Source: onedrive.bat.exe, 00000002.00000002.105194211165.00000000048C5000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: OriginalFilenamePowerShell.EXEj% vs onedrive.bat.exe |
Source: onedrive.bat.exe, 00000002.00000002.105194211165.00000000048C5000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: q,\\StringFileInfo\\040904B0\\OriginalFilename vs onedrive.bat.exe |
Source: onedrive.bat.exe, 00000002.00000002.105194211165.00000000048B2000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: OriginalFilenameSystem.Management.Automation.dllv+ vs onedrive.bat.exe |
Source: onedrive.bat.exe, 00000002.00000002.105194211165.00000000048B2000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: q,\\StringFileInfo\\000004B0\\OriginalFilename vs onedrive.bat.exe |
Source: onedrive.bat.exe, 00000002.00000000.103939392812.0000000000564000.00000002.00000001.01000000.00000003.sdmp | Binary or memory string: OriginalFilenamePowerShell.EXEj% vs onedrive.bat.exe |
Source: onedrive.bat.exe, 00000002.00000002.105194211165.00000000048A1000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: OriginalFilenameSystem.Management.Automation.dllv+ vs onedrive.bat.exe |
Source: onedrive.bat.exe, 00000002.00000002.105194211165.00000000048A1000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: OriginalFilename vs onedrive.bat.exe |
Source: onedrive.bat.exe, 00000002.00000002.105194211165.00000000048A1000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: q,\\StringFileInfo\\000004B0\\OriginalFilename vs onedrive.bat.exe |
Source: onedrive.bat.exe, 00000002.00000002.105188091472.00000000028B6000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: OriginalFilenameclr.dllT vs onedrive.bat.exe |
Source: onedrive.bat.exe, 00000002.00000002.105194211165.00000000049F8000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: OriginalFileName vs onedrive.bat.exe |
Source: onedrive.bat.exe | Binary or memory string: OriginalFilenamePowerShell.EXEj% vs onedrive.bat.exe |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Code function: 2_2_047DEBC8 |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Code function: 2_2_047DEBB8 |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Code function: 2_2_07CB81B8 |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Code function: 2_2_07CB81B1 |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Code function: 2_2_07CF6D18 |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Code function: 2_2_07CFEAC8 |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Code function: 2_2_07CF9150 |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Code function: 2_2_07CFEABD |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Code function: 2_2_07EE7DA8 |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Code function: 2_2_07EE2478 |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Code function: 2_2_07EE8ED0 |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Code function: 2_2_07EE5E90 |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Code function: 2_2_07EE4678 |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Code function: 2_2_07EE3C60 |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Code function: 2_2_07EEB240 |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Code function: 2_2_07EE3218 |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Code function: 2_2_07F00040 |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Code function: 2_2_07F0ED92 |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Code function: 2_2_07F052C0 |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Code function: 2_2_07F052B8 |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Code function: 2_2_07CB3798 push esi; retf 0007h |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Code function: 2_2_07CB3787 push ebx; retf 0007h |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Code function: 2_2_07CB57B0 push esp; retf 0007h |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Code function: 2_2_07CB3C10 push edi; retf 0007h |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Code function: 2_2_07CFDA58 push 0807CA01h; retn 076Ah |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Code function: 2_2_07CFE659 push es; retf 0007h |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Code function: 2_2_07CFE8FD push 00000007h; ret |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Code function: 2_2_07CFF589 push cs; retf 0007h |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Code function: 2_2_07CF7380 push 00000007h; ret |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Code function: 2_2_07CF9022 push eax; retf |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Code function: 2_2_07EEAA6A push 8B059113h; iretd |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Process information set: NOOPENFILEERRORBOX |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost\v4.0_3.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.ConsoleHost.dll VolumeInformation |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Management.Automation\v4.0_3.0.0.0__31bf3856ad364e35\System.Management.Automation.dll VolumeInformation |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.DirectoryServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.dll VolumeInformation |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0213~31bf3856ad364e35~amd64~~10.0.19041.1151.cat VolumeInformation |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.PowerShell.Security\v4.0_3.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Security.dll VolumeInformation |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation |
Source: C:\Users\user\Desktop\onedrive.bat.exe | Queries volume information: C:\ VolumeInformation |