Source: powershell.exe, 00000006.00000003.217179808.0000012B7D198000.00000004.00000001.sdmp | String found in binary or memory: http://crl.globalsign.net/root-r2.crl0 |
Source: powershell.exe, 00000006.00000002.226355731.0000012B101A6000.00000004.00000001.sdmp | String found in binary or memory: http://nuget.org/NuGet.exe |
Source: powershell.exe, 00000006.00000002.230782159.0000012B7D140000.00000004.00000001.sdmp, powershell.exe, 00000006.00000002.218129835.0000012B00210000.00000004.00000001.sdmp | String found in binary or memory: http://pesterbdd.com/images/Pester.png |
Source: powershell.exe, 00000006.00000002.217765028.0000012B00001000.00000004.00000001.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name |
Source: powershell.exe, 00000006.00000002.230782159.0000012B7D140000.00000004.00000001.sdmp, powershell.exe, 00000006.00000002.218129835.0000012B00210000.00000004.00000001.sdmp | String found in binary or memory: http://www.apache.org/licenses/LICENSE-2.0.html |
Source: powershell.exe, 00000006.00000002.226355731.0000012B101A6000.00000004.00000001.sdmp | String found in binary or memory: https://contoso.com/ |
Source: powershell.exe, 00000006.00000002.226355731.0000012B101A6000.00000004.00000001.sdmp | String found in binary or memory: https://contoso.com/Icon |
Source: powershell.exe, 00000006.00000002.226355731.0000012B101A6000.00000004.00000001.sdmp | String found in binary or memory: https://contoso.com/License |
Source: powershell.exe, 00000006.00000002.230782159.0000012B7D140000.00000004.00000001.sdmp, powershell.exe, 00000006.00000002.218129835.0000012B00210000.00000004.00000001.sdmp | String found in binary or memory: https://github.com/Pester/Pester |
Source: powershell.exe, 00000006.00000002.224611933.0000012B01C61000.00000004.00000001.sdmp | String found in binary or memory: https://go.micro |
Source: powershell.exe, 00000006.00000002.226355731.0000012B101A6000.00000004.00000001.sdmp | String found in binary or memory: https://nuget.org/nuget.exe |
Source: C:\Users\user\Desktop\anchorDNS_x64.exe | Code function: 0_2_00007FF63EC0F1C7 | 0_2_00007FF63EC0F1C7 |
Source: C:\Users\user\Desktop\anchorDNS_x64.exe | Code function: 0_2_00007FF63EC352C0 | 0_2_00007FF63EC352C0 |
Source: C:\Users\user\Desktop\anchorDNS_x64.exe | Code function: 0_2_00007FF63EC042E4 | 0_2_00007FF63EC042E4 |
Source: C:\Users\user\Desktop\anchorDNS_x64.exe | Code function: 0_2_00007FF63EC2D00C | 0_2_00007FF63EC2D00C |
Source: C:\Users\user\Desktop\anchorDNS_x64.exe | Code function: 0_2_00007FF63EC0F80E | 0_2_00007FF63EC0F80E |
Source: C:\Users\user\Desktop\anchorDNS_x64.exe | Code function: 0_2_00007FF63EC1D004 | 0_2_00007FF63EC1D004 |
Source: C:\Users\user\Desktop\anchorDNS_x64.exe | Code function: 0_2_00007FF63EC0777A | 0_2_00007FF63EC0777A |
Source: C:\Users\user\Desktop\anchorDNS_x64.exe | Code function: 0_2_00007FF63EC1AFAE | 0_2_00007FF63EC1AFAE |
Source: C:\Users\user\Desktop\anchorDNS_x64.exe | Code function: 0_2_00007FF63EC32754 | 0_2_00007FF63EC32754 |
Source: C:\Users\user\Desktop\anchorDNS_x64.exe | Code function: 0_2_00007FF63EC2FF60 | 0_2_00007FF63EC2FF60 |
Source: C:\Users\user\Desktop\anchorDNS_x64.exe | Code function: 0_2_00007FF63EC0176B | 0_2_00007FF63EC0176B |
Source: C:\Users\user\Desktop\anchorDNS_x64.exe | Code function: 0_2_00007FF63EC1890E | 0_2_00007FF63EC1890E |
Source: C:\Users\user\Desktop\anchorDNS_x64.exe | Code function: 0_2_00007FF63EC0C0FC | 0_2_00007FF63EC0C0FC |
Source: C:\Users\user\Desktop\anchorDNS_x64.exe | Code function: 0_2_00007FF63EC28926 | 0_2_00007FF63EC28926 |
Source: C:\Users\user\Desktop\anchorDNS_x64.exe | Code function: 0_2_00007FF63EC0E8EC | 0_2_00007FF63EC0E8EC |
Source: C:\Users\user\Desktop\anchorDNS_x64.exe | Code function: 0_2_00007FF63EC020D8 | 0_2_00007FF63EC020D8 |
Source: C:\Users\user\Desktop\anchorDNS_x64.exe | Code function: 0_2_00007FF63EC2908C | 0_2_00007FF63EC2908C |
Source: C:\Users\user\Desktop\anchorDNS_x64.exe | Code function: 0_2_00007FF63EC2E894 | 0_2_00007FF63EC2E894 |
Source: C:\Users\user\Desktop\anchorDNS_x64.exe | Code function: 0_2_00007FF63EC01094 | 0_2_00007FF63EC01094 |
Source: C:\Users\user\Desktop\anchorDNS_x64.exe | Code function: 0_2_00007FF63EC0C8B2 | 0_2_00007FF63EC0C8B2 |
Source: C:\Users\user\Desktop\anchorDNS_x64.exe | Code function: 0_2_00007FF63EC23609 | 0_2_00007FF63EC23609 |
Source: C:\Users\user\Desktop\anchorDNS_x64.exe | Code function: 0_2_00007FF63EC0A5F6 | 0_2_00007FF63EC0A5F6 |
Source: C:\Users\user\Desktop\anchorDNS_x64.exe | Code function: 0_2_00007FF63EC3EE18 | 0_2_00007FF63EC3EE18 |
Source: C:\Users\user\Desktop\anchorDNS_x64.exe | Code function: 0_2_00007FF63EC08E1C | 0_2_00007FF63EC08E1C |
Source: C:\Users\user\Desktop\anchorDNS_x64.exe | Code function: 0_2_00007FF63EC0C5BE | 0_2_00007FF63EC0C5BE |
Source: C:\Users\user\Desktop\anchorDNS_x64.exe | Code function: 0_2_00007FF63EC195A8 | 0_2_00007FF63EC195A8 |
Source: C:\Users\user\Desktop\anchorDNS_x64.exe | Code function: 0_2_00007FF63EC2F5B0 | 0_2_00007FF63EC2F5B0 |
Source: C:\Users\user\Desktop\anchorDNS_x64.exe | Code function: 0_2_00007FF63EC1CD36 | 0_2_00007FF63EC1CD36 |
Source: C:\Users\user\Desktop\anchorDNS_x64.exe | Code function: 0_2_00007FF63EC03575 | 0_2_00007FF63EC03575 |
Source: C:\Users\user\Desktop\anchorDNS_x64.exe | Code function: 0_2_00007FF63EC09F0A | 0_2_00007FF63EC09F0A |
Source: C:\Users\user\Desktop\anchorDNS_x64.exe | Code function: 0_2_00007FF63EC08716 | 0_2_00007FF63EC08716 |
Source: C:\Users\user\Desktop\anchorDNS_x64.exe | Code function: 0_2_00007FF63EC1BF22 | 0_2_00007FF63EC1BF22 |
Source: C:\Users\user\Desktop\anchorDNS_x64.exe | Code function: 0_2_00007FF63EC066C4 | 0_2_00007FF63EC066C4 |
Source: C:\Users\user\Desktop\anchorDNS_x64.exe | Code function: 0_2_00007FF63EC216CE | 0_2_00007FF63EC216CE |
Source: C:\Users\user\Desktop\anchorDNS_x64.exe | Code function: 0_2_00007FF63EC0AED2 | 0_2_00007FF63EC0AED2 |
Source: C:\Users\user\Desktop\anchorDNS_x64.exe | Code function: 0_2_00007FF63EC3B6E8 | 0_2_00007FF63EC3B6E8 |
Source: C:\Users\user\Desktop\anchorDNS_x64.exe | Code function: 0_2_00007FF63EC3CEEC | 0_2_00007FF63EC3CEEC |
Source: C:\Users\user\Desktop\anchorDNS_x64.exe | Code function: 0_2_00007FF63EC06EEC | 0_2_00007FF63EC06EEC |
Source: C:\Users\user\Desktop\anchorDNS_x64.exe | Code function: 0_2_00007FF63EC0B68A | 0_2_00007FF63EC0B68A |
Source: C:\Users\user\Desktop\anchorDNS_x64.exe | Code function: 0_2_00007FF63EC0BE8E | 0_2_00007FF63EC0BE8E |
Source: C:\Users\user\Desktop\anchorDNS_x64.exe | Code function: 0_2_00007FF63EC07E98 | 0_2_00007FF63EC07E98 |
Source: C:\Users\user\Desktop\anchorDNS_x64.exe | Code function: 0_2_00007FF63EC42E48 | 0_2_00007FF63EC42E48 |
Source: C:\Users\user\Desktop\anchorDNS_x64.exe | Code function: 0_2_00007FF63EC0CE64 | 0_2_00007FF63EC0CE64 |
Source: C:\Users\user\Desktop\anchorDNS_x64.exe | Code function: 0_2_00007FF63EC25414 | 0_2_00007FF63EC25414 |
Source: C:\Users\user\Desktop\anchorDNS_x64.exe | Code function: 0_2_00007FF63EC103FD | 0_2_00007FF63EC103FD |
Source: C:\Users\user\Desktop\anchorDNS_x64.exe | Code function: 0_2_00007FF63EC3D404 | 0_2_00007FF63EC3D404 |
Source: C:\Users\user\Desktop\anchorDNS_x64.exe | Code function: 0_2_00007FF63EC17C28 | 0_2_00007FF63EC17C28 |
Source: C:\Users\user\Desktop\anchorDNS_x64.exe | Code function: 0_2_00007FF63EC22C2F | 0_2_00007FF63EC22C2F |
Source: C:\Users\user\Desktop\anchorDNS_x64.exe | Code function: 0_2_00007FF63EC06BCC | 0_2_00007FF63EC06BCC |
Source: C:\Users\user\Desktop\anchorDNS_x64.exe | Code function: 0_2_00007FF63EC1C3C2 | 0_2_00007FF63EC1C3C2 |
Source: C:\Users\user\Desktop\anchorDNS_x64.exe | Code function: 0_2_00007FF63EC073F4 | 0_2_00007FF63EC073F4 |
Source: C:\Users\user\Desktop\anchorDNS_x64.exe | Code function: 0_2_00007FF63EC1EBAA | 0_2_00007FF63EC1EBAA |
Source: C:\Users\user\Desktop\anchorDNS_x64.exe | Code function: 0_2_00007FF63EC1A3AE | 0_2_00007FF63EC1A3AE |
Source: C:\Users\user\Desktop\anchorDNS_x64.exe | Code function: 0_2_00007FF63EC1FBB4 | 0_2_00007FF63EC1FBB4 |
Source: C:\Users\user\Desktop\anchorDNS_x64.exe | Code function: 0_2_00007FF63EC0AB96 | 0_2_00007FF63EC0AB96 |
Source: C:\Users\user\Desktop\anchorDNS_x64.exe | Code function: 0_2_00007FF63EC3FB64 | 0_2_00007FF63EC3FB64 |
Source: C:\Users\user\Desktop\anchorDNS_x64.exe | Code function: 0_2_00007FF63EC27CCD | 0_2_00007FF63EC27CCD |
Source: C:\Users\user\Desktop\anchorDNS_x64.exe | Code function: 0_2_00007FF63EC27CCC | 0_2_00007FF63EC27CCC |
Source: C:\Users\user\Desktop\anchorDNS_x64.exe | Code function: 0_2_00007FF63EC144C3 | 0_2_00007FF63EC144C3 |
Source: C:\Users\user\Desktop\anchorDNS_x64.exe | Code function: 0_2_00007FF63EC174C4 | 0_2_00007FF63EC174C4 |
Source: C:\Users\user\Desktop\anchorDNS_x64.exe | Code function: 0_2_00007FF63EC1B4E4 | 0_2_00007FF63EC1B4E4 |
Source: C:\Users\user\Desktop\anchorDNS_x64.exe | Code function: 0_2_00007FF63EC2048A | 0_2_00007FF63EC2048A |
Source: C:\Users\user\Desktop\anchorDNS_x64.exe | Code function: 0_2_00007FF63EC08476 | 0_2_00007FF63EC08476 |
Source: C:\Users\user\Desktop\anchorDNS_x64.exe | Code function: 0_2_00007FF63EC3BC9C | 0_2_00007FF63EC3BC9C |
Source: C:\Users\user\Desktop\anchorDNS_x64.exe | Code function: 0_2_00007FF63EC09CA4 | 0_2_00007FF63EC09CA4 |
Source: C:\Users\user\Desktop\anchorDNS_x64.exe | Code function: 0_2_00007FF63EC0B45A | 0_2_00007FF63EC0B45A |
Source: C:\Users\user\Desktop\anchorDNS_x64.exe | Code function: 0_2_00007FF63EC0BC62 | 0_2_00007FF63EC0BC62 |
Source: C:\Users\user\Desktop\anchorDNS_x64.exe | Code function: 0_2_00007FF63EC15209 | 0_2_00007FF63EC15209 |
Source: C:\Users\user\Desktop\anchorDNS_x64.exe | Code function: 0_2_00007FF63EC039FB | 0_2_00007FF63EC039FB |
Source: C:\Users\user\Desktop\anchorDNS_x64.exe | Code function: 0_2_00007FF63EC071F6 | 0_2_00007FF63EC071F6 |
Source: C:\Users\user\Desktop\anchorDNS_x64.exe | Code function: 0_2_00007FF63EC279D8 | 0_2_00007FF63EC279D8 |
Source: C:\Users\user\Desktop\anchorDNS_x64.exe | Code function: 0_2_00007FF63EC0E192 | 0_2_00007FF63EC0E192 |
Source: C:\Users\user\Desktop\anchorDNS_x64.exe | Code function: 0_2_00007FF63EC08992 | 0_2_00007FF63EC08992 |
Source: C:\Users\user\Desktop\anchorDNS_x64.exe | Code function: 0_2_00007FF63EC2217C | 0_2_00007FF63EC2217C |
Source: C:\Users\user\Desktop\anchorDNS_x64.exe | Code function: 0_2_00007FF63EC1F148 | 0_2_00007FF63EC1F148 |
Source: C:\Users\user\Desktop\anchorDNS_x64.exe | Code function: 0_2_00007FF63EC1614C | 0_2_00007FF63EC1614C |
Source: C:\Users\user\Desktop\anchorDNS_x64.exe | Code function: 0_2_00007FF63EC0693C | 0_2_00007FF63EC0693C |
Source: C:\Users\user\Desktop\anchorDNS_x64.exe | Code function: 0_2_00007FF63EC0A16E | 0_2_00007FF63EC0A16E |
Source: C:\Users\user\Desktop\anchorDNS_x64.exe | Code function: 0_2_00007FF63EC1DB2C | 0_2_00007FF63EC1DB2C |
Source: C:\Users\user\Desktop\anchorDNS_x64.exe | Code function: 0_2_00007FF63EC07B16 | 0_2_00007FF63EC07B16 |
Source: C:\Users\user\Desktop\anchorDNS_x64.exe | Code function: 0_2_00007FF63EC1F31E | 0_2_00007FF63EC1F31E |
Source: C:\Users\user\Desktop\anchorDNS_x64.exe | Code function: 0_2_00007FF63EC012B6 | 0_2_00007FF63EC012B6 |
Source: C:\Users\user\Desktop\anchorDNS_x64.exe | Code function: 0_2_00007FF63EC0C2F2 | 0_2_00007FF63EC0C2F2 |
Source: C:\Users\user\Desktop\anchorDNS_x64.exe | Code function: 0_2_00007FF63EC08248 | 0_2_00007FF63EC08248 |
Source: C:\Users\user\Desktop\anchorDNS_x64.exe | Code function: 0_2_00007FF63EC28250 | 0_2_00007FF63EC28250 |
Source: C:\Users\user\Desktop\anchorDNS_x64.exe | Code function: 0_2_00007FF63EC2FA54 | 0_2_00007FF63EC2FA54 |
Source: C:\Users\user\Desktop\anchorDNS_x64.exe | Code function: 0_2_00007FF63EC0BA3A | 0_2_00007FF63EC0BA3A |
Source: unknown | Process created: C:\Users\user\Desktop\anchorDNS_x64.exe 'C:\Users\user\Desktop\anchorDNS_x64.exe' | |
Source: C:\Users\user\Desktop\anchorDNS_x64.exe | Process created: C:\Windows\System32\cmd.exe cmd.exe /c timeout 3 && del C:\Users\user\Desktop\anchorDNS_x64.exe | |
Source: C:\Users\user\Desktop\anchorDNS_x64.exe | Process created: C:\Windows\System32\cmd.exe cmd.exe /C PowerShell 'Start-Sleep 3; Remove-Item C:\Users\user\Desktop\anchorDNS_x64.exe' | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\timeout.exe timeout 3 | |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe PowerShell 'Start-Sleep 3; Remove-Item C:\Users\user\Desktop\anchorDNS_x64.exe' | |
Source: C:\Users\user\Desktop\anchorDNS_x64.exe | Process created: C:\Windows\System32\cmd.exe cmd.exe /c timeout 3 && del C:\Users\user\Desktop\anchorDNS_x64.exe | Jump to behavior |
Source: C:\Users\user\Desktop\anchorDNS_x64.exe | Process created: C:\Windows\System32\cmd.exe cmd.exe /C PowerShell 'Start-Sleep 3; Remove-Item C:\Users\user\Desktop\anchorDNS_x64.exe' | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\timeout.exe timeout 3 | Jump to behavior |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe PowerShell 'Start-Sleep 3; Remove-Item C:\Users\user\Desktop\anchorDNS_x64.exe' | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\ VolumeInformation | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package00113~31bf3856ad364e35~amd64~~10.0.17134.1.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package00113~31bf3856ad364e35~amd64~~10.0.17134.1.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package00113~31bf3856ad364e35~amd64~~10.0.17134.1.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package00113~31bf3856ad364e35~amd64~~10.0.17134.1.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package00113~31bf3856ad364e35~amd64~~10.0.17134.1.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\ VolumeInformation | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package00113~31bf3856ad364e35~amd64~~10.0.17134.1.cat VolumeInformation | Jump to behavior |