenated method names: 'Dispose', 'o2OgZ4YRLJ', 'werraI3qGK', 'Vn7EDJgkMW', 'DfRgDlGX0c', 'xEOgzuOU63', 'ProcessDialogKey', 'OTqrfBVYhh', 'hagrgQF8t2', 'DLxrroVbLP' |
Source: 0.2.proforma invoice.exe.4370698.0.raw.unpack, sBAJnnnSn1gmI7iGZs.cs | High entropy of concatenated method names: 'vTygTfjQw5', 'kQAgplqUAi', 'poQgwGU4bb', 'pvCgyPfLNj', 'Gsrgi1ojiH', 'VOQg0BiauF', 'u7lo5UUBwV5WPQSGYp', 'VUaBvKf4B36YI99wcL', 'HegggeAaGk', 'ajXgYUk6eF' |
Source: 0.2.proforma invoice.exe.4370698.0.raw.unpack, nSt0wLKSpDoHL65hAM.cs | High entropy of concatenated method names: 'kf9TUt6qJb', 'dEhTM3ntPg', 'DP9TQXxtkG', 'dhoQD56ZD1', 'pUSQz9guBa', 'ObkTfQwQdy', 'ueyTgigWcu', 'IthTrwFKcw', 'HPwTYyvdYA', 'TD6TnG9HWi' |
Source: 0.2.proforma invoice.exe.4370698.0.raw.unpack, YAC4Z07oQGU4bb0vCP.cs | High entropy of concatenated method names: 'yvMMlTfH9j', 'NWeMdMNaOt', 'jqvMqcZ8RB', 'HEtM79QLkg', 'moYMi55LPx', 'OLcM0JTxie', 'x1oMJwDyDT', 'yKAMVDbWU3', 'fRxMWs8bdx', 'xEdMFxo3gW' |
Source: 0.2.proforma invoice.exe.4370698.0.raw.unpack, icgbEF8LHdvAJJNCZN.cs | High entropy of concatenated method names: 'j1fQIUNn0f', 'AlqQeimjtI', 'xVmQsPB0tl', 'g12QljmIZO', 'jhqQd1XopS', 'yMaQRnfD7e', 'wuIQ7tO5k6', 'EvYQLiywYW', 'VXkC8HMQrSnXDQoNWFt', 'A4WOskM8E3RCfxTIBT3' |
Source: 0.2.proforma invoice.exe.4370698.0.raw.unpack, DBVYhhZ4agQF8t2qLx.cs | High entropy of concatenated method names: 'zZTWG8F2PP', 'VKoWaJlAPy', 'i31Wk5ZP0k', 'qtqW8f6BPa', 'Fn5W2oUOnK', 'n5CWxIPHo5', 'vZ7WKQCByS', 'MLyW33sV6R', 'kd8WheLstB', 'RouWPxUC5g' |
Source: C:\Users\user\Desktop\proforma invoice.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\Desktop\proforma invoice.exe TID: 7872 | Thread sleep time: -922337203685477s >= -30000s | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe TID: 2916 | Thread sleep time: -1844674407370954s >= -30000s | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe TID: 1368 | Thread sleep time: -922337203685477s >= -30000s | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe TID: 888 | Thread sleep time: -8301034833169293s >= -30000s | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe TID: 6124 | Thread sleep time: -922337203685477s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe TID: 7740 | Thread sleep count: 36 > 30 | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe TID: 7740 | Thread sleep time: -33204139332677172s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe TID: 7740 | Thread sleep time: -100000s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe TID: 7740 | Thread sleep time: -99875s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe TID: 6348 | Thread sleep count: 3622 > 30 | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe TID: 7740 | Thread sleep time: -99766s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe TID: 6348 | Thread sleep count: 6210 > 30 | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe TID: 7740 | Thread sleep time: -99641s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe TID: 7740 | Thread sleep time: -99532s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe TID: 7740 | Thread sleep time: -99407s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe TID: 7740 | Thread sleep time: -99297s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe TID: 7740 | Thread sleep time: -99188s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe TID: 7740 | Thread sleep time: -99063s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe TID: 7740 | Thread sleep time: -98938s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe TID: 7740 | Thread sleep time: -98813s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe TID: 7740 | Thread sleep time: -98688s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe TID: 7740 | Thread sleep time: -98577s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe TID: 7740 | Thread sleep time: -98467s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe TID: 7740 | Thread sleep time: -98360s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe TID: 7740 | Thread sleep time: -98250s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe TID: 7740 | Thread sleep time: -98141s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe TID: 7740 | Thread sleep time: -98016s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe TID: 7740 | Thread sleep time: -97907s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe TID: 7740 | Thread sleep time: -97782s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe TID: 7740 | Thread sleep time: -97657s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe TID: 7740 | Thread sleep time: -97547s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe TID: 7740 | Thread sleep time: -97438s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe TID: 7740 | Thread sleep time: -97313s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe TID: 7740 | Thread sleep time: -97188s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe TID: 7740 | Thread sleep time: -97063s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe TID: 7740 | Thread sleep time: -96938s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe TID: 7740 | Thread sleep time: -96828s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe TID: 7740 | Thread sleep time: -96719s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe TID: 7740 | Thread sleep time: -96594s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe TID: 7740 | Thread sleep time: -96484s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe TID: 7740 | Thread sleep time: -96375s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe TID: 7740 | Thread sleep time: -96266s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe TID: 7740 | Thread sleep time: -96157s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe TID: 7740 | Thread sleep time: -96032s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe TID: 7740 | Thread sleep time: -95907s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe TID: 7740 | Thread sleep time: -95782s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe TID: 7740 | Thread sleep time: -95672s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe TID: 7740 | Thread sleep time: -95563s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe TID: 7740 | Thread sleep time: -95438s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe TID: 7740 | Thread sleep time: -95313s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe TID: 7740 | Thread sleep time: -95188s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe TID: 7740 | Thread sleep time: -95063s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe TID: 7740 | Thread sleep time: -94954s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe TID: 7740 | Thread sleep time: -94829s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe TID: 7740 | Thread sleep time: -94704s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe TID: 7740 | Thread sleep time: -94579s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe TID: 7740 | Thread sleep time: -94454s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe TID: 7740 | Thread sleep time: -94329s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe TID: 7740 | Thread sleep time: -94204s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe TID: 7772 | Thread sleep time: -922337203685477s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe TID: 604 | Thread sleep count: 34 > 30 | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe TID: 604 | Thread sleep time: -31359464925306218s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe TID: 604 | Thread sleep time: -100000s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe TID: 604 | Thread sleep time: -99874s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe TID: 1048 | Thread sleep count: 8315 > 30 | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe TID: 1048 | Thread sleep count: 1538 > 30 | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe TID: 604 | Thread sleep time: -99765s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe TID: 604 | Thread sleep time: -99656s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe TID: 604 | Thread sleep time: -99546s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe TID: 604 | Thread sleep time: -99432s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe TID: 604 | Thread sleep time: -99312s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe TID: 604 | Thread sleep time: -99202s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe TID: 604 | Thread sleep time: -99093s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe TID: 604 | Thread sleep time: -98984s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe TID: 604 | Thread sleep time: -98873s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe TID: 604 | Thread sleep time: -98765s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe TID: 604 | Thread sleep time: -98656s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe TID: 604 | Thread sleep time: -98546s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe TID: 604 | Thread sleep time: -98437s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe TID: 604 | Thread sleep time: -98327s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe TID: 604 | Thread sleep time: -98209s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe TID: 604 | Thread sleep time: -98078s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe TID: 604 | Thread sleep time: -97968s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe TID: 604 | Thread sleep time: -97859s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe TID: 604 | Thread sleep time: -97750s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe TID: 604 | Thread sleep time: -97640s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe TID: 604 | Thread sleep time: -97528s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe TID: 604 | Thread sleep time: -97421s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe TID: 604 | Thread sleep time: -97312s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe TID: 604 | Thread sleep time: -97203s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe TID: 604 | Thread sleep time: -97093s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe TID: 604 | Thread sleep time: -96975s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe TID: 604 | Thread sleep time: -96859s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe TID: 604 | Thread sleep time: -96749s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe TID: 604 | Thread sleep time: -96640s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe TID: 604 | Thread sleep time: -96531s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe TID: 604 | Thread sleep time: -96421s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe TID: 604 | Thread sleep time: -96312s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe TID: 604 | Thread sleep time: -96203s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe TID: 604 | Thread sleep time: -96093s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe TID: 604 | Thread sleep time: -95984s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe TID: 604 | Thread sleep time: -95874s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe TID: 604 | Thread sleep time: -95765s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe TID: 604 | Thread sleep time: -95656s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe TID: 604 | Thread sleep time: -95546s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe TID: 604 | Thread sleep time: -95410s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe TID: 604 | Thread sleep time: -95281s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe TID: 604 | Thread sleep time: -95171s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe TID: 604 | Thread sleep time: -95062s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe TID: 604 | Thread sleep time: -94953s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe TID: 604 | Thread sleep time: -94843s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe TID: 604 | Thread sleep time: -94732s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe TID: 604 | Thread sleep time: -94624s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe TID: 604 | Thread sleep time: -94514s >= -30000s | |
Source: C:\Users\user\Desktop\proforma invoice.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Thread delayed: delay time: 100000 | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Thread delayed: delay time: 99875 | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Thread delayed: delay time: 99766 | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Thread delayed: delay time: 99641 | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Thread delayed: delay time: 99532 | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Thread delayed: delay time: 99407 | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Thread delayed: delay time: 99297 | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Thread delayed: delay time: 99188 | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Thread delayed: delay time: 99063 | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Thread delayed: delay time: 98938 | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Thread delayed: delay time: 98813 | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Thread delayed: delay time: 98688 | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Thread delayed: delay time: 98577 | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Thread delayed: delay time: 98467 | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Thread delayed: delay time: 98360 | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Thread delayed: delay time: 98250 | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Thread delayed: delay time: 98141 | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Thread delayed: delay time: 98016 | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Thread delayed: delay time: 97907 | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Thread delayed: delay time: 97782 | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Thread delayed: delay time: 97657 | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Thread delayed: delay time: 97547 | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Thread delayed: delay time: 97438 | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Thread delayed: delay time: 97313 | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Thread delayed: delay time: 97188 | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Thread delayed: delay time: 97063 | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Thread delayed: delay time: 96938 | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Thread delayed: delay time: 96828 | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Thread delayed: delay time: 96719 | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Thread delayed: delay time: 96594 | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Thread delayed: delay time: 96484 | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Thread delayed: delay time: 96375 | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Thread delayed: delay time: 96266 | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Thread delayed: delay time: 96157 | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Thread delayed: delay time: 96032 | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Thread delayed: delay time: 95907 | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Thread delayed: delay time: 95782 | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Thread delayed: delay time: 95672 | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Thread delayed: delay time: 95563 | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Thread delayed: delay time: 95438 | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Thread delayed: delay time: 95313 | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Thread delayed: delay time: 95188 | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Thread delayed: delay time: 95063 | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Thread delayed: delay time: 94954 | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Thread delayed: delay time: 94829 | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Thread delayed: delay time: 94704 | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Thread delayed: delay time: 94579 | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Thread delayed: delay time: 94454 | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Thread delayed: delay time: 94329 | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Thread delayed: delay time: 94204 | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Thread delayed: delay time: 922337203685477 | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Thread delayed: delay time: 100000 | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Thread delayed: delay time: 99874 | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Thread delayed: delay time: 99765 | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Thread delayed: delay time: 99656 | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Thread delayed: delay time: 99546 | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Thread delayed: delay time: 99432 | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Thread delayed: delay time: 99312 | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Thread delayed: delay time: 99202 | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Thread delayed: delay time: 99093 | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Thread delayed: delay time: 98984 | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Thread delayed: delay time: 98873 | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Thread delayed: delay time: 98765 | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Thread delayed: delay time: 98656 | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Thread delayed: delay time: 98546 | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Thread delayed: delay time: 98437 | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Thread delayed: delay time: 98327 | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Thread delayed: delay time: 98209 | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Thread delayed: delay time: 98078 | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Thread delayed: delay time: 97968 | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Thread delayed: delay time: 97859 | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Thread delayed: delay time: 97750 | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Thread delayed: delay time: 97640 | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Thread delayed: delay time: 97528 | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Thread delayed: delay time: 97421 | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Thread delayed: delay time: 97312 | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Thread delayed: delay time: 97203 | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Thread delayed: delay time: 97093 | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Thread delayed: delay time: 96975 | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Thread delayed: delay time: 96859 | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Thread delayed: delay time: 96749 | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Thread delayed: delay time: 96640 | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Thread delayed: delay time: 96531 | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Thread delayed: delay time: 96421 | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Thread delayed: delay time: 96312 | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Thread delayed: delay time: 96203 | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Thread delayed: delay time: 96093 | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Thread delayed: delay time: 95984 | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Thread delayed: delay time: 95874 | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Thread delayed: delay time: 95765 | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Thread delayed: delay time: 95656 | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Thread delayed: delay time: 95546 | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Thread delayed: delay time: 95410 | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Thread delayed: delay time: 95281 | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Thread delayed: delay time: 95171 | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Thread delayed: delay time: 95062 | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Thread delayed: delay time: 94953 | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Thread delayed: delay time: 94843 | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Thread delayed: delay time: 94732 | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Thread delayed: delay time: 94624 | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Thread delayed: delay time: 94514 | |
Source: C:\Users\user\Desktop\proforma invoice.exe | Queries volume information: C:\Users\user\Desktop\proforma invoice.exe VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Xml\v4.0_4.0.0.0__b77a5c561934e089\System.XML.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Queries volume information: C:\Windows\Fonts\micross.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost\v4.0_3.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.ConsoleHost.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Management.Automation\v4.0_3.0.0.0__31bf3856ad364e35\System.Management.Automation.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Management.Automation\v4.0_3.0.0.0__31bf3856ad364e35\System.Management.Automation.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Xml\v4.0_4.0.0.0__b77a5c561934e089\System.XML.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.Management.Infrastructure\v4.0_1.0.0.0__31bf3856ad364e35\Microsoft.Management.Infrastructure.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Numerics\v4.0_4.0.0.0__b77a5c561934e089\System.Numerics.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Management\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Management.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.PowerShell.Security\v4.0_3.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Security.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\ VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-GroupPolicy-ClientTools-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\Microsoft.Management.Infrastructure.Native\v4.0_1.0.0.0__31bf3856ad364e35\Microsoft.Management.Infrastructure.Native.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\AppvClient\Microsoft.AppV.AppVClientPowerShell.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1865.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-WOW64-Package~31bf3856ad364e35~amd64~en-GB~10.0.19041.1.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility\v4.0_3.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Utility.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Configuration.Install\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\BitLocker\Microsoft.BitLocker.Structures.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management\v4.0_3.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Management.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost\v4.0_3.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.ConsoleHost.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Management.Automation\v4.0_3.0.0.0__31bf3856ad364e35\System.Management.Automation.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Management.Automation\v4.0_3.0.0.0__31bf3856ad364e35\System.Management.Automation.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Xml\v4.0_4.0.0.0__b77a5c561934e089\System.XML.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.Management.Infrastructure\v4.0_1.0.0.0__31bf3856ad364e35\Microsoft.Management.Infrastructure.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Numerics\v4.0_4.0.0.0__b77a5c561934e089\System.Numerics.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.DirectoryServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Management\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Management.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.PowerShell.Security\v4.0_3.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Security.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\ VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-GroupPolicy-ClientTools-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\Microsoft.Management.Infrastructure.Native\v4.0_1.0.0.0__31bf3856ad364e35\Microsoft.Management.Infrastructure.Native.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\AppvClient\Microsoft.AppV.AppVClientPowerShell.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1865.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-WOW64-Package~31bf3856ad364e35~amd64~en-GB~10.0.19041.1.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility\v4.0_3.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Utility.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Configuration.Install\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\BitLocker\Microsoft.BitLocker.Structures.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management\v4.0_3.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Management.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Queries volume information: C:\Users\user\Desktop\proforma invoice.exe VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Xml\v4.0_4.0.0.0__b77a5c561934e089\System.XML.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Management\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Management.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Security\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Security.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\proforma invoice.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Queries volume information: C:\Users\user\AppData\Roaming\CGWlZD.exe VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Xml\v4.0_4.0.0.0__b77a5c561934e089\System.XML.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Queries volume information: C:\Users\user\AppData\Roaming\CGWlZD.exe VolumeInformation | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Xml\v4.0_4.0.0.0__b77a5c561934e089\System.XML.dll VolumeInformation | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Management\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Management.dll VolumeInformation | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Security\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Security.dll VolumeInformation | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation | |
Source: C:\Users\user\AppData\Roaming\CGWlZD.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation | |