Source: C:\Users\user\Desktop\4si9noTBNw.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Section loaded: ktmw32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Section loaded: wbemcomn.dll | Jump to behavior |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Section loaded: dlnashext.dll | Jump to behavior |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Section loaded: wpdshext.dll | Jump to behavior |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Section loaded: edputil.dll | Jump to behavior |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Section loaded: windows.staterepositoryps.dll | Jump to behavior |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Section loaded: appresolver.dll | Jump to behavior |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Section loaded: bcp47langs.dll | Jump to behavior |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Section loaded: slc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Section loaded: sppc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Section loaded: onecorecommonproxystub.dll | Jump to behavior |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Section loaded: onecoreuapcommonproxystub.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Program Files (x86)\Java\VTixufCejPQZEvXiB.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Program Files (x86)\Java\VTixufCejPQZEvXiB.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Program Files (x86)\Java\VTixufCejPQZEvXiB.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Program Files (x86)\Java\VTixufCejPQZEvXiB.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Program Files (x86)\Java\VTixufCejPQZEvXiB.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Program Files (x86)\Java\VTixufCejPQZEvXiB.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Program Files (x86)\Java\VTixufCejPQZEvXiB.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Program Files (x86)\Java\VTixufCejPQZEvXiB.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Program Files (x86)\Java\VTixufCejPQZEvXiB.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Program Files (x86)\Java\VTixufCejPQZEvXiB.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Program Files (x86)\Java\VTixufCejPQZEvXiB.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Program Files (x86)\Java\VTixufCejPQZEvXiB.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Program Files (x86)\Java\VTixufCejPQZEvXiB.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Program Files (x86)\Java\VTixufCejPQZEvXiB.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Program Files (x86)\Java\VTixufCejPQZEvXiB.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Program Files (x86)\Java\VTixufCejPQZEvXiB.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Program Files (x86)\Java\VTixufCejPQZEvXiB.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Program Files (x86)\Java\VTixufCejPQZEvXiB.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Program Files (x86)\Java\VTixufCejPQZEvXiB.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Program Files (x86)\Java\VTixufCejPQZEvXiB.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Program Files (x86)\Java\VTixufCejPQZEvXiB.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Program Files (x86)\Java\VTixufCejPQZEvXiB.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Program Files (x86)\Java\VTixufCejPQZEvXiB.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Program Files (x86)\Java\VTixufCejPQZEvXiB.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Program Files (x86)\Java\VTixufCejPQZEvXiB.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Program Files (x86)\Java\VTixufCejPQZEvXiB.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Program Files (x86)\Java\VTixufCejPQZEvXiB.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Program Files (x86)\Java\VTixufCejPQZEvXiB.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Program Files (x86)\Java\VTixufCejPQZEvXiB.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\cvtres.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\cvtres.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\cvtres.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\cvtres.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\cvtres.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\cvtres.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\cvtres.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\Public\AccountPictures\winlogon.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Users\Public\AccountPictures\winlogon.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\Public\AccountPictures\winlogon.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\Public\AccountPictures\winlogon.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\Public\AccountPictures\winlogon.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Users\Public\AccountPictures\winlogon.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\Public\AccountPictures\winlogon.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\Public\AccountPictures\winlogon.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\Public\AccountPictures\winlogon.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\Public\AccountPictures\winlogon.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\Public\AccountPictures\winlogon.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\Public\AccountPictures\winlogon.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\Public\AccountPictures\winlogon.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\Public\AccountPictures\winlogon.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\Public\AccountPictures\winlogon.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\Public\AccountPictures\winlogon.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Users\Public\AccountPictures\winlogon.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\Public\AccountPictures\winlogon.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\Public\AccountPictures\winlogon.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Users\Public\AccountPictures\winlogon.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\Public\AccountPictures\winlogon.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\Public\AccountPictures\winlogon.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\Public\AccountPictures\winlogon.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\Public\AccountPictures\winlogon.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\Public\AccountPictures\winlogon.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\Public\AccountPictures\winlogon.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\Public\AccountPictures\winlogon.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\Public\AccountPictures\winlogon.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\Public\AccountPictures\winlogon.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: atl.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: mscoree.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: version.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: vcruntime140_clr0400.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: cryptsp.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: rsaenh.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: cryptbase.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: windows.storage.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wldp.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: amsi.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: userenv.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: profapi.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: msasn1.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: gpapi.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: msisip.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wshext.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: appxsip.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: opcservices.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: secur32.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: uxtheme.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: urlmon.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: iertutil.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: srvcli.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: netutils.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: propsys.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wininet.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: microsoft.management.infrastructure.native.unmanaged.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: mi.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: miutils.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wmidcom.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: dpapi.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wbemcomn.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: atl.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: mscoree.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: version.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: vcruntime140_clr0400.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: cryptsp.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: rsaenh.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: cryptbase.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: windows.storage.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wldp.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: msasn1.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: gpapi.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: amsi.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: userenv.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: profapi.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: msisip.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wshext.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: appxsip.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: opcservices.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: secur32.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: uxtheme.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: urlmon.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: iertutil.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: srvcli.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: netutils.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: propsys.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wininet.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: microsoft.management.infrastructure.native.unmanaged.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: mi.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: miutils.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wmidcom.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: dpapi.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wbemcomn.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: atl.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: mscoree.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: version.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: vcruntime140_clr0400.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: cryptsp.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: rsaenh.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: cryptbase.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: windows.storage.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wldp.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: msasn1.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: amsi.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: userenv.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: profapi.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: gpapi.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: msisip.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wshext.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: appxsip.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: opcservices.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: secur32.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: uxtheme.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: urlmon.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: iertutil.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: srvcli.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: netutils.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: propsys.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wininet.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: microsoft.management.infrastructure.native.unmanaged.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: mi.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: miutils.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wmidcom.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: dpapi.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wbemcomn.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: atl.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: mscoree.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: version.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: vcruntime140_clr0400.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: cryptsp.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: rsaenh.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: cryptbase.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: amsi.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: windows.storage.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wldp.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: userenv.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: msasn1.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: profapi.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: gpapi.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: msisip.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wshext.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: appxsip.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: opcservices.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: secur32.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: uxtheme.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: urlmon.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: iertutil.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: srvcli.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: netutils.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: propsys.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wininet.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: microsoft.management.infrastructure.native.unmanaged.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: mi.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: miutils.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wmidcom.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: dpapi.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wbemcomn.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: atl.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: mscoree.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: version.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: vcruntime140_clr0400.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: cryptsp.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: rsaenh.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: cryptbase.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: amsi.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: userenv.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: profapi.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: windows.storage.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wldp.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: msasn1.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: msisip.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wshext.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: appxsip.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: opcservices.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: gpapi.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: secur32.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: uxtheme.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: urlmon.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: iertutil.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: srvcli.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: netutils.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: propsys.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wininet.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: microsoft.management.infrastructure.native.unmanaged.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: mi.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: miutils.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wmidcom.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: dpapi.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wbemcomn.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: atl.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: mscoree.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: version.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: vcruntime140_clr0400.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: cryptsp.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: rsaenh.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: cryptbase.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: windows.storage.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wldp.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: msasn1.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: amsi.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: userenv.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: profapi.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: gpapi.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: msisip.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wshext.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: appxsip.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: opcservices.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: secur32.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: uxtheme.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: urlmon.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: iertutil.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: srvcli.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: netutils.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: propsys.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wininet.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: microsoft.management.infrastructure.native.unmanaged.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: mi.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: miutils.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wmidcom.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: dpapi.dll | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wbemcomn.dll | |
Source: C:\Windows\System32\cmd.exe | Section loaded: cmdext.dll | |
Source: C:\Windows\System32\chcp.com | Section loaded: ulib.dll | |
Source: C:\Windows\System32\chcp.com | Section loaded: fsutilext.dll | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Section loaded: mscoree.dll | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Section loaded: version.dll | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Section loaded: vcruntime140_clr0400.dll | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Section loaded: uxtheme.dll | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Section loaded: windows.storage.dll | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Section loaded: wldp.dll | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Section loaded: profapi.dll | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Section loaded: cryptsp.dll | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Section loaded: rsaenh.dll | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Section loaded: cryptbase.dll | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Section loaded: sspicli.dll | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Section loaded: mscoree.dll | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Section loaded: version.dll | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Section loaded: vcruntime140_clr0400.dll | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Section loaded: uxtheme.dll | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Section loaded: windows.storage.dll | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Section loaded: wldp.dll | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Section loaded: profapi.dll | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Section loaded: cryptsp.dll | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Section loaded: rsaenh.dll | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Section loaded: cryptbase.dll | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Section loaded: sspicli.dll | |
Source: C:\Program Files\Windows Defender\en-GB\conhost.exe | Section loaded: mscoree.dll | |
Source: C:\Program Files\Windows Defender\en-GB\conhost.exe | Section loaded: apphelp.dll | |
Source: C:\Program Files\Windows Defender\en-GB\conhost.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Program Files\Windows Defender\en-GB\conhost.exe | Section loaded: version.dll | |
Source: C:\Program Files\Windows Defender\en-GB\conhost.exe | Section loaded: vcruntime140_clr0400.dll | |
Source: C:\Program Files\Windows Defender\en-GB\conhost.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Program Files\Windows Defender\en-GB\conhost.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Program Files\Windows Defender\en-GB\conhost.exe | Section loaded: uxtheme.dll | |
Source: C:\Program Files\Windows Defender\en-GB\conhost.exe | Section loaded: windows.storage.dll | |
Source: C:\Program Files\Windows Defender\en-GB\conhost.exe | Section loaded: wldp.dll | |
Source: C:\Program Files\Windows Defender\en-GB\conhost.exe | Section loaded: profapi.dll | |
Source: C:\Program Files\Windows Defender\en-GB\conhost.exe | Section loaded: cryptsp.dll | |
Source: C:\Program Files\Windows Defender\en-GB\conhost.exe | Section loaded: rsaenh.dll | |
Source: C:\Program Files\Windows Defender\en-GB\conhost.exe | Section loaded: cryptbase.dll | |
Source: C:\Program Files\Windows Defender\en-GB\conhost.exe | Section loaded: sspicli.dll | |
Source: C:\Program Files\Windows Defender\en-GB\conhost.exe | Section loaded: mscoree.dll | |
Source: C:\Program Files\Windows Defender\en-GB\conhost.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Program Files\Windows Defender\en-GB\conhost.exe | Section loaded: version.dll | |
Source: C:\Program Files\Windows Defender\en-GB\conhost.exe | Section loaded: vcruntime140_clr0400.dll | |
Source: C:\Program Files\Windows Defender\en-GB\conhost.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Program Files\Windows Defender\en-GB\conhost.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Program Files\Windows Defender\en-GB\conhost.exe | Section loaded: uxtheme.dll | |
Source: C:\Program Files\Windows Defender\en-GB\conhost.exe | Section loaded: windows.storage.dll | |
Source: C:\Program Files\Windows Defender\en-GB\conhost.exe | Section loaded: wldp.dll | |
Source: C:\Program Files\Windows Defender\en-GB\conhost.exe | Section loaded: profapi.dll | |
Source: C:\Program Files\Windows Defender\en-GB\conhost.exe | Section loaded: cryptsp.dll | |
Source: C:\Program Files\Windows Defender\en-GB\conhost.exe | Section loaded: rsaenh.dll | |
Source: C:\Program Files\Windows Defender\en-GB\conhost.exe | Section loaded: cryptbase.dll | |
Source: C:\Program Files\Windows Defender\en-GB\conhost.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\System32\PING.EXE | Section loaded: iphlpapi.dll | |
Source: C:\Windows\System32\PING.EXE | Section loaded: mswsock.dll | |
Source: C:\Windows\System32\PING.EXE | Section loaded: dnsapi.dll | |
Source: C:\Windows\System32\PING.EXE | Section loaded: rasadhlp.dll | |
Source: C:\Windows\System32\PING.EXE | Section loaded: fwpuclnt.dll | |
Source: C:\Windows\System32\PING.EXE | Section loaded: winnsi.dll | |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: fastprox.dll | |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: ncobjapi.dll | |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: wbemcomn.dll | |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: wbemcomn.dll | |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: mpclient.dll | |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: userenv.dll | |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: version.dll | |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: userenv.dll | |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: msasn1.dll | |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: wmitomi.dll | |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: mi.dll | |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: miutils.dll | |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: miutils.dll | |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: gpapi.dll | |
Source: C:\Recovery\VTixufCejPQZEvXiB.exe | Section loaded: mscoree.dll | |
Source: C:\Recovery\VTixufCejPQZEvXiB.exe | Section loaded: apphelp.dll | |
Source: C:\Recovery\VTixufCejPQZEvXiB.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Recovery\VTixufCejPQZEvXiB.exe | Section loaded: version.dll | |
Source: C:\Recovery\VTixufCejPQZEvXiB.exe | Section loaded: vcruntime140_clr0400.dll | |
Source: C:\Recovery\VTixufCejPQZEvXiB.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Recovery\VTixufCejPQZEvXiB.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Recovery\VTixufCejPQZEvXiB.exe | Section loaded: uxtheme.dll | |
Source: C:\Recovery\VTixufCejPQZEvXiB.exe | Section loaded: windows.storage.dll | |
Source: C:\Recovery\VTixufCejPQZEvXiB.exe | Section loaded: wldp.dll | |
Source: C:\Recovery\VTixufCejPQZEvXiB.exe | Section loaded: profapi.dll | |
Source: C:\Recovery\VTixufCejPQZEvXiB.exe | Section loaded: cryptsp.dll | |
Source: C:\Recovery\VTixufCejPQZEvXiB.exe | Section loaded: rsaenh.dll | |
Source: C:\Recovery\VTixufCejPQZEvXiB.exe | Section loaded: cryptbase.dll | |
Source: C:\Recovery\VTixufCejPQZEvXiB.exe | Section loaded: sspicli.dll | |
Source: C:\Program Files\Windows Defender\en-GB\conhost.exe | Section loaded: mscoree.dll | |
Source: C:\Program Files\Windows Defender\en-GB\conhost.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Program Files\Windows Defender\en-GB\conhost.exe | Section loaded: version.dll | |
Source: C:\Program Files\Windows Defender\en-GB\conhost.exe | Section loaded: vcruntime140_clr0400.dll | |
Source: C:\Program Files\Windows Defender\en-GB\conhost.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Program Files\Windows Defender\en-GB\conhost.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Program Files\Windows Defender\en-GB\conhost.exe | Section loaded: uxtheme.dll | |
Source: C:\Program Files\Windows Defender\en-GB\conhost.exe | Section loaded: windows.storage.dll | |
Source: C:\Program Files\Windows Defender\en-GB\conhost.exe | Section loaded: wldp.dll | |
Source: C:\Program Files\Windows Defender\en-GB\conhost.exe | Section loaded: profapi.dll | |
Source: C:\Program Files\Windows Defender\en-GB\conhost.exe | Section loaded: cryptsp.dll | |
Source: C:\Program Files\Windows Defender\en-GB\conhost.exe | Section loaded: rsaenh.dll | |
Source: C:\Program Files\Windows Defender\en-GB\conhost.exe | Section loaded: cryptbase.dll | |
Source: C:\Program Files\Windows Defender\en-GB\conhost.exe | Section loaded: sspicli.dll | |
Source: C:\Users\Public\AccountPictures\winlogon.exe | Section loaded: mscoree.dll | |
Source: C:\Users\Public\AccountPictures\winlogon.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Users\Public\AccountPictures\winlogon.exe | Section loaded: version.dll | |
Source: C:\Users\Public\AccountPictures\winlogon.exe | Section loaded: vcruntime140_clr0400.dll | |
Source: C:\Users\Public\AccountPictures\winlogon.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Users\Public\AccountPictures\winlogon.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Users\Public\AccountPictures\winlogon.exe | Section loaded: uxtheme.dll | |
Source: C:\Users\Public\AccountPictures\winlogon.exe | Section loaded: windows.storage.dll | |
Source: C:\Users\Public\AccountPictures\winlogon.exe | Section loaded: wldp.dll | |
Source: C:\Users\Public\AccountPictures\winlogon.exe | Section loaded: profapi.dll | |
Source: C:\Users\Public\AccountPictures\winlogon.exe | Section loaded: cryptsp.dll | |
Source: C:\Users\Public\AccountPictures\winlogon.exe | Section loaded: rsaenh.dll | |
Source: C:\Users\Public\AccountPictures\winlogon.exe | Section loaded: cryptbase.dll | |
Source: C:\Users\Public\AccountPictures\winlogon.exe | Section loaded: sspicli.dll | |
Source: C:\Program Files\Windows Defender\en-GB\conhost.exe | Section loaded: mscoree.dll | |
Source: C:\Program Files\Windows Defender\en-GB\conhost.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Program Files\Windows Defender\en-GB\conhost.exe | Section loaded: version.dll | |
Source: C:\Program Files\Windows Defender\en-GB\conhost.exe | Section loaded: vcruntime140_clr0400.dll | |
Source: C:\Program Files\Windows Defender\en-GB\conhost.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Program Files\Windows Defender\en-GB\conhost.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Program Files\Windows Defender\en-GB\conhost.exe | Section loaded: uxtheme.dll | |
Source: C:\Program Files\Windows Defender\en-GB\conhost.exe | Section loaded: windows.storage.dll | |
Source: C:\Program Files\Windows Defender\en-GB\conhost.exe | Section loaded: wldp.dll | |
Source: C:\Program Files\Windows Defender\en-GB\conhost.exe | Section loaded: profapi.dll | |
Source: C:\Program Files\Windows Defender\en-GB\conhost.exe | Section loaded: cryptsp.dll | |
Source: C:\Program Files\Windows Defender\en-GB\conhost.exe | Section loaded: rsaenh.dll | |
Source: C:\Program Files\Windows Defender\en-GB\conhost.exe | Section loaded: cryptbase.dll | |
Source: C:\Program Files\Windows Defender\en-GB\conhost.exe | Section loaded: sspicli.dll | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Section loaded: mscoree.dll | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Section loaded: version.dll | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Section loaded: vcruntime140_clr0400.dll | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Section loaded: uxtheme.dll | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Section loaded: windows.storage.dll | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Section loaded: wldp.dll | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Section loaded: profapi.dll | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Section loaded: cryptsp.dll | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Section loaded: rsaenh.dll | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Section loaded: cryptbase.dll | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Section loaded: sspicli.dll | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Section loaded: ktmw32.dll | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Section loaded: rasapi32.dll | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Section loaded: rasman.dll | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Section loaded: rtutils.dll | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Section loaded: mswsock.dll | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Section loaded: winhttp.dll | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Section loaded: ondemandconnroutehelper.dll | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Section loaded: iphlpapi.dll | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Section loaded: dhcpcsvc6.dll | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Section loaded: dhcpcsvc.dll | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Section loaded: dnsapi.dll | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Section loaded: winnsi.dll | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Section loaded: rasadhlp.dll | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Section loaded: fwpuclnt.dll | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Section loaded: wbemcomn.dll | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Section loaded: amsi.dll | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Section loaded: userenv.dll | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Section loaded: winmm.dll | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Section loaded: winmmbase.dll | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Section loaded: mmdevapi.dll | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Section loaded: devobj.dll | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Section loaded: ksuser.dll | |
Source: 4si9noTBNw.exe, IWPQttnkpFdSgFyq8vn.cs | High entropy of concatenated method names: 'WU6P6ZscMb', 'oog8m3b5nUCjCqfjrsqq', 'qDaAu9b5P2xhyGYyphuU', 'm6UNAYb5diSZviucc8Qv', 'GNpgK5b5IVee6vUlEuww', 'vsdj4Db54SBU7p91U995', 'UoUYq1b5b1b50yLDuGOf', 'tuQRK8b5Kh2f4MEcG3pM', 'eRBYDqb56k2IZRmwEW3b', 'tDPP40EJFt' |
Source: 4si9noTBNw.exe, eOMvH46bWfJR42MeJJU.cs | High entropy of concatenated method names: 'Ecn6P1MItW', 'HpU6dKkpaf', 'MHD6ISnf35', 'fXl6i4buHE74D7UjAjGX', 'CHTidlbuMRHRTVDtFMbx', 'ESNfm0bu3LEmrZQeQUru', 'BJTcqXbu7CXSOIOjZpns', 'FoRrx9buyqb1OsgOBba6', 'VZDqxTbuJ1k3Sj922N22', 'V2Djxmbu9LlqIN1FFHU4' |
Source: 4si9noTBNw.exe, HI2jHDJU3ecyZiDQa9.cs | High entropy of concatenated method names: 'eSuSu2S5b', 'k9q4ffbwBfdk5s3CVKgj', 'aS8P6ubwWvh8etxCNrOs', 'VyWXZDbwpRBF4XQNfgF6', 'JlRrEGbw5VAmARex4d9x', 'A651V7MJZ', 'aUrl1Gneq', 'ocpiY9WnP', 'QYdXLkmQW', 'jfvvyeFeN' |
Source: 4si9noTBNw.exe, HrrwsKRmpPclrQAyF0B.cs | High entropy of concatenated method names: 'x3dRhudCSW', 'uYnS3dbrpdB2aavyRcli', 'v0tbu6br5XWIkGLHKceF', 'ty09rlbrw6EMxYnmFgtK', 'vLgqkubroiaYxIt1wyCW', 'tneRAAbrBfvjsoyiUylZ', 'IPy', 'method_0', 'method_1', 'method_2' |
Source: 4si9noTBNw.exe, YKq4Thlt6OVYpMvt5bL.cs | High entropy of concatenated method names: 'iKIbUyi2AhP', 'DTuljUngoG', 'CSKbUJPKaox', 'odcxEcb8ZUBgjydJH21D', 'uu6iQ4b8FGKPZNTHmL9R', 'tyW1TPb8NR5VWeP2htKI', 'j2yxVqb8TATlWKUHkc4K', 'sOPdAjb8V4gUGUTBaOyp', 'moPF3Gb8tEAn0ihrSNva', 'RLnvBVb8k56ggAp0ue6p' |
Source: 4si9noTBNw.exe, Q5VRT9UZTk9rE45gpvL.cs | High entropy of concatenated method names: 'bW7UamqP1S', 'wBNJXdbC15oxZmVZFE6u', 'MrLkJBbCJpNdvf9pKTMT', 'QOyGyHbC9kVMPQICt6aW', 'mm9CQpbCllVoPA1Snqbg', 'P9X', 'vmethod_0', 'FRKbdoKAhHM', 'imethod_0', 'wlPCRjbCHLi8mIW4LtvD' |
Source: 4si9noTBNw.exe, x8Jksr1RuEDR7xN2W4D.cs | High entropy of concatenated method names: 'Os31ZA0mbi', 'cWu1FflfiJ', 'zhl1Vd0xWw', 'YRuS3ObcBA0NuhgboO9k', 'hMSWGCbcWFMlCqw60sDg', 'jQa5cfbcpbxEAbWUxcOf', 'pMP2dObc5B9Msy26auA1', 'MgM1cS1i9P', 'bZs18d6kkp', 'DTt1GJh1h0' |
Source: 4si9noTBNw.exe, vvtPHoKSrjDPpiCEKwA.cs | High entropy of concatenated method names: 'P83', 'KZ3', 'TH7', 'imethod_0', 'vmethod_0', 'zTlbUOh9UNn', 'b3Obdbm8D8P', 'vqyIDMbDjSFIgcEsoTNI', 'pq9maDbDenZRE9F5dm4n', 'Y92oxSbDrt16vOMwrDiH' |
Source: 4si9noTBNw.exe, JC5kapYjMG06T6wktBW.cs | High entropy of concatenated method names: 'VLCYrxE4Tb', 'wacYgPFeqW', 'ks7YaC5xo9', 'GBPY0sxO9e', 'flZYEy8aGB', 'eQRAADbT6OQnUx6uy4t1', 'F39giJbTId2MdgWGNNoM', 'hRbmNhbTK2dDGVP7CdSr', 'zJYEtXbTUob235Fh6KB4', 'AFcoSjbTm9u1UKbtNq2K' |
Source: 4si9noTBNw.exe, J3NntmK8R9wK1mKZPCw.cs | High entropy of concatenated method names: 'GcBKa6KAwn', 'xIVK0xATWb', 'ys0KELnVo0', 'E7iChLbuO7UvBELYXZnD', 'xr9dAPbu2lZvH4XTJ3LD', 'PljUk4buUM14HtpYuvfN', 'I4EljmbumyMrMfnlsH5G', 'qaDKNEg5Hv', 'ASXKTu1tn5', 'k4bKZoFxAj' |
Source: 4si9noTBNw.exe, NPma2Yw2dcDehopWD9e.cs | High entropy of concatenated method names: 'MTmwMVEpxX', 'zrSw3HQeOP', 'oU4wHgHXBX', 'RjVw7kHnkR', 'Xiawyy3bMD', 'l2kQM8bZwdkZF6UTvC6Q', 'puDulrbZhrJrO11T62LP', 'f5ml4ZbZQ9RDF0lLsX9k', 'GwbBvwbZo3d8w5A94uwa', 'AWvtcObZpB9JT6gFxKII' |
Source: 4si9noTBNw.exe, R76a7YPwl28Hgq7meLA.cs | High entropy of concatenated method names: 'iSJPGa8i8T', 'id8PNLQ8Zj', 'yoqPT9oOYn', 'FaOsxLb5tonCyLcDe2Jn', 'yLdvG1b5kdreUxd4aXCn', 'WkVgSwb5Fu7kE55MeQdh', 'Q3xsjtb5VQEAFmlfsE0A', 'osePppY2er', 'LsWP50GfHo', 'MolPBwdfwm' |
Source: 4si9noTBNw.exe, MEvjowIjcYufCjRH4QI.cs | High entropy of concatenated method names: 'dReIEDv2tp', 'y7lILyqriC', 'srlIqinjAh', 'OPbIzRCfNB', 'jiQK4TjEAa', 'jIRKbdoH0T', 'N7tKnFF6X2', 'H1sr6DbDXYnA2ENXXOop', 'kVkBqcbDlQSjdML2YQNV', 'VeiaOobDiNTc43x2qKXu' |
Source: 4si9noTBNw.exe, sUDVcHnIDy6VfX8GsQ4.cs | High entropy of concatenated method names: 'DNXn6BrrtY', 'XRHnUWV7ln', 'uionmj8kxv', 'DmZnO1108C', 'MBaGWubp3rtYXXUWyEZj', 'pe0HHubpf4fOOhDGRtsU', 'j8dP7ybpMFKl10Eq1vC1', 'TNpqFIbpHD2O0O66f1d8', 'esE3ndbp72HkLcJE02GN', 'q8Ar0Gbpyh85Es9SKioF' |
Source: 4si9noTBNw.exe, AFlFQUrWHcMVNLhwyip.cs | High entropy of concatenated method names: 'method_0', 'h59', 'R73', 'tVoruZlanw', 'R4Ey3xbaqk0Wk8Sm2iNH', 'c0WuS7bazHf8mCFmbTtH', 'YrNQCwb04jVRjuvjt5ry', 'TiqtKcb0bI13EU8S0juV', 'nvSnVfb0n9ml38g7loNc', 'JJIQF9b0Ptr1IXlGnIN3' |
Source: 4si9noTBNw.exe, aKugbDacY1m1306t5cA.cs | High entropy of concatenated method names: 'method_0', 'method_1', 'blSaGsI9kJ', 'INwaNHCNkk', 'OfRaTKMDLa', 'Dispose', 'emE4tabE8dCISDvI42vN', 'zIEqtjbEGEugwgbjyVvj', 'TLTpJrbENP4K4pXle0Cg', 'nBxjyMbETd6PxAnuVJlX' |
Source: 4si9noTBNw.exe, QRa5f36889vQVIaXJtO.cs | High entropy of concatenated method names: 'jMj6aAD2vq', 'pog60BHxNw', 'Qsbs25bSyQuYhpQtruiZ', 'xxxogIbSHAn0ExKPVliv', 'HMoK20bS7h49lYWAokJQ', 'jIL6N95DkD', 'MEN6T8vRM3', 'N7q6Z4DcFE', 'FLM6FUFag0', 'd5q6VY8Ulm' |
Source: 4si9noTBNw.exe, IPIrIvUyIgwrV3PTZIb.cs | High entropy of concatenated method names: 'LHuUlxwBWl', 'f0ZMwxbSNyEmjPnyxEPa', 'ndMsqFbS8I1QjGXdF4Yl', 'xIuy9fbSGcCX4UkrXB8H', 'piw1fkbSTP5anGPm0xNp', 'jUlU9HScGr', 'D4wtNqbSxUbDFm0ZayhR', 'Ov3BgsbSsRSMg45PQrMM', 'akkNcybSRODxkYiODCXj', 'X9a6APbSSWLloe5A71HY' |
Source: 4si9noTBNw.exe, VClUh2z1y17W48lUVm.cs | High entropy of concatenated method names: 'a0Vbb91lv0', 'pI2bPWOvBB', 't39bdq65aB', 'WCxbIsL7rC', 'JS4bK7eu4v', 'jP8b6YPuHx', 'FQebmv3EVp', 'vLsrl3boIRaV0LcC0heY', 'Mk0o5xboKbKamt34BfC2', 'SkWeaObo6MTB2pXjku8W' |
Source: 4si9noTBNw.exe, rIPkTIo8Dd3y76hx0Id.cs | High entropy of concatenated method names: 'qT7oLfQJ6A', 'MLgozW2vUN', 'YM9oNd5iTq', 'cwMoTOc9CQ', 'a0hoZua6oU', 'gLmoF9KRf4', 'jHpoVJ4VHF', 'Av6otRxStm', 'swLokjiuMW', 'eAIojJOJnq' |
Source: 4si9noTBNw.exe, FrNNtTUcfWY6uQE5Y5r.cs | High entropy of concatenated method names: 'P9X', 'u35bUfodk6A', 'imethod_0', 'kaVUGArq7o', 'M6GVgqbC6TApDxlrkcHt', 'vklcwtbCU4xZUHeLktiB', 'jHs5pKbCm9KNw3SFalsp', 'h6a0tCbCOaFUcgEjkn1s', 'pSI9QIbC2h7EOLCnUm05' |
Source: 4si9noTBNw.exe, G9n8A0rsAFAZ6lbZRXu.cs | High entropy of concatenated method names: 'qkqbUwpPxS1', 'eoObKQyk5uV', 's90dv0b0hPw1wbgbqtM2', 'hkOK7ib0QGUr0YbH2KpY', 'qkVQr6b0wnDXVHMiNvvn', 'Mq0YHbb0B5Um1QC0yQjV', 'AdxxjGb0pBE4iMUGpeaZ', 'O5VbOMb05kSKPImBdEA2', 'imethod_0', 'eoObKQyk5uV' |
Source: 4si9noTBNw.exe, i3W3LBSkDd55KwsAydR.cs | High entropy of concatenated method names: 'y3qaWTbeJcH6v0y4lGeh', 'JIyTaqbe7iXFuesZ5DAR', 'bwbm5ZbeyiQ2rcc3JZN3', 'NgaOdRbe9ca4WMVqFyCR', 'zmwSeWTkoN', 'Mh9', 'method_0', 'Nm0Sr2bhrl', 'mxiSg55kLc', 'TBLSagasKk' |
Source: 4si9noTBNw.exe, aCwFj0l3TwnouTDEHyb.cs | High entropy of concatenated method names: 'RHollSFhUp', 'aHiO2tb8fcQ2iZJfTVgK', 'fvwfCob8MEpi6NcSpLMW', 'bdkN7Ib8OJ6YlMaFDbOx', 'W0iudsb82bVs40k57gMR', 'po4D21b83bm3wvZYwmAf', 'dIyl7YNAF2', 'qboyJdb8UCgATROFhgvZ', 'oCY7Lxb8KFCnIw0Wvflf', 'jE317Zb86p2nhFBeKUtw' |
Source: 4si9noTBNw.exe, EPxQAYWEvhwoQ6vIq9q.cs | High entropy of concatenated method names: 'MsrWqDRnSa', 'fsjWzuQmag', 'S2mD4CoBvX', 'UTVDbrOf97', 'ssdDnbJmlq', 'rPVDPd9CFH', 'Rpx', 'method_4', 'f6W', 'uL1' |
Source: 4si9noTBNw.exe, XBfD69peAHvVY8UF3TT.cs | High entropy of concatenated method names: 'F5cpgC6QtW', 'VMMpaihse5', 'AH4p0IBrBO', 'ptwpEHe1kF', 'rSSpLxprAI', 'N4EdFybVItwTjZuLoJXR', 'OZxctPbVPgVeAoweEerT', 'YwBbp2bVdLxMVrHE4bCe', 'VXuc6QbVKPCpBoOnT6Bs', 'ia0CQhbV6i5VsD11OlY0' |
Source: 4si9noTBNw.exe, v7JLgfmnZhPs34xuq6g.cs | High entropy of concatenated method names: 'ne0mdA7LSt', 'yRbmIEZZDn', 'OvQmKVVwqJ', 'dBhm6LkvXF', 'WrGmURAhc2', 'tLImmXLTsQ', 'JrImOCqrmb', 'p4Vm2jVAEY', 'VrYmfEpQvn', 'XRNmMUClx8' |
Source: 4si9noTBNw.exe, pFe3gJi7QqdnIyqQXqb.cs | High entropy of concatenated method names: 'qIP0CYbGS7IbdQFM2KkJ', 'tWvnYhbGCSBwGvUWHS2K', 'dLpkSvbGDSlWbdsrIhFN', 'CFGbfYbGuB9JLWNx99Qa', 'method_0', 'method_1', 'SaPiJlYmUG', 'O57i9uhMvZ', 'Wmyi10dK5U', 'cKTilbcRt9' |
Source: 4si9noTBNw.exe, DcGrRehNDCbMvGpdtfx.cs | High entropy of concatenated method names: 'a99', 'yzL', 'method_0', 'method_1', 'x77', 'dVwhZjeAFT', 'T7phFnYpV3', 'Dispose', 'D31', 'wNK' |
Source: 4si9noTBNw.exe, xUhT9qXM0nWka4MFgaY.cs | High entropy of concatenated method names: 'NIRYbdvk1M', 'reBxUpbNGTKUVrs18JSw', 'CjiNrYbNcihvw5Qijmkk', 'olgn64bN8HBwk0UyRjNH', 'WyaXHyRnqi', 'qjDX7Fnnvk', 'AR0Xy0SUk8', 'eieXJVsd9W', 'jurX9qf6hf', 'aO7X1P3grh' |
Source: 4si9noTBNw.exe, tAtdmM5W5cvLE9vcrdi.cs | High entropy of concatenated method names: 'DB4', 'method_0', 'method_1', 'method_2', 'method_3', 'method_4', 'method_5', 'A47', 'fC4', 'aK3' |
Source: 4si9noTBNw.exe, dZixGWxCMVqAxEPgteI.cs | High entropy of concatenated method names: 'Dispose', 'MoveNext', 'get_Current', 'Reset', 'get_Current', 'GetEnumerator', 'GetEnumerator', 'vheFywbeTfih2wuXOEZY', 'nD6F9AbeGSI422oZVnjN', 'mUXywJbeNshoqSB3N3Fb' |
Source: 4si9noTBNw.exe, WnFSh4INGesn0Omfn7P.cs | High entropy of concatenated method names: 'eVxIt4m1Sw', 'Mh6734bDMdk7Q4T0s3SX', 'hbwrZ9bD20OdhrpDkS0M', 'T1BmmFbDfF4fiJiiv8kW', 'U1J', 'P9X', 'lwrbd73vLcG', 'Rahbdyxq8CR', 'otLbU6wlWZg', 'imethod_0' |
Source: 4si9noTBNw.exe, kIAlNYWUsQJGa2nLW77.cs | High entropy of concatenated method names: 'KZtWOLgFKt', 'QPGW2Alo4d', 'method_0', 'method_1', 'I27', 'c6a', 'C5p', 'nQlWfvROgn', 'method_2', 'uc7' |
Source: 4si9noTBNw.exe, kQ9UZVwWXV7agOcR8a5.cs | High entropy of concatenated method names: 'method_0', 'NuGwuu0QHN', 'bchwSKy7m1', 'kinwCIUgRH', 'mArwx0ooHF', 'Xf8wsXK7ZB', 'PPGwRqhBc7', 'NFEyWjbZRkv6YQXwgQKV', 'N2XAOPbZxKXRxED7nbvC', 'pyywD7bZsDEq1Nldo5Tp' |
Source: 4si9noTBNw.exe, JDkuhaDiPkWdZ2SEtBM.cs | High entropy of concatenated method names: 'Owtu33OWC8', 't5NhQ5bjdZIqj0CIUAIb', 'uW0eI3bjnUdfxSrM4nNs', 'wwZfDJbjPG5V2iHAjreW', 'kt5', 'KT4DvkbRak', 'ReadByte', 'get_CanRead', 'get_CanSeek', 'get_CanWrite' |
Source: 4si9noTBNw.exe, xS6C9lUo50S81M07MXT.cs | High entropy of concatenated method names: 'lB8U5s894e', 'xaaUB0T26l', 'ipHUWKPF50', 'RnAUDQmSTi', 'ps2UuoqANl', 'XKAUSqA35i', 'HM8Mc2bSzEfZNgRQukW0', 'NJHfrybC4sJDK6thAisa', 'hvyU7UbCbU0VTbyXw7VB', 'YaVL5GbCnEUS92xVGBBw' |
Source: 4si9noTBNw.exe, XbT34TuCsvxNAZbQb5w.cs | High entropy of concatenated method names: 'Close', 'qL6', 'y7QusY0rbS', 'gXFuRuV5JA', 'vAkuA5pFTE', 'Write', 'get_CanRead', 'get_CanSeek', 'get_CanWrite', 'get_Length' |
Source: 4si9noTBNw.exe, Xr4BZ6I7w1uuAm4o5wd.cs | High entropy of concatenated method names: 'ODYIoOJGI1', 'aWHIp2pBt2', 'kDWI5Y5VE9', 'CGiZBtbWt3Zg68vnOBIg', 'Oc8iwobWFdur72dcf72q', 'fP0dZGbWVnTXkvaqrDil', 'V4YLJ5bWkeVXr1qLQ6HE', 'YXhIYp54Rg', 'QnwIhH9I1L', 'BdRlqQbWT47vxoDfeRWB' |
Source: 4si9noTBNw.exe, dYaZBM6mcwuESxyln3F.cs | High entropy of concatenated method names: 'uc262XAbkT', 'lJS6feBXrl', 'kBhXLJbuY7AiVqnb3UwX', 'HB1WUxbuXCSA6PIQsZkn', 'E9lPsrbuvmOeg4cws7WB', 'YHCKOZbuh5CwrGYxLpQG', 'lUwYFFbuQwWxc2Xsl0dt', 'XKkUr3buw7W1IEqgDXTl', 'cWus8Tbuob8yN656sClv', 'bMHw04bupDKoxIsTwPmH' |
Source: 4si9noTBNw.exe, oEc3ue613FL3MvSTJNo.cs | High entropy of concatenated method names: 'wLR6peSRWx', 'lTgo5UbueuYgZKAaBlNI', 's9wrvLburByRM9SDc1Jt', 'HCLf38bukM07UsfxBCaG', 'ckNWyrbujUndnXrs5g4V', 'GxJ5c6bugZW8JqVmLYvj', 'Rod6iaNMc7', 'Lv56XR5jcc', 'IMF6vIrYjo', 'Ksw6YKxUYb' |
Source: 4si9noTBNw.exe, nHX2MEukIVWBufLdnru.cs | High entropy of concatenated method names: 'OgLuef1seM', 'k6r', 'ueK', 'QH3', 'z24ur4scfh', 'Flush', 'NnHugN377k', 'SOOua8LqA3', 'Write', 'vpvu0XF7e2' |
Source: 4si9noTBNw.exe, c8ku1w5cBq4jZTbFAC1.cs | High entropy of concatenated method names: 'bi25GZimTN', 'ypF5NR1Rj7', 'BKC5T9yco8', 'XQK5ZsHTKh', 'AVZ5F6S9ea', 'FSP5VkQspD', 'CSs5tZN4vQ', 'Oyw5kMnvia', 'CWQ5j2aB8F', 'ORX5es4Js8' |
Source: 4si9noTBNw.exe, qHDvmF0J95Squ092xQv.cs | High entropy of concatenated method names: 'M2qKr1bLi6jNgXhG3Pm2', 'U0B6rebLXWVrBEwy46Sh', 'ciFErc26Ll', 'JJJyFibLQhEFQ8xhlHKi', 'Esmg84bLwoDyVsXBmTvm', 'vihpPYbLoCdks3k6vjUf', 'yAiyD8bLpvRnyVk3dyCH', 'P3APSCbL56NO5ghL4IVw', 'Rh0KuIbLB6HJt3p3hj7l', 'Q49IiibLWrHkc60i6rAU' |
Source: 4si9noTBNw.exe, mq5cUCL9gTpdAFriRFq.cs | High entropy of concatenated method names: 'mvmL5qZyqZ', 'GR5LBxpIel', 'L9JLWUIJ0c', 'idLLDyS1ld', 'bYjLuIoNH1', 'Iq8LSWZa9N', 'T0WLCdaU8A', 'bZrLx0bj3N', 'HZXLsn2ymD', 'nLVLRrsWel' |
Source: 4si9noTBNw.exe, UK5OS5HvBbSStYmCNhE.cs | High entropy of concatenated method names: 'gRI1MpCxpn', 'tvR13UT6uZ', 'CwpMGUbcbXXD6b3TbHbI', 'kD6tsVbAz89mOjJTd0Q8', 'fp8acdbc4KiYF7rp2NOF', 'dGnvribcnukb3qMi9JrF', 'HDD9kybcPeNqu2FqQBc4', 'vcb11wA26m', 'mC5l00bc6Ob4wZAmBtZV', 'cGfSaWbcIIflVWituDWX' |
Source: 4si9noTBNw.exe, w1nFLcYORxmNsmj3ISS.cs | High entropy of concatenated method names: 'ySuYWGpfsi', 'OxUYfnDaUo', 'cAgYMbEHcP', 'SZoY3qiyqI', 'loWYHapj0h', 'vcIY75Dhew', 'wqWYymckyF', 'BgjYJCBCsK', 'fEBY9VHbVA', 'KksY173U26' |
Source: 4si9noTBNw.exe, WdXmT4Bq5GMXSXAR5aP.cs | High entropy of concatenated method names: 'rsVW4QitoU', 'Y3NWbg1rp6', 'Yd7', 'OpdWnyneJM', 'l4iWPCcO9r', 'blqWdVsL1T', 'adSWIBZPT5', 'AR7JOIbkOTlj8vdleLtE', 'ttMmhobkU6RflL3MVqFJ', 'Pa7F7VbkmYSK4fIiUXi6' |
Source: 4si9noTBNw.exe, s755HHdQpQTvXoYuwE9.cs | High entropy of concatenated method names: 'VZq', 'KZ3', 'XA4', 'imethod_0', 'e23', 'xqabUPaOhiU', 'b3Obdbm8D8P', 'RbwIEDbBDHBsMyeSQLNc', 'k87y9cbBuG9Zd4XsJsAV', 'OPv9bDbBS7BqcMcjxi9j' |
Source: 4si9noTBNw.exe, i23bCaImM3FiHMs6XI0.cs | High entropy of concatenated method names: 'Rpx', 'KZ3', 'imethod_0', 'vmethod_0', 'mx8bUIOpmnY', 'b3Obdbm8D8P', 'l1XqmNbWYw6tbOSDupcw', 'I33laVbWh9IuExxh7xkX', 'AHYtwpbWQFOIyHHRdW6h', 'MvnwOBbWw0r5Scm064xn' |
Source: 4si9noTBNw.exe, exkhVEUO6n2eCNoAhev.cs | High entropy of concatenated method names: 'jIQUfnOBdL', 'lWnUMhEUDF', 'aQcU3FZV6i', 'iTZtTDbSp0aWoQ1l1gZ4', 'Xl0OW5bSweWwnmJ2JXm4', 'sVi5HobSoVhXKASpqNcU', 'QRGWB3bS5TJDmKBFtWrG', 'sYMw1xbSBoqQID0HG25y', 'klpLAMbSW1wi9vWc7wEg', 'GliNLRbSDDJ9tA8I3dor' |
Source: 4si9noTBNw.exe, devr50pZQ85kOqWOfsC.cs | High entropy of concatenated method names: 'lGfpVEUqc1', 'HSMptRV1sV', 'EKupkIh8yW', 'DC98x7bFLHu3NHsjxYAw', 'zryaUMbF0Moe3y9vJG7c', 'hNnNJrbFEs1KuDlRMJ8C', 'VqbnFTbFqLihx1kKoii1', 'tuHxHVbFz7wVHFtKC6B6', 'fngOBkbV4D38sqGcZKZ3', 'X378subVbvSRrqDWoiuY' |
Source: 4si9noTBNw.exe, aTMRHYRTKLTveGkebx5.cs | High entropy of concatenated method names: 'IHqbUhS0BBF', 'V1lRFT1tiL', 'yTXRVPLS2G', 'pltRtXjJN5', 'WbV6cabr8hdpHZjWDKoc', 'D19gjdbrGDLs9I3G4NHh', 'd2ZeHvbrNfmpIjV1ZW12', 'Bjb8bLbrToUaBCFwGn16', 'GvbabtbrZqWa1LlCnt6h', 'dVNUnLbrFaZbE8gvo5Nk' |
Source: 4si9noTBNw.exe, qZkXtQQYly7orSFlBuq.cs | High entropy of concatenated method names: 'UIsQQwFpAd', 'j7DQwMNyea', 'qWCQokUHBu', 'NhlQp1MKKW', 'TAtQ5Pmotv', 'xttCtIbZmno0D1OGHEmB', 'gjxF2SbZ66McxlABi8QE', 'J1qFkpbZUp8mrPcFAxUV', 'zWDaQ1bZOpneMesSjR0G', 'eEkK11bZ2dl42FooyJpS' |
Source: 4si9noTBNw.exe, sNS8OEaWkVg5r78UVE4.cs | High entropy of concatenated method names: 'N0fauVsXQj', 'I78aShYnI6', 'iwDaChDZsW', 'J3FaxHIdUW', 'Dispose', 'YtgGCZbEu0gGlvcDx8h3', 'qRaecMbES31XO5s1Uadb', 'i73NBpbECSYREQJxMPKQ', 'Vq9kcEbEx5DH8kNdjX7G', 'MupVa0bEsVcrGJNNePbd' |
Source: 4si9noTBNw.exe, bLlsVg5U0b9kkMMYwf0.cs | High entropy of concatenated method names: 'dSD5OrUJLT', 'tUp52Ucnu8', 'aSS5fNTj8Q', 'yudvfrbViq1DZDstnDZw', 'EnDuMPbV11m9DALfSoaF', 'UFeNTkbVlXkCoQJvpZJR', 'rG9818bVXt99asAguC2r', 'xcywh5bVv3N59lTMgHXF' |
Source: 4si9noTBNw.exe, Pc8anUdAnCpDbgdaux4.cs | High entropy of concatenated method names: 'R3AdLySl5F', 'jyboqjbW2XBC850y9Vf6', 'XZMtFibWfkgaRW1CEDOi', 'YqZridbWm2Uv5Rr996HJ', 'HFPS5nbWOLLvfOrJCGUG', 'BAatkJbW39yIUIdvwguE', 'fVqg6SbWHXrLvZ4ZKDfH', 'z3u69VbW7erJqNPLnVAp', 'FPXIKXU3Ff', 'WcT4TabW1nyI4iWUbSVy' |
Source: 4si9noTBNw.exe, XfTEA56MAEn0pibsMs3.cs | High entropy of concatenated method names: 'P9X', 'Rc0bdvvHoVy', 'vmethod_0', 'imethod_0', 'uqdTG8buDDyOqsqdrfIS', 'WkoaNTbuB0B2CJe6rZHd', 'waoM3lbuWni9cYrUc7PE', 'Y2peAJbuuJoyenhD0jgJ', 'W9EJaIbuSsKyuHFi4WkU', 'pMhCv4buCk0jnsrDx8ZX' |
Source: 4si9noTBNw.exe, xWFdtBKhISLiadldGS0.cs | High entropy of concatenated method names: 'dnBKWfA0Mh', 'jhdrMObDVDjE4klqmWrw', 'PqUsZDbDZHUL2VSNoLbE', 'z9ZPpHbDFZoRcNCYup3B', 'mwMYb5bDt1UGnec0hhUK', 'E94', 'P9X', 'vmethod_0', 'a77bdlNbLB5', 'KRVbUmrjJVx' |
Source: 4si9noTBNw.exe, nYHJ2QmY2gKQjF75k8S.cs | High entropy of concatenated method names: 'ouGwC5bskxre0RhpNH0f', 'QF0hmIbsjTL2fWNN2l8h', 'd9a3qY4l8M', 'dOGxSqbsaYKNT2EOQhD3', 'TZeflabsrlf5r0Qi9CAF', 'sfFRgsbsgqiSQdce7OyQ', 'Stahc0bs0m7iBY9orVUb', 'vZEMKWbsEj6fteh4V6Qm', 'iCHHbHBvxl', 'tEpVvdbR4UBju4RwXU77' |
Source: 4si9noTBNw.exe, igrYyI1r1tjnI4HpVoF.cs | High entropy of concatenated method names: 'm1I', 'G4q', 'w29', 'jnObUMxm20c', 'avMbdZIwUjD', 'Bgnk6gbc8oHRtp838dcM', 'ALA9TPbcGTGJQVqKvkCa', 'u6YeOGbcN5iuxbpSnqSb', 'zjSQgNbcT57txjpIN1yW', 'R71WHvbcZrEofYYHtOWt' |
Source: 4si9noTBNw.exe, X6jkY6BT2lBlFy7kCW4.cs | High entropy of concatenated method names: 'HULBFSjL4V', 'btsBVQ7lDp', 'J0ABtUVDhY', 'OeyBkbu6vA', 'TtRBjJr5Yd', 'HQALHQbtLKRiX3vhdaLX', 'HrqQGabtq4YvDImfOA2v', 'YF3w61btzLrGC3Sd6aCL', 'XfbpHubt0Q9sSBuCDmvs', 'aKfAvabtEmTjuCUx9nbf' |
Source: 4si9noTBNw.exe, VUgsBHISUExAOLUQhEe.cs | High entropy of concatenated method names: 'l29', 'P9X', 'vmethod_0', 'LMwbd2pFLMe', 'h24Ixo8o1L', 'imethod_0', 'fEYxXmbWeYUN5BQVTekc', 'ds0wMBbWrnU1ZaQMwCPe', 'C0rUbobWgaYywEeWTr4c', 'VFS9JJbWaNqJ7PrKOREx' |
Source: 4si9noTBNw.exe, M2vxprlRESRyCyyr6nM.cs | High entropy of concatenated method names: 'N2N', 'GsxbUHqRMjt', 'TMblclHFKy', 'XZSbU7Cvoc4', 'chWgiBb8DCJThPoU0eKE', 'y9Ilk6b8uwAl3gM4iOPU', 'akSHh7b8BdvTC5jbufao', 'ddas5Ub8Wom0AIlrKgba', 'stcslRb8SKH5NwRKS01B', 'IO4wh5b8CyygdF5CQ8K9' |
Source: 4si9noTBNw.exe, Bpr2BUnlbPsn6tabHbe.cs | High entropy of concatenated method names: 'UPjnXWn6eO', 'FiXnvwagEi', 'Qm3CY4bpoYKqxDnnDGk6', 'hHYpp1bpQKrnfs3xSBpy', 'SiMym5bpwlG4kHZeNGkH', 'eN1fePbppOCDBHagSAHT', 'EgdSlBbp5NdmkU3sBKVn', 'PLxP0XbpB7n2Mil5qiBO', 'vQm28cbpWnVxmr6Yyhge', 'puvTtVbpDglEIMO5aAbd' |
Source: 4si9noTBNw.exe, zVn3jelaEra36uJLPdf.cs | High entropy of concatenated method names: 'w52', 'o38', 'vmethod_0', 'iHWlEYOnXG', 'GjGbU9PVZEy', 'H7rhIAb8aEwXgHh2FwSd', 'r2uesBb8r4TIJg8gmJRp', 'tXsnhOb8gIF1AuNI5MFm', 'tVDOIob80lK9sonWr9rc', 'jGp6sEb8E5abYw96t5Qb' |
Source: 4si9noTBNw.exe, a6rLn8i2je1HGHZjrwB.cs | High entropy of concatenated method names: 'Rrr', 'y1x', 'ok6bUXV7AUW', 'y82bUvGpOJ5', 'osrj78bGfL42REPeXjD1', 'iZnibjbGMB0X7a1ZDkfm', 'p5a24DbG3vuqtjlagoUd', 'Eal5XWbGHZaNyp2S4Dw3', 'Q6VFxObG7VaK30rtqsEU', 'qxgieUbGyVPm3Rs9Q04b' |
Source: 4si9noTBNw.exe, HsIB8XbqSEpwb5HQVZT.cs | High entropy of concatenated method names: 'KZ3', 'fW4', 'imethod_0', 'U7v', 'PHrbUb8NgQp', 'b3Obdbm8D8P', 'XY8tHBboz0S8DNghsf7w', 'wCoJbrbp48mX0oqYlpdv', 's019IRbpbX7k6VIOntwK', 'ubCd6hbpnoDfOC0GE4hD' |
Source: 4si9noTBNw.exe, hNmGcjnWuBwgG4TaA1J.cs | High entropy of concatenated method names: 'gPMn84vLUI', 'z57nGMZEPD', 'HLwWYebp8GXYvELDUjLR', 'cXSR6WbpASdXy3rQv698', 'MBli4XbpcCLJ0EirYyut', 'h56qUnbpG6ZMyu72To2E', 'VbinFFWl8f', 'VrhWNybpTDH59T5KDiPx', 'jvR2L2bpZjf6PZlmRq6Q', 'KY6qE1bpFA3j1qLdLMpj' |
Source: 4si9noTBNw.exe, auDqZ504ahmB8YKhbCs.cs | High entropy of concatenated method names: 'Nns0d4qdJV', 'T5V0IQXf71', 'PRbqGNbLPAhtpv3esV5y', 'bwOWgLbLdf2lSxlvY0Vm', 'IVmMUebLb33xRGVvZluq', 'ab4OJ4bLnmR6MGtbWScb', 'fbXBDLbLIq9Z7vH07t91', 'wdNXIWbLKlqp4EPAnO29', 'kEB0nCdm4o', 'uZAAxtbELgDnPjdHiCmW' |
Source: 4si9noTBNw.exe, EOkjgwaMgaPg453Paua.cs | High entropy of concatenated method names: 'iPsa7G6uTw', 'Lf2a11gc4k', 'c2maXrB7Ku', 'mYvavf6qNv', 'VaiaYAB9Em', 'pDEahaTuEO', 'IM9aQ96huP', 'wtiaw80H6x', 'Dispose', 'QAuie2bEoIF47hqDmcXy' |
Source: 4si9noTBNw.exe, JeU0gcLAAXG4IMMUDjl.cs | High entropy of concatenated method names: 'pMFbKDrBggV', 'gLibKuaDXFa', 'eVtbKS1AHWT', 'svrbKCYVbLJ', 'yRebKxUvNbt', 'EGQbKsoWlik', 'sMpbKRF20Ka', 'q2DqIsN4ss', 'T6XbKAO9pQu', 'wmTbKcSTJp7' |
Source: 4si9noTBNw.exe, R3SxwQRWpBQ8UJpuGvO.cs | High entropy of concatenated method names: 'dqkRue3OWe', 'nwbRSnRtaj', 'H1TRCx58BI', 'LXHRxbMA92', 'PbkRsfIbB4', 'n0qRRAONde', 'aZJRASC3No', 'M53RcCcODN', 'GhwR8fQvQb', 'SrFRGqBrkG' |
Source: 4si9noTBNw.exe, DZTwLupqmEQneagKYE0.cs | High entropy of concatenated method names: 'SMj54Ex8W5', 'SvC5bDWhPB', 'nTv5nbPbya', 'NFc5PNb1Xo', 'FQm5dcYOsu', 'eIT5IRuUZY', 'g6UZxDbVMTFkZEfk2YpQ', 'eST7isbV2Y89SJNPMFd7', 'HFanchbVf3bCTUrLByHf', 'Pt4bJxbV3VVYdkLYauqY' |
Source: 4si9noTBNw.exe, KULE0rAWN9ZujanSfHO.cs | High entropy of concatenated method names: 'Q1nAueH0BB', 'hrLASB7BV6', 'OlBACscp1W', 'TRgAxdSO70', 'gEjAsiYH8D', 'JYAARBOpZ6', 'vSsAApFXHX', 'otMActFAS5', 'c2WA8XaSX9', 'bl6AGSNgS5' |
Source: 4si9noTBNw.exe, rcZ3xnoP8aNA0dMsIPS.cs | High entropy of concatenated method names: 'method_0', 'YU8', 'method_1', 'method_2', 't0ToI6ib9M', 'Write', 'd6ZoKKx7KO', 'HTno6IsDdD', 'Flush', 'vl7' |
Source: 4si9noTBNw.exe, wpuioCbrL3yE90PkSdk.cs | High entropy of concatenated method names: 'P9X', 'nlabaeJTFf', 'PRwbU407uxA', 'imethod_0', 'o01b0IKNQx', 'tBJkIvboghjjv1jXn2c6', 'BoW0tgboaolAVexGZZik', 'gSpTSdboeYyYOYCaycMD', 'NUVjkUborcPB6gbMBZJ2', 'd1OD5Cbo0BDUKlULISsB' |
Source: 4si9noTBNw.exe, AWiGJVPkeR19qtmQDPE.cs | High entropy of concatenated method names: 'eDBdPGvwwQ', 'pEFdd0J6rk', 'uUEdIJYt6T', 'gJDa58bBfP3xjKP4anS7', 'wvgoqRbBOpI1LXmP1JOQ', 'AgHvksbB2TM4yrkYhT7t', 'aYDd2hRnGZ', 'gCxrJEbB7m8UeibCXaib', 'jZ3JJIbB37FYffYKRlv6', 'nlEC8DbBHXOFu01gxkQM' |
Source: 4si9noTBNw.exe, uNgXnZA01cfOCuKYw2N.cs | High entropy of concatenated method names: 'e64ALun2KV', 'GopAqlkiJl', 'qZsAzPfr0O', 'vgFc4UmfEZ', 'ERKcbdCRIg', 'l26cnWANt4', 'xJKcP3Iurw', 'TNkcdPIR61', 'iZVcIYZIHh', 'ffmcK7JYZm' |
Source: 4si9noTBNw.exe, x8GyWym3dXFv5kVJ1ls.cs | High entropy of concatenated method names: 'q76', 'method_0', 'p9e', 'hkB', 'method_1', 'method_2', 'PgXfNrbCcniCw0CuURJ6', 'Qd5DHmbC86wm9eanGyf1', 'M2tfuCbCGPbCJbcwRiUd', 'f8QrLFbCNKM0HC9SjuvM' |
Source: 4si9noTBNw.exe, IXip9H6WwHkM7v08KL3.cs | High entropy of concatenated method names: 'SGV6u0Gcfs', 'm8g6SIyCRr', 'OkxKu7buLx51QkkwALAM', 'MpK4YWbu0CDIhjNMt8m0', 'yD5edVbuE9cdJxslqvBl', 'DbSykPbuqcLcq0iK8r4I', 's1rf6qbuzWVrFjJEnY0t', 'Nu6Yq2bS4fSQUTFpov5v', 'KCpvYqbSbs0KQqUH964f', 'KcOMyYbSnyx7QKBnLGW3' |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Java\VTixufCejPQZEvXiB.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Java\VTixufCejPQZEvXiB.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Java\VTixufCejPQZEvXiB.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Java\VTixufCejPQZEvXiB.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Java\VTixufCejPQZEvXiB.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Java\VTixufCejPQZEvXiB.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Java\VTixufCejPQZEvXiB.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Java\VTixufCejPQZEvXiB.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Java\VTixufCejPQZEvXiB.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Java\VTixufCejPQZEvXiB.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Java\VTixufCejPQZEvXiB.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Java\VTixufCejPQZEvXiB.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Java\VTixufCejPQZEvXiB.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Java\VTixufCejPQZEvXiB.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Java\VTixufCejPQZEvXiB.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Java\VTixufCejPQZEvXiB.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Java\VTixufCejPQZEvXiB.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Java\VTixufCejPQZEvXiB.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Java\VTixufCejPQZEvXiB.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Java\VTixufCejPQZEvXiB.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Java\VTixufCejPQZEvXiB.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Java\VTixufCejPQZEvXiB.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Java\VTixufCejPQZEvXiB.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Java\VTixufCejPQZEvXiB.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Java\VTixufCejPQZEvXiB.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Java\VTixufCejPQZEvXiB.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Java\VTixufCejPQZEvXiB.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Java\VTixufCejPQZEvXiB.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Java\VTixufCejPQZEvXiB.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Java\VTixufCejPQZEvXiB.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Java\VTixufCejPQZEvXiB.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Java\VTixufCejPQZEvXiB.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Java\VTixufCejPQZEvXiB.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Java\VTixufCejPQZEvXiB.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Java\VTixufCejPQZEvXiB.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Java\VTixufCejPQZEvXiB.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Java\VTixufCejPQZEvXiB.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Java\VTixufCejPQZEvXiB.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Java\VTixufCejPQZEvXiB.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Java\VTixufCejPQZEvXiB.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Java\VTixufCejPQZEvXiB.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Java\VTixufCejPQZEvXiB.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Java\VTixufCejPQZEvXiB.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Java\VTixufCejPQZEvXiB.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Java\VTixufCejPQZEvXiB.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Java\VTixufCejPQZEvXiB.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Java\VTixufCejPQZEvXiB.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Java\VTixufCejPQZEvXiB.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Java\VTixufCejPQZEvXiB.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Java\VTixufCejPQZEvXiB.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Java\VTixufCejPQZEvXiB.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Java\VTixufCejPQZEvXiB.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Java\VTixufCejPQZEvXiB.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Java\VTixufCejPQZEvXiB.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Java\VTixufCejPQZEvXiB.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Java\VTixufCejPQZEvXiB.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Java\VTixufCejPQZEvXiB.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Java\VTixufCejPQZEvXiB.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Java\VTixufCejPQZEvXiB.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Java\VTixufCejPQZEvXiB.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Java\VTixufCejPQZEvXiB.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Program Files (x86)\Java\VTixufCejPQZEvXiB.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\AccountPictures\winlogon.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\AccountPictures\winlogon.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\AccountPictures\winlogon.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\AccountPictures\winlogon.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\AccountPictures\winlogon.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\AccountPictures\winlogon.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\AccountPictures\winlogon.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\AccountPictures\winlogon.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\AccountPictures\winlogon.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\AccountPictures\winlogon.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\AccountPictures\winlogon.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\AccountPictures\winlogon.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\AccountPictures\winlogon.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\AccountPictures\winlogon.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\AccountPictures\winlogon.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\AccountPictures\winlogon.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\AccountPictures\winlogon.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\AccountPictures\winlogon.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\AccountPictures\winlogon.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\AccountPictures\winlogon.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\AccountPictures\winlogon.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\AccountPictures\winlogon.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\AccountPictures\winlogon.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\AccountPictures\winlogon.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\AccountPictures\winlogon.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\AccountPictures\winlogon.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\AccountPictures\winlogon.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\AccountPictures\winlogon.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\AccountPictures\winlogon.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\AccountPictures\winlogon.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\AccountPictures\winlogon.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\AccountPictures\winlogon.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\AccountPictures\winlogon.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\AccountPictures\winlogon.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\AccountPictures\winlogon.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\AccountPictures\winlogon.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\AccountPictures\winlogon.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\AccountPictures\winlogon.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\AccountPictures\winlogon.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\AccountPictures\winlogon.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\AccountPictures\winlogon.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\AccountPictures\winlogon.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\AccountPictures\winlogon.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\AccountPictures\winlogon.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\AccountPictures\winlogon.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\AccountPictures\winlogon.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\AccountPictures\winlogon.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\AccountPictures\winlogon.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\AccountPictures\winlogon.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\AccountPictures\winlogon.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\AccountPictures\winlogon.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\AccountPictures\winlogon.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\AccountPictures\winlogon.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\AccountPictures\winlogon.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\AccountPictures\winlogon.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\AccountPictures\winlogon.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\AccountPictures\winlogon.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\AccountPictures\winlogon.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\AccountPictures\winlogon.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\AccountPictures\winlogon.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\AccountPictures\winlogon.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\Public\AccountPictures\winlogon.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe TID: 7616 | Thread sleep time: -922337203685477s >= -30000s | Jump to behavior |
Source: C:\Program Files (x86)\Java\VTixufCejPQZEvXiB.exe TID: 7828 | Thread sleep time: -922337203685477s >= -30000s | Jump to behavior |
Source: C:\Program Files (x86)\Java\VTixufCejPQZEvXiB.exe TID: 7844 | Thread sleep time: -922337203685477s >= -30000s | Jump to behavior |
Source: C:\Users\Public\AccountPictures\winlogon.exe TID: 8320 | Thread sleep time: -922337203685477s >= -30000s | Jump to behavior |
Source: C:\Users\Public\AccountPictures\winlogon.exe TID: 8336 | Thread sleep time: -922337203685477s >= -30000s | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 7780 | Thread sleep count: 1582 > 30 | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 7324 | Thread sleep time: -9223372036854770s >= -30000s | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 8024 | Thread sleep time: -1844674407370954s >= -30000s | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 7872 | Thread sleep count: 1521 > 30 | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 8164 | Thread sleep time: -12912720851596678s >= -30000s | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 8056 | Thread sleep time: -922337203685477s >= -30000s | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 7888 | Thread sleep count: 2088 > 30 | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 7340 | Thread sleep time: -922337203685477s >= -30000s | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 8064 | Thread sleep time: -922337203685477s >= -30000s | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 7968 | Thread sleep count: 1549 > 30 | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 8160 | Thread sleep time: -922337203685477s >= -30000s | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 8000 | Thread sleep time: -922337203685477s >= -30000s | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 7792 | Thread sleep count: 1641 > 30 | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 8172 | Thread sleep time: -11068046444225724s >= -30000s | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 7976 | Thread sleep time: -922337203685477s >= -30000s | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 7860 | Thread sleep count: 2198 > 30 | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 8156 | Thread sleep time: -922337203685477s >= -30000s | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 7868 | Thread sleep time: -922337203685477s >= -30000s | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe TID: 8352 | Thread sleep time: -922337203685477s >= -30000s | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe TID: 8344 | Thread sleep time: -922337203685477s >= -30000s | |
Source: C:\Program Files\Windows Defender\en-GB\conhost.exe TID: 8328 | Thread sleep time: -922337203685477s >= -30000s | |
Source: C:\Program Files\Windows Defender\en-GB\conhost.exe TID: 8332 | Thread sleep time: -922337203685477s >= -30000s | |
Source: C:\Recovery\VTixufCejPQZEvXiB.exe TID: 8384 | Thread sleep time: -922337203685477s >= -30000s | |
Source: C:\Program Files\Windows Defender\en-GB\conhost.exe TID: 8444 | Thread sleep time: -922337203685477s >= -30000s | |
Source: C:\Users\Public\AccountPictures\winlogon.exe TID: 8640 | Thread sleep time: -922337203685477s >= -30000s | |
Source: C:\Program Files\Windows Defender\en-GB\conhost.exe TID: 8776 | Thread sleep time: -922337203685477s >= -30000s | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe TID: 8936 | Thread sleep time: -30000s >= -30000s | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe TID: 9060 | Thread sleep time: -34126476536362649s >= -30000s | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe TID: 9060 | Thread sleep time: -600000s >= -30000s | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe TID: 9060 | Thread sleep time: -599781s >= -30000s | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe TID: 9060 | Thread sleep time: -598843s >= -30000s | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe TID: 9060 | Thread sleep time: -598625s >= -30000s | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe TID: 9060 | Thread sleep time: -598500s >= -30000s | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe TID: 9060 | Thread sleep time: -598343s >= -30000s | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe TID: 9044 | Thread sleep time: -7200000s >= -30000s | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe TID: 9060 | Thread sleep time: -597578s >= -30000s | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe TID: 9060 | Thread sleep time: -597359s >= -30000s | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe TID: 9060 | Thread sleep time: -597208s >= -30000s | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe TID: 9060 | Thread sleep time: -597068s >= -30000s | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe TID: 9060 | Thread sleep time: -596906s >= -30000s | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe TID: 9060 | Thread sleep time: -596761s >= -30000s | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe TID: 9060 | Thread sleep time: -596640s >= -30000s | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe TID: 9044 | Thread sleep time: -300000s >= -30000s | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe TID: 9060 | Thread sleep time: -596468s >= -30000s | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe TID: 9060 | Thread sleep time: -596347s >= -30000s | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe TID: 9060 | Thread sleep time: -596218s >= -30000s | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe TID: 9060 | Thread sleep time: -596108s >= -30000s | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe TID: 9060 | Thread sleep time: -595988s >= -30000s | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe TID: 9060 | Thread sleep time: -595859s >= -30000s | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe TID: 9060 | Thread sleep time: -595721s >= -30000s | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe TID: 9060 | Thread sleep time: -595580s >= -30000s | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe TID: 9060 | Thread sleep time: -595125s >= -30000s | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe TID: 9060 | Thread sleep time: -594822s >= -30000s | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe TID: 9060 | Thread sleep time: -594669s >= -30000s | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe TID: 9060 | Thread sleep time: -594495s >= -30000s | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe TID: 9060 | Thread sleep time: -594387s >= -30000s | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe TID: 9060 | Thread sleep time: -594278s >= -30000s | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe TID: 9060 | Thread sleep time: -594171s >= -30000s | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe TID: 9060 | Thread sleep time: -594062s >= -30000s | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe TID: 9060 | Thread sleep time: -593950s >= -30000s | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe TID: 9060 | Thread sleep time: -593842s >= -30000s | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe TID: 9060 | Thread sleep time: -593734s >= -30000s | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe TID: 9060 | Thread sleep time: -593625s >= -30000s | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe TID: 9060 | Thread sleep time: -593509s >= -30000s | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe TID: 9060 | Thread sleep time: -593399s >= -30000s | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe TID: 9060 | Thread sleep time: -593296s >= -30000s | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe TID: 9060 | Thread sleep time: -593187s >= -30000s | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe TID: 9060 | Thread sleep time: -593078s >= -30000s | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe TID: 9060 | Thread sleep time: -592968s >= -30000s | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe TID: 9060 | Thread sleep time: -592859s >= -30000s | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe TID: 9060 | Thread sleep time: -592726s >= -30000s | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe TID: 9060 | Thread sleep time: -592512s >= -30000s | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe TID: 9060 | Thread sleep time: -591978s >= -30000s | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe TID: 9060 | Thread sleep time: -591858s >= -30000s | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe TID: 9060 | Thread sleep time: -591749s >= -30000s | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe TID: 9060 | Thread sleep time: -591640s >= -30000s | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe TID: 9060 | Thread sleep time: -591528s >= -30000s | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe TID: 9060 | Thread sleep time: -591420s >= -30000s | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe TID: 9060 | Thread sleep time: -591309s >= -30000s | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe TID: 9060 | Thread sleep time: -591177s >= -30000s | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe TID: 9060 | Thread sleep time: -591048s >= -30000s | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe TID: 9060 | Thread sleep time: -590916s >= -30000s | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe TID: 9060 | Thread sleep time: -590773s >= -30000s | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe TID: 9060 | Thread sleep time: -590656s >= -30000s | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe TID: 9060 | Thread sleep time: -590546s >= -30000s | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe TID: 9060 | Thread sleep time: -590437s >= -30000s | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe TID: 9060 | Thread sleep time: -590326s >= -30000s | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe TID: 9060 | Thread sleep time: -590201s >= -30000s | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe TID: 9060 | Thread sleep time: -590093s >= -30000s | |
Source: C:\Windows\System32\svchost.exe TID: 9140 | Thread sleep time: -30000s >= -30000s | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Users\user\Desktop\4si9noTBNw.exe VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Security\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Security.dll VolumeInformation | Jump to behavior |
Source: C:\Program Files (x86)\Java\VTixufCejPQZEvXiB.exe | Queries volume information: C:\Program Files (x86)\Java\VTixufCejPQZEvXiB.exe VolumeInformation | Jump to behavior |
Source: C:\Program Files (x86)\Java\VTixufCejPQZEvXiB.exe | Queries volume information: C:\Program Files (x86)\Java\VTixufCejPQZEvXiB.exe VolumeInformation | Jump to behavior |
Source: C:\Users\Public\AccountPictures\winlogon.exe | Queries volume information: C:\Users\Public\AccountPictures\winlogon.exe VolumeInformation | Jump to behavior |
Source: C:\Users\Public\AccountPictures\winlogon.exe | Queries volume information: C:\Users\Public\AccountPictures\winlogon.exe VolumeInformation | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\ VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-GroupPolicy-ClientTools-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-AppManagement-AppV-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\AppvClient\Microsoft.AppV.AppVClientPowerShell.dll VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1865.cat VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-Package~31bf3856ad364e35~amd64~en-GB~10.0.19041.1151.cat VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\BitLocker\Microsoft.BitLocker.Structures.dll VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\ VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-GroupPolicy-ClientTools-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-AppManagement-AppV-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\AppvClient\Microsoft.AppV.AppVClientPowerShell.dll VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1865.cat VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-Package~31bf3856ad364e35~amd64~en-GB~10.0.19041.1151.cat VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\BitLocker\Microsoft.BitLocker.Structures.dll VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\ VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-GroupPolicy-ClientTools-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-AppManagement-AppV-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\AppvClient\Microsoft.AppV.AppVClientPowerShell.dll VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1865.cat VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-Package~31bf3856ad364e35~amd64~en-GB~10.0.19041.1151.cat VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\BitLocker\Microsoft.BitLocker.Structures.dll VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\ VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-GroupPolicy-ClientTools-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-AppManagement-AppV-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\AppvClient\Microsoft.AppV.AppVClientPowerShell.dll VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1865.cat VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-Package~31bf3856ad364e35~amd64~en-GB~10.0.19041.1151.cat VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\BitLocker\Microsoft.BitLocker.Structures.dll VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\ VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-GroupPolicy-ClientTools-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-AppManagement-AppV-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\AppvClient\Microsoft.AppV.AppVClientPowerShell.dll VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1865.cat VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-Package~31bf3856ad364e35~amd64~en-GB~10.0.19041.1151.cat VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\BitLocker\Microsoft.BitLocker.Structures.dll VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\ VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-GroupPolicy-ClientTools-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-AppManagement-AppV-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\AppvClient\Microsoft.AppV.AppVClientPowerShell.dll VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1865.cat VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-Package~31bf3856ad364e35~amd64~en-GB~10.0.19041.1151.cat VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\BitLocker\Microsoft.BitLocker.Structures.dll VolumeInformation | |
Source: C:\Windows\System32\cmd.exe | Queries volume information: C:\ VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Users\user\Desktop\4si9noTBNw.exe VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Users\user\Desktop\4si9noTBNw.exe VolumeInformation | |
Source: C:\Program Files\Windows Defender\en-GB\conhost.exe | Queries volume information: C:\Program Files\Windows Defender\en-GB\conhost.exe VolumeInformation | |
Source: C:\Program Files\Windows Defender\en-GB\conhost.exe | Queries volume information: C:\Program Files\Windows Defender\en-GB\conhost.exe VolumeInformation | |
Source: C:\Recovery\VTixufCejPQZEvXiB.exe | Queries volume information: C:\Recovery\VTixufCejPQZEvXiB.exe VolumeInformation | |
Source: C:\Program Files\Windows Defender\en-GB\conhost.exe | Queries volume information: C:\Program Files\Windows Defender\en-GB\conhost.exe VolumeInformation | |
Source: C:\Users\Public\AccountPictures\winlogon.exe | Queries volume information: C:\Users\Public\AccountPictures\winlogon.exe VolumeInformation | |
Source: C:\Program Files\Windows Defender\en-GB\conhost.exe | Queries volume information: C:\Program Files\Windows Defender\en-GB\conhost.exe VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Users\user\Desktop\4si9noTBNw.exe VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Security\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Security.dll VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\calibril.ttf VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\calibrii.ttf VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\calibrili.ttf VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\calibrib.ttf VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\calibriz.ttf VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\cambria.ttc VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\cambriai.ttf VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\cambriab.ttf VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\cambria.ttc VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\Candaral.ttf VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\Candarai.ttf VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\Candarali.ttf VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\Candarab.ttf VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\Candaraz.ttf VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\comic.ttf VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\comici.ttf VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\comicbd.ttf VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\comicz.ttf VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\constan.ttf VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\constani.ttf VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\constanb.ttf VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\constanz.ttf VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\corbel.ttf VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\corbell.ttf VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\corbeli.ttf VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\corbelli.ttf VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\corbelb.ttf VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\corbelz.ttf VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\cour.ttf VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\couri.ttf VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\courbd.ttf VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\courbi.ttf VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\ebrima.ttf VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\ebrimabd.ttf VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\framd.ttf VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\FRADM.TTF VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\framdit.ttf VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\FRADMIT.TTF VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\FRAHV.TTF VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\FRAHVIT.TTF VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\gadugi.ttf VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\gadugib.ttf VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\georgiai.ttf VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\georgiab.ttf VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\georgiaz.ttf VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\impact.ttf VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\Inkfree.ttf VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\javatext.ttf VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\LeelawUI.ttf VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\LeelUIsl.ttf VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\LeelaUIb.ttf VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\lucon.ttf VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\l_10646.ttf VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\malgun.ttf VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\malgunsl.ttf VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\malgunbd.ttf VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\himalaya.ttf VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\msjh.ttc VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\msjhl.ttc VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\msjhbd.ttc VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\msjh.ttc VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\msjhl.ttc VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\msjhbd.ttc VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\ntailu.ttf VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\ntailub.ttf VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\phagspa.ttf VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\phagspab.ttf VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\micross.ttf VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\taileb.ttf VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\msyh.ttc VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\msyhl.ttc VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\msyhbd.ttc VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\msyh.ttc VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\msyhl.ttc VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\msyi.ttf VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\mingliub.ttc VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\mingliub.ttc VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\mingliub.ttc VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\monbaiti.ttf VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\msgothic.ttc VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\msgothic.ttc VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\msgothic.ttc VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\mvboli.ttf VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\mmrtext.ttf VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\mmrtextb.ttf VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\Nirmala.ttf VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\NirmalaS.ttf VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\NirmalaB.ttf VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\pala.ttf VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\palai.ttf VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\palab.ttf VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\palabi.ttf VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\segoepr.ttf VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\segoeprb.ttf VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\segoesc.ttf VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\segoescb.ttf VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\seguihis.ttf VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\simsun.ttc VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\simsunb.ttf VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\Sitka.ttc VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\SitkaI.ttc VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\SitkaB.ttc VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\SitkaZ.ttc VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\SitkaB.ttc VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\SitkaZ.ttc VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\Sitka.ttc VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\SitkaI.ttc VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\SitkaB.ttc VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\SitkaI.ttc VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\sylfaen.ttf VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\symbol.ttf VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\tahoma.ttf VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\tahomabd.ttf VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\timesi.ttf VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\timesbd.ttf VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\timesbi.ttf VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\trebuc.ttf VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\trebucit.ttf VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\trebucbd.ttf VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\trebucbi.ttf VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\verdana.ttf VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\verdanai.ttf VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\verdanab.ttf VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\verdanaz.ttf VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\webdings.ttf VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\wingding.ttf VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\YuGothR.ttc VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\YuGothM.ttc VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\YuGothL.ttc VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\YuGothB.ttc VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\YuGothM.ttc VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\holomdl2.ttf VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\AGENCYR.TTF VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\AGENCYB.TTF VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\BKANT.TTF VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\ANTQUAB.TTF VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\ANTQUABI.TTF VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\BERNHC.TTF VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\BOD_R.TTF VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\BOD_CR.TTF VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\BOD_BLAR.TTF VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\BOD_CI.TTF VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\BOD_BLAI.TTF VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\BOD_CBI.TTF VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\BOOKOS.TTF VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\BOOKOSB.TTF VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\BOOKOSI.TTF VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\BRADHITC.TTF VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\BRITANIC.TTF VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\BRLNSR.TTF VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\BROADW.TTF VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\BRUSHSCI.TTF VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\BSSYM7.TTF VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\CALIFR.TTF VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\CALISTB.TTF VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\CENTAUR.TTF VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\CENTURY.TTF VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\COOPBL.TTF VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\COPRGTB.TTF VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\ERASMD.TTF VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\ERASLGHT.TTF VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\FRABKIT.TTF VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\GILI____.TTF VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\GOUDOS.TTF VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\GOUDOSB.TTF VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\GOUDYSTO.TTF VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\HARLOWSI.TTF VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\HARNGTON.TTF VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\HATTEN.TTF VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\HTOWERTI.TTF VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\INFROMAN.TTF VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\ITCBLKAD.TTF VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\ITCKRIST.TTF VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\LATINWD.TTF VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\LBRITEDI.TTF VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\LEELAWDB.TTF VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\LFAXI.TTF VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\MSUIGHUR.TTF VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\OCRAEXT.TTF VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\OLDENGL.TTF VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\ONYX.TTF VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\PARCHM.TTF VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\PERBI___.TTF VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\PERTILI.TTF VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\POORICH.TTF VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\REFSAN.TTF VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\REFSPCL.TTF VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\ROCK.TTF VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\ROCKI.TTF VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\ROCKB.TTF VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\ROCKEB.TTF VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\ROCKBI.TTF VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\ROCC____.TTF VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\SCRIPTBL.TTF VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\SHOWG.TTF VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\TCMI____.TTF VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\TCBI____.TTF VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\TCCB____.TTF VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\TEMPSITC.TTF VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\VINERITC.TTF VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\flat_officeFontsPreview.ttf VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\OFFSYMSL.TTF VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\OFFSYMB.TTF VolumeInformation | |
Source: C:\Users\user\Desktop\4si9noTBNw.exe | Queries volume information: C:\Windows\Fonts\arialbd.ttf VolumeInformation | |
Source: C:\Windows\System32\svchost.exe | Queries volume information: C:\ProgramData\Microsoft\Network\Downloader\edb.chk VolumeInformation | |
Source: C:\Windows\System32\svchost.exe | Queries volume information: C:\ProgramData\Microsoft\Network\Downloader\edb.log VolumeInformation | |
Source: C:\Windows\System32\svchost.exe | Queries volume information: C:\ProgramData\Microsoft\Network\Downloader\edb.chk VolumeInformation | |
Source: C:\Windows\System32\svchost.exe | Queries volume information: C:\ProgramData\Microsoft\Network\Downloader\edb.log VolumeInformation | |
Source: C:\Windows\System32\svchost.exe | Queries volume information: C:\ProgramData\Microsoft\Network\Downloader\edb.log VolumeInformation | |
Source: C:\Windows\System32\svchost.exe | Queries volume information: C:\ProgramData\Microsoft\Network\Downloader\edb.log VolumeInformation | |
Source: C:\Windows\System32\svchost.exe | Queries volume information: C:\ProgramData\Microsoft\Network\Downloader\edb.chk VolumeInformation | |
Source: C:\Windows\System32\svchost.exe | Queries volume information: C:\ProgramData\Microsoft\Network\Downloader\qmgr.db VolumeInformation | |
Source: C:\Windows\System32\svchost.exe | Queries volume information: C:\ProgramData\Microsoft\Network\Downloader\qmgr.jfm VolumeInformation | |
Source: C:\Windows\System32\svchost.exe | Queries volume information: C:\ProgramData\Microsoft\Network\Downloader\qmgr.db VolumeInformation | |
Source: C:\Windows\System32\svchost.exe | Queries volume information: C:\ProgramData\Microsoft\Network\Downloader\qmgr.db VolumeInformation | |
Source: C:\Windows\System32\svchost.exe | Queries volume information: C:\ VolumeInformation | |
Source: C:\Windows\System32\svchost.exe | Queries volume information: C:\ VolumeInformation | |