Windows Analysis Report
Cotizaci#U00f3n#12643283.exe

Overview

General Information

Sample name: Cotizaci#U00f3n#12643283.exe
renamed because original name is a hash value
Original sample name: Cotizacin#12643283.exe
Analysis ID: 1501088
MD5: 23788e22bc2ee1417a5c7fdf0f58715f
SHA1: f47805df01143591bc654056b9fda905850e9539
SHA256: d613473068f000318d1015b85a0f49f9191263041ae8debcc7250876ae146304
Tags: exeFormbook
Infos:

Detection

FormBook
Score: 100
Range: 0 - 100
Whitelisted: false
Confidence: 100%

Signatures

Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Sigma detected: Scheduled temp file as task from temp location
Yara detected AntiVM3
Yara detected FormBook
.NET source code contains potential unpacker
AI detected suspicious sample
Adds a directory exclusion to Windows Defender
Loading BitLocker PowerShell Module
Machine Learning detection for dropped file
Machine Learning detection for sample
Sigma detected: Powershell Base64 Encoded MpPreference Cmdlet
Uses schtasks.exe or at.exe to add and modify task schedules
Abnormal high CPU Usage
Allocates memory with a write watch (potentially for evading sandboxes)
Checks if the current process is being debugged
Contains functionality for execution timing, often used to detect debuggers
Contains functionality to access loader functionality (e.g. LdrGetProcedureAddress)
Contains functionality to call native functions
Contains functionality to check if a debugger is running (IsDebuggerPresent)
Contains functionality to dynamically determine API calls
Contains functionality to read the PEB
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Detected potential crypto function
Drops PE files
Enables debug privileges
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Found large amount of non-executed APIs
Found potential string decryption / allocating functions
May sleep (evasive loops) to hinder dynamic analysis
Queries the volume information (name, serial number etc) of a device
Sample execution stops while process was sleeping (likely an evasion)
Sample file is different than original file name gathered from version info
Sigma detected: Powershell Defender Exclusion
Sigma detected: Suspicious Add Scheduled Task Parent
Sigma detected: Suspicious Schtasks From Env Var Folder
Uses 32bit PE files
Uses code obfuscation techniques (call, push, ret)
Yara signature match

Classification

AV Detection

barindex
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe ReversingLabs: Detection: 78%
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Virustotal: Detection: 68% Perma Link
Source: Cotizaci#U00f3n#12643283.exe ReversingLabs: Detection: 78%
Source: Cotizaci#U00f3n#12643283.exe Virustotal: Detection: 68% Perma Link
Source: Yara match File source: 7.2.vbc.exe.400000.0.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 7.2.vbc.exe.400000.0.unpack, type: UNPACKEDPE
Source: Yara match File source: 00000007.00000002.2862181424.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000007.00000002.2862655444.0000000000E50000.00000004.00001000.00020000.00000000.sdmp, type: MEMORY
Source: Submited Sample Integrated Neural Analysis Model: Matched 100.0% probability
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Joe Sandbox ML: detected
Source: Cotizaci#U00f3n#12643283.exe Joe Sandbox ML: detected
Source: Cotizaci#U00f3n#12643283.exe Static PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
Source: Cotizaci#U00f3n#12643283.exe Static PE information: DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
Source: Binary string: ziKI.pdbSHA256OWjP source: Cotizaci#U00f3n#12643283.exe, SoEOsZIV.exe.0.dr
Source: Binary string: wntdll.pdbUGP source: vbc.exe, 00000007.00000002.2862902887.0000000006F30000.00000040.00001000.00020000.00000000.sdmp
Source: Binary string: wntdll.pdb source: vbc.exe, vbc.exe, 00000007.00000002.2862902887.0000000006F30000.00000040.00001000.00020000.00000000.sdmp
Source: Binary string: ziKI.pdb source: Cotizaci#U00f3n#12643283.exe, SoEOsZIV.exe.0.dr
Source: Cotizaci#U00f3n#12643283.exe, 00000000.00000002.2200126332.0000000002797000.00000004.00000800.00020000.00000000.sdmp, SoEOsZIV.exe, 00000008.00000002.2254774684.00000000031A0000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name

E-Banking Fraud

barindex
Source: Yara match File source: 7.2.vbc.exe.400000.0.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 7.2.vbc.exe.400000.0.unpack, type: UNPACKEDPE
Source: Yara match File source: 00000007.00000002.2862181424.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000007.00000002.2862655444.0000000000E50000.00000004.00001000.00020000.00000000.sdmp, type: MEMORY

System Summary

barindex
Source: 7.2.vbc.exe.400000.0.raw.unpack, type: UNPACKEDPE Matched rule: Windows_Trojan_Formbook_1112e116 Author: unknown
Source: 7.2.vbc.exe.400000.0.unpack, type: UNPACKEDPE Matched rule: Windows_Trojan_Formbook_1112e116 Author: unknown
Source: 00000007.00000002.2862181424.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY Matched rule: Windows_Trojan_Formbook_1112e116 Author: unknown
Source: 00000007.00000002.2862655444.0000000000E50000.00000004.00001000.00020000.00000000.sdmp, type: MEMORY Matched rule: Windows_Trojan_Formbook_1112e116 Author: unknown
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Process Stats: CPU usage > 49%
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_0042CC13 NtClose, 7_2_0042CC13
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FA2C70 NtFreeVirtualMemory,LdrInitializeThunk, 7_2_06FA2C70
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FA2DF0 NtQuerySystemInformation,LdrInitializeThunk, 7_2_06FA2DF0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FA2B60 NtClose,LdrInitializeThunk, 7_2_06FA2B60
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FA35C0 NtCreateMutant,LdrInitializeThunk, 7_2_06FA35C0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FA4650 NtSuspendThread, 7_2_06FA4650
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FA4340 NtSetContextThread, 7_2_06FA4340
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FA2EE0 NtQueueApcThread, 7_2_06FA2EE0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FA2EA0 NtAdjustPrivilegesToken, 7_2_06FA2EA0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FA2E80 NtReadVirtualMemory, 7_2_06FA2E80
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FA2E30 NtWriteVirtualMemory, 7_2_06FA2E30
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FA2FE0 NtCreateFile, 7_2_06FA2FE0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FA2FB0 NtResumeThread, 7_2_06FA2FB0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FA2FA0 NtQuerySection, 7_2_06FA2FA0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FA2F90 NtProtectVirtualMemory, 7_2_06FA2F90
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FA2F60 NtCreateProcessEx, 7_2_06FA2F60
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FA2F30 NtCreateSection, 7_2_06FA2F30
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FA2CF0 NtOpenProcess, 7_2_06FA2CF0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FA2CC0 NtQueryVirtualMemory, 7_2_06FA2CC0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FA2CA0 NtQueryInformationToken, 7_2_06FA2CA0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FA2C60 NtCreateKey, 7_2_06FA2C60
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FA2C00 NtQueryInformationProcess, 7_2_06FA2C00
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FA2DD0 NtDelayExecution, 7_2_06FA2DD0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FA2DB0 NtEnumerateKey, 7_2_06FA2DB0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FA2D30 NtUnmapViewOfSection, 7_2_06FA2D30
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FA2D10 NtMapViewOfSection, 7_2_06FA2D10
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FA2D00 NtSetInformationFile, 7_2_06FA2D00
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FA2AF0 NtWriteFile, 7_2_06FA2AF0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FA2AD0 NtReadFile, 7_2_06FA2AD0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FA2AB0 NtWaitForSingleObject, 7_2_06FA2AB0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FA2BF0 NtAllocateVirtualMemory, 7_2_06FA2BF0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FA2BE0 NtQueryValueKey, 7_2_06FA2BE0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FA2BA0 NtEnumerateValueKey, 7_2_06FA2BA0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FA2B80 NtQueryInformationFile, 7_2_06FA2B80
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FA3090 NtSetValueKey, 7_2_06FA3090
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FA3010 NtOpenDirectoryObject, 7_2_06FA3010
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FA3D70 NtOpenThread, 7_2_06FA3D70
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FA3D10 NtOpenProcessToken, 7_2_06FA3D10
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FA39B0 NtGetContextThread, 7_2_06FA39B0
Source: C:\Users\user\Desktop\Cotizaci#U00f3n#12643283.exe Code function: 0_2_00CDE074 0_2_00CDE074
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_004018EC 7_2_004018EC
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_004018F0 7_2_004018F0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_00403A40 7_2_00403A40
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_0042F203 7_2_0042F203
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_00401AD0 7_2_00401AD0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_00401440 7_2_00401440
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_004034C0 7_2_004034C0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_00402CD0 7_2_00402CD0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_004034B8 7_2_004034B8
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_00410513 7_2_00410513
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_00416DAF 7_2_00416DAF
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_00416DB3 7_2_00416DB3
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_00410733 7_2_00410733
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_004017B0 7_2_004017B0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_0040E7B3 7_2_0040E7B3
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F8C6E0 7_2_06F8C6E0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F6C7C0 7_2_06F6C7C0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F70770 7_2_06F70770
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F94750 7_2_06F94750
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_07030591 7_2_07030591
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_07014420 7_2_07014420
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_07022446 7_2_07022446
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F70535 7_2_06F70535
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_0701E4F6 7_2_0701E4F6
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FF02C0 7_2_06FF02C0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_0702A352 7_2_0702A352
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_070303E6 7_2_070303E6
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F7E3F0 7_2_06F7E3F0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_07010274 7_2_07010274
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_0700A118 7_2_0700A118
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_070241A2 7_2_070241A2
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_070301AA 7_2_070301AA
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_070281CC 7_2_070281CC
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_07002000 7_2_07002000
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FF8158 7_2_06FF8158
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F60100 7_2_06F60100
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_07012F30 7_2_07012F30
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F82E90 7_2_06F82E90
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F70E59 7_2_06F70E59
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F7CFE0 7_2_06F7CFE0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_0702EE26 7_2_0702EE26
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F62FC8 7_2_06F62FC8
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FEEFA0 7_2_06FEEFA0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_0702CE93 7_2_0702CE93
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FE4F40 7_2_06FE4F40
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F90F30 7_2_06F90F30
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FB2F28 7_2_06FB2F28
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_0702EEDB 7_2_0702EEDB
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F60CF2 7_2_06F60CF2
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_0700CD1F 7_2_0700CD1F
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F70C00 7_2_06F70C00
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F6ADE0 7_2_06F6ADE0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F88DBF 7_2_06F88DBF
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_07010CB5 7_2_07010CB5
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F7AD00 7_2_06F7AD00
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_0702AB40 7_2_0702AB40
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F6EA80 7_2_06F6EA80
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_07026BD7 7_2_07026BD7
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F9E8F0 7_2_06F9E8F0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F568B8 7_2_06F568B8
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_0703A9A6 7_2_0703A9A6
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F72840 7_2_06F72840
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F7A840 7_2_06F7A840
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F729A0 7_2_06F729A0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F86962 7_2_06F86962
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_0702F7B0 7_2_0702F7B0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FB5630 7_2_06FB5630
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_070216CC 7_2_070216CC
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_07027571 7_2_07027571
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F61460 7_2_06F61460
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_0700D5B0 7_2_0700D5B0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_070395C3 7_2_070395C3
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_0702F43F 7_2_0702F43F
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_0702132D 7_2_0702132D
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F8B2C0 7_2_06F8B2C0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F752A0 7_2_06F752A0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FB739A 7_2_06FB739A
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F5D34C 7_2_06F5D34C
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_070112ED 7_2_070112ED
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F770C0 7_2_06F770C0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_0703B16B 7_2_0703B16B
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F7B1B0 7_2_06F7B1B0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F5F172 7_2_06F5F172
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FA516C 7_2_06FA516C
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_0701F0CC 7_2_0701F0CC
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_0702F0E0 7_2_0702F0E0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_070270E9 7_2_070270E9
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_0702FF09 7_2_0702FF09
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F79EB0 7_2_06F79EB0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_0702FFB1 7_2_0702FFB1
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F71F92 7_2_06F71F92
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_07021D5A 7_2_07021D5A
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_07027D73 7_2_07027D73
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FE9C32 7_2_06FE9C32
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F8FDC0 7_2_06F8FDC0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F73D40 7_2_06F73D40
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_0702FCF2 7_2_0702FCF2
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FB5AA0 7_2_06FB5AA0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_0702FB76 7_2_0702FB76
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FE3A6C 7_2_06FE3A6C
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FADBF9 7_2_06FADBF9
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FE5BF0 7_2_06FE5BF0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_07027A46 7_2_07027A46
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_0702FA49 7_2_0702FA49
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F8FB80 7_2_06F8FB80
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_07011AA3 7_2_07011AA3
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_0700DAAC 7_2_0700DAAC
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_0701DAC6 7_2_0701DAC6
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_07005910 7_2_07005910
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F738E0 7_2_06F738E0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FDD800 7_2_06FDD800
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F79950 7_2_06F79950
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F8B950 7_2_06F8B950
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Code function: 8_2_0190E074 8_2_0190E074
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: String function: 06FDEA12 appears 86 times
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: String function: 06F5B970 appears 280 times
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: String function: 06FA5130 appears 58 times
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: String function: 06FEF290 appears 105 times
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: String function: 06FB7E54 appears 111 times
Source: Cotizaci#U00f3n#12643283.exe, 00000000.00000002.2200126332.0000000002751000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenameCasio.dllD vs Cotizaci#U00f3n#12643283.exe
Source: Cotizaci#U00f3n#12643283.exe, 00000000.00000000.2182180428.0000000000408000.00000002.00000001.01000000.00000003.sdmp Binary or memory string: OriginalFilenamezi vs Cotizaci#U00f3n#12643283.exe
Source: Cotizaci#U00f3n#12643283.exe, 00000000.00000002.2199273038.0000000000A2E000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameclr.dllT vs Cotizaci#U00f3n#12643283.exe
Source: Cotizaci#U00f3n#12643283.exe, 00000000.00000002.2202816597.000000000392E000.00000004.00000800.00020000.00000000.sdmp Binary or memory string: OriginalFilenameTyrone.dll8 vs Cotizaci#U00f3n#12643283.exe
Source: Cotizaci#U00f3n#12643283.exe, 00000000.00000002.2210589976.00000000051B0000.00000004.08000000.00040000.00000000.sdmp Binary or memory string: OriginalFilenameCasio.dllD vs Cotizaci#U00f3n#12643283.exe
Source: Cotizaci#U00f3n#12643283.exe, 00000000.00000002.2210800655.00000000051C0000.00000004.08000000.00040000.00000000.sdmp Binary or memory string: OriginalFilenameSalmun.dll. vs Cotizaci#U00f3n#12643283.exe
Source: Cotizaci#U00f3n#12643283.exe, 00000000.00000002.2211398389.0000000006A90000.00000004.08000000.00040000.00000000.sdmp Binary or memory string: OriginalFilenameTyrone.dll8 vs Cotizaci#U00f3n#12643283.exe
Source: Cotizaci#U00f3n#12643283.exe Binary or memory string: OriginalFilenameziKI.exe4 vs Cotizaci#U00f3n#12643283.exe
Source: Cotizaci#U00f3n#12643283.exe Static PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
Source: 7.2.vbc.exe.400000.0.raw.unpack, type: UNPACKEDPE Matched rule: Windows_Trojan_Formbook_1112e116 reference_sample = 6246f3b89f0e4913abd88ae535ae3597865270f58201dc7f8ec0c87f15ff370a, os = windows, severity = x86, creation_date = 2021-06-14, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Formbook, fingerprint = b8b88451ad8c66b54e21455d835a5d435e52173c86e9b813ffab09451aff7134, id = 1112e116-dee0-4818-a41f-ca5c1c41b4b8, last_modified = 2021-08-23
Source: 7.2.vbc.exe.400000.0.unpack, type: UNPACKEDPE Matched rule: Windows_Trojan_Formbook_1112e116 reference_sample = 6246f3b89f0e4913abd88ae535ae3597865270f58201dc7f8ec0c87f15ff370a, os = windows, severity = x86, creation_date = 2021-06-14, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Formbook, fingerprint = b8b88451ad8c66b54e21455d835a5d435e52173c86e9b813ffab09451aff7134, id = 1112e116-dee0-4818-a41f-ca5c1c41b4b8, last_modified = 2021-08-23
Source: 00000007.00000002.2862181424.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY Matched rule: Windows_Trojan_Formbook_1112e116 reference_sample = 6246f3b89f0e4913abd88ae535ae3597865270f58201dc7f8ec0c87f15ff370a, os = windows, severity = x86, creation_date = 2021-06-14, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Formbook, fingerprint = b8b88451ad8c66b54e21455d835a5d435e52173c86e9b813ffab09451aff7134, id = 1112e116-dee0-4818-a41f-ca5c1c41b4b8, last_modified = 2021-08-23
Source: 00000007.00000002.2862655444.0000000000E50000.00000004.00001000.00020000.00000000.sdmp, type: MEMORY Matched rule: Windows_Trojan_Formbook_1112e116 reference_sample = 6246f3b89f0e4913abd88ae535ae3597865270f58201dc7f8ec0c87f15ff370a, os = windows, severity = x86, creation_date = 2021-06-14, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Formbook, fingerprint = b8b88451ad8c66b54e21455d835a5d435e52173c86e9b813ffab09451aff7134, id = 1112e116-dee0-4818-a41f-ca5c1c41b4b8, last_modified = 2021-08-23
Source: Cotizaci#U00f3n#12643283.exe Static PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: SoEOsZIV.exe.0.dr Static PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: 0.2.Cotizaci#U00f3n#12643283.exe.3b26650.2.raw.unpack, X64Lfi1jtVl3jyEt1i.cs Security API names: _0020.SetAccessControl
Source: 0.2.Cotizaci#U00f3n#12643283.exe.3b26650.2.raw.unpack, X64Lfi1jtVl3jyEt1i.cs Security API names: System.Security.Principal.WindowsIdentity.GetCurrent()
Source: 0.2.Cotizaci#U00f3n#12643283.exe.3b26650.2.raw.unpack, X64Lfi1jtVl3jyEt1i.cs Security API names: _0020.AddAccessRule
Source: 0.2.Cotizaci#U00f3n#12643283.exe.6a90000.6.raw.unpack, O6gQHwN7UIkW5MiRmW.cs Security API names: System.Security.Principal.WindowsIdentity.GetCurrent()
Source: 0.2.Cotizaci#U00f3n#12643283.exe.3b26650.2.raw.unpack, O6gQHwN7UIkW5MiRmW.cs Security API names: System.Security.Principal.WindowsIdentity.GetCurrent()
Source: 0.2.Cotizaci#U00f3n#12643283.exe.6a90000.6.raw.unpack, X64Lfi1jtVl3jyEt1i.cs Security API names: _0020.SetAccessControl
Source: 0.2.Cotizaci#U00f3n#12643283.exe.6a90000.6.raw.unpack, X64Lfi1jtVl3jyEt1i.cs Security API names: System.Security.Principal.WindowsIdentity.GetCurrent()
Source: 0.2.Cotizaci#U00f3n#12643283.exe.6a90000.6.raw.unpack, X64Lfi1jtVl3jyEt1i.cs Security API names: _0020.AddAccessRule
Source: classification engine Classification label: mal100.troj.evad.winEXE@24/11@0/0
Source: C:\Users\user\Desktop\Cotizaci#U00f3n#12643283.exe File created: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Mutant created: NULL
Source: C:\Windows\System32\conhost.exe Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:3080:120:WilError_03
Source: C:\Windows\System32\conhost.exe Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:7028:120:WilError_03
Source: C:\Windows\System32\conhost.exe Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:1804:120:WilError_03
Source: C:\Users\user\Desktop\Cotizaci#U00f3n#12643283.exe File created: C:\Users\user\AppData\Local\Temp\tmpAC01.tmp Jump to behavior
Source: Cotizaci#U00f3n#12643283.exe Static PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: Cotizaci#U00f3n#12643283.exe Static file information: TRID: Win32 Executable (generic) Net Framework (10011505/4) 49.80%
Source: C:\Users\user\Desktop\Cotizaci#U00f3n#12643283.exe File read: C:\Users\user\Desktop\desktop.ini Jump to behavior
Source: C:\Users\user\Desktop\Cotizaci#U00f3n#12643283.exe Key opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers Jump to behavior
Source: Cotizaci#U00f3n#12643283.exe ReversingLabs: Detection: 78%
Source: Cotizaci#U00f3n#12643283.exe Virustotal: Detection: 68%
Source: C:\Users\user\Desktop\Cotizaci#U00f3n#12643283.exe File read: C:\Users\user\Desktop\Cotizaci#U00f3n#12643283.exe Jump to behavior
Source: unknown Process created: C:\Users\user\Desktop\Cotizaci#U00f3n#12643283.exe "C:\Users\user\Desktop\Cotizaci#U00f3n#12643283.exe"
Source: C:\Users\user\Desktop\Cotizaci#U00f3n#12643283.exe Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath "C:\Users\user\AppData\Roaming\SoEOsZIV.exe"
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Users\user\Desktop\Cotizaci#U00f3n#12643283.exe Process created: C:\Windows\SysWOW64\schtasks.exe "C:\Windows\System32\schtasks.exe" /Create /TN "Updates\SoEOsZIV" /XML "C:\Users\user\AppData\Local\Temp\tmpAC01.tmp"
Source: C:\Windows\SysWOW64\schtasks.exe Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Users\user\Desktop\Cotizaci#U00f3n#12643283.exe Process created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe"
Source: unknown Process created: C:\Users\user\AppData\Roaming\SoEOsZIV.exe C:\Users\user\AppData\Roaming\SoEOsZIV.exe
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process created: C:\Windows\System32\wbem\WmiPrvSE.exe C:\Windows\system32\wbem\wmiprvse.exe -secured -Embedding
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Process created: C:\Windows\SysWOW64\schtasks.exe "C:\Windows\System32\schtasks.exe" /Create /TN "Updates\SoEOsZIV" /XML "C:\Users\user\AppData\Local\Temp\tmpBE22.tmp"
Source: C:\Windows\SysWOW64\schtasks.exe Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Process created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe"
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Process created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe"
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Process created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe"
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Process created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe"
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Process created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe"
Source: C:\Users\user\Desktop\Cotizaci#U00f3n#12643283.exe Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath "C:\Users\user\AppData\Roaming\SoEOsZIV.exe" Jump to behavior
Source: C:\Users\user\Desktop\Cotizaci#U00f3n#12643283.exe Process created: C:\Windows\SysWOW64\schtasks.exe "C:\Windows\System32\schtasks.exe" /Create /TN "Updates\SoEOsZIV" /XML "C:\Users\user\AppData\Local\Temp\tmpAC01.tmp" Jump to behavior
Source: C:\Users\user\Desktop\Cotizaci#U00f3n#12643283.exe Process created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe" Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Process created: C:\Windows\SysWOW64\schtasks.exe "C:\Windows\System32\schtasks.exe" /Create /TN "Updates\SoEOsZIV" /XML "C:\Users\user\AppData\Local\Temp\tmpBE22.tmp" Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Process created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe" Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Process created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe" Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Process created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe" Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Process created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe" Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Process created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe" Jump to behavior
Source: C:\Users\user\Desktop\Cotizaci#U00f3n#12643283.exe Section loaded: mscoree.dll Jump to behavior
Source: C:\Users\user\Desktop\Cotizaci#U00f3n#12643283.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Users\user\Desktop\Cotizaci#U00f3n#12643283.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Users\user\Desktop\Cotizaci#U00f3n#12643283.exe Section loaded: version.dll Jump to behavior
Source: C:\Users\user\Desktop\Cotizaci#U00f3n#12643283.exe Section loaded: vcruntime140_clr0400.dll Jump to behavior
Source: C:\Users\user\Desktop\Cotizaci#U00f3n#12643283.exe Section loaded: ucrtbase_clr0400.dll Jump to behavior
Source: C:\Users\user\Desktop\Cotizaci#U00f3n#12643283.exe Section loaded: ucrtbase_clr0400.dll Jump to behavior
Source: C:\Users\user\Desktop\Cotizaci#U00f3n#12643283.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Users\user\Desktop\Cotizaci#U00f3n#12643283.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Users\user\Desktop\Cotizaci#U00f3n#12643283.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Users\user\Desktop\Cotizaci#U00f3n#12643283.exe Section loaded: profapi.dll Jump to behavior
Source: C:\Users\user\Desktop\Cotizaci#U00f3n#12643283.exe Section loaded: cryptsp.dll Jump to behavior
Source: C:\Users\user\Desktop\Cotizaci#U00f3n#12643283.exe Section loaded: rsaenh.dll Jump to behavior
Source: C:\Users\user\Desktop\Cotizaci#U00f3n#12643283.exe Section loaded: cryptbase.dll Jump to behavior
Source: C:\Users\user\Desktop\Cotizaci#U00f3n#12643283.exe Section loaded: dwrite.dll Jump to behavior
Source: C:\Users\user\Desktop\Cotizaci#U00f3n#12643283.exe Section loaded: windowscodecs.dll Jump to behavior
Source: C:\Users\user\Desktop\Cotizaci#U00f3n#12643283.exe Section loaded: amsi.dll Jump to behavior
Source: C:\Users\user\Desktop\Cotizaci#U00f3n#12643283.exe Section loaded: userenv.dll Jump to behavior
Source: C:\Users\user\Desktop\Cotizaci#U00f3n#12643283.exe Section loaded: msasn1.dll Jump to behavior
Source: C:\Users\user\Desktop\Cotizaci#U00f3n#12643283.exe Section loaded: gpapi.dll Jump to behavior
Source: C:\Users\user\Desktop\Cotizaci#U00f3n#12643283.exe Section loaded: ntmarta.dll Jump to behavior
Source: C:\Users\user\Desktop\Cotizaci#U00f3n#12643283.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Users\user\Desktop\Cotizaci#U00f3n#12643283.exe Section loaded: propsys.dll Jump to behavior
Source: C:\Users\user\Desktop\Cotizaci#U00f3n#12643283.exe Section loaded: edputil.dll Jump to behavior
Source: C:\Users\user\Desktop\Cotizaci#U00f3n#12643283.exe Section loaded: urlmon.dll Jump to behavior
Source: C:\Users\user\Desktop\Cotizaci#U00f3n#12643283.exe Section loaded: iertutil.dll Jump to behavior
Source: C:\Users\user\Desktop\Cotizaci#U00f3n#12643283.exe Section loaded: srvcli.dll Jump to behavior
Source: C:\Users\user\Desktop\Cotizaci#U00f3n#12643283.exe Section loaded: netutils.dll Jump to behavior
Source: C:\Users\user\Desktop\Cotizaci#U00f3n#12643283.exe Section loaded: windows.staterepositoryps.dll Jump to behavior
Source: C:\Users\user\Desktop\Cotizaci#U00f3n#12643283.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\Desktop\Cotizaci#U00f3n#12643283.exe Section loaded: appresolver.dll Jump to behavior
Source: C:\Users\user\Desktop\Cotizaci#U00f3n#12643283.exe Section loaded: bcp47langs.dll Jump to behavior
Source: C:\Users\user\Desktop\Cotizaci#U00f3n#12643283.exe Section loaded: slc.dll Jump to behavior
Source: C:\Users\user\Desktop\Cotizaci#U00f3n#12643283.exe Section loaded: sppc.dll Jump to behavior
Source: C:\Users\user\Desktop\Cotizaci#U00f3n#12643283.exe Section loaded: onecorecommonproxystub.dll Jump to behavior
Source: C:\Users\user\Desktop\Cotizaci#U00f3n#12643283.exe Section loaded: onecoreuapcommonproxystub.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: atl.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: mscoree.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: version.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: vcruntime140_clr0400.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: ucrtbase_clr0400.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: ucrtbase_clr0400.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: cryptsp.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: rsaenh.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: cryptbase.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: amsi.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: userenv.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: profapi.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: msasn1.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: gpapi.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: msisip.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: wshext.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: appxsip.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: opcservices.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: secur32.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: urlmon.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: iertutil.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: srvcli.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: netutils.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: propsys.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: wininet.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: microsoft.management.infrastructure.native.unmanaged.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: mi.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: miutils.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: wmidcom.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: dpapi.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: wbemcomn.dll Jump to behavior
Source: C:\Windows\SysWOW64\schtasks.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Windows\SysWOW64\schtasks.exe Section loaded: taskschd.dll Jump to behavior
Source: C:\Windows\SysWOW64\schtasks.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Section loaded: mscoree.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Section loaded: version.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Section loaded: vcruntime140_clr0400.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Section loaded: ucrtbase_clr0400.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Section loaded: ucrtbase_clr0400.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Section loaded: profapi.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Section loaded: cryptsp.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Section loaded: rsaenh.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Section loaded: cryptbase.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Section loaded: dwrite.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Section loaded: windowscodecs.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Section loaded: amsi.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Section loaded: userenv.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Section loaded: msasn1.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Section loaded: gpapi.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Section loaded: propsys.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Section loaded: edputil.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Section loaded: urlmon.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Section loaded: iertutil.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Section loaded: srvcli.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Section loaded: netutils.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Section loaded: windows.staterepositoryps.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Section loaded: appresolver.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Section loaded: bcp47langs.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Section loaded: slc.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Section loaded: sppc.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Section loaded: onecorecommonproxystub.dll Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Section loaded: onecoreuapcommonproxystub.dll Jump to behavior
Source: C:\Windows\System32\wbem\WmiPrvSE.exe Section loaded: fastprox.dll Jump to behavior
Source: C:\Windows\System32\wbem\WmiPrvSE.exe Section loaded: ncobjapi.dll Jump to behavior
Source: C:\Windows\System32\wbem\WmiPrvSE.exe Section loaded: wbemcomn.dll Jump to behavior
Source: C:\Windows\System32\wbem\WmiPrvSE.exe Section loaded: wbemcomn.dll Jump to behavior
Source: C:\Windows\System32\wbem\WmiPrvSE.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Windows\System32\wbem\WmiPrvSE.exe Section loaded: mpclient.dll Jump to behavior
Source: C:\Windows\System32\wbem\WmiPrvSE.exe Section loaded: userenv.dll Jump to behavior
Source: C:\Windows\System32\wbem\WmiPrvSE.exe Section loaded: version.dll Jump to behavior
Source: C:\Windows\System32\wbem\WmiPrvSE.exe Section loaded: msasn1.dll Jump to behavior
Source: C:\Windows\System32\wbem\WmiPrvSE.exe Section loaded: wmitomi.dll Jump to behavior
Source: C:\Windows\System32\wbem\WmiPrvSE.exe Section loaded: mi.dll Jump to behavior
Source: C:\Windows\System32\wbem\WmiPrvSE.exe Section loaded: miutils.dll Jump to behavior
Source: C:\Windows\System32\wbem\WmiPrvSE.exe Section loaded: miutils.dll Jump to behavior
Source: C:\Windows\System32\wbem\WmiPrvSE.exe Section loaded: gpapi.dll Jump to behavior
Source: C:\Windows\SysWOW64\schtasks.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Windows\SysWOW64\schtasks.exe Section loaded: taskschd.dll Jump to behavior
Source: C:\Windows\SysWOW64\schtasks.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Users\user\Desktop\Cotizaci#U00f3n#12643283.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0EE7644B-1BAD-48B1-9889-0281C206EB85}\InprocServer32 Jump to behavior
Source: Window Recorder Window detected: More than 3 window changes detected
Source: C:\Users\user\Desktop\Cotizaci#U00f3n#12643283.exe File opened: C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorrc.dll Jump to behavior
Source: Cotizaci#U00f3n#12643283.exe Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR
Source: Cotizaci#U00f3n#12643283.exe Static PE information: DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
Source: Cotizaci#U00f3n#12643283.exe Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
Source: Binary string: ziKI.pdbSHA256OWjP source: Cotizaci#U00f3n#12643283.exe, SoEOsZIV.exe.0.dr
Source: Binary string: wntdll.pdbUGP source: vbc.exe, 00000007.00000002.2862902887.0000000006F30000.00000040.00001000.00020000.00000000.sdmp
Source: Binary string: wntdll.pdb source: vbc.exe, vbc.exe, 00000007.00000002.2862902887.0000000006F30000.00000040.00001000.00020000.00000000.sdmp
Source: Binary string: ziKI.pdb source: Cotizaci#U00f3n#12643283.exe, SoEOsZIV.exe.0.dr

Data Obfuscation

barindex
Source: 0.2.Cotizaci#U00f3n#12643283.exe.2787c50.0.raw.unpack, hrlPDhZiofKOntEGsn.cs .Net Code: DguLQ26lK
Source: 0.2.Cotizaci#U00f3n#12643283.exe.2787c50.0.raw.unpack, hrlPDhZiofKOntEGsn.cs .Net Code: zF7AknH7e System.Reflection.Assembly.Load(byte[])
Source: 0.2.Cotizaci#U00f3n#12643283.exe.3b26650.2.raw.unpack, X64Lfi1jtVl3jyEt1i.cs .Net Code: klJtkkAvFm System.Reflection.Assembly.Load(byte[])
Source: 0.2.Cotizaci#U00f3n#12643283.exe.51b0000.4.raw.unpack, hrlPDhZiofKOntEGsn.cs .Net Code: DguLQ26lK
Source: 0.2.Cotizaci#U00f3n#12643283.exe.51b0000.4.raw.unpack, hrlPDhZiofKOntEGsn.cs .Net Code: zF7AknH7e System.Reflection.Assembly.Load(byte[])
Source: 0.2.Cotizaci#U00f3n#12643283.exe.6a90000.6.raw.unpack, X64Lfi1jtVl3jyEt1i.cs .Net Code: klJtkkAvFm System.Reflection.Assembly.Load(byte[])
Source: 8.2.SoEOsZIV.exe.3167c08.0.raw.unpack, hrlPDhZiofKOntEGsn.cs .Net Code: DguLQ26lK
Source: 8.2.SoEOsZIV.exe.3167c08.0.raw.unpack, hrlPDhZiofKOntEGsn.cs .Net Code: zF7AknH7e System.Reflection.Assembly.Load(byte[])
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_004489BB LoadLibraryW,GetProcAddress,GetProcAddress,EncodePointer,EncodePointer,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,DecodePointer,DecodePointer,DecodePointer,DecodePointer,DecodePointer,DecodePointer, 7_2_004489BB
Source: C:\Users\user\Desktop\Cotizaci#U00f3n#12643283.exe Code function: 0_2_00CDD958 push esp; iretd 0_2_00CDD959
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_00412876 push A7A06875h; ret 7_2_0041287B
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_0040D8FE push esp; retf 7_2_0040D8FF
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_00424A62 push D336233Ah; ret 7_2_00424A67
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_0041FACF push edx; iretd 7_2_0041FAD2
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_0042446A push ebp; ret 7_2_00424470
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_00403CC0 push eax; ret 7_2_00403CC2
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_004164D3 pushad ; retn 81BAh 7_2_004164A5
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_00422CF2 push es; retn 0000h 7_2_00422CFA
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_00423D08 push edx; retf 7_2_00423D26
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_00447DF5 push ecx; ret 7_2_00447E08
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_0040D699 push es; ret 7_2_0040D6A2
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_00411F68 pushfd ; iretd 7_2_00411F69
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F327FA pushad ; ret 7_2_06F327F9
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F3225F pushad ; ret 7_2_06F327F9
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F3283D push eax; iretd 7_2_06F32858
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F609AD push ecx; mov dword ptr [esp], ecx 7_2_06F609B6
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F3135D push eax; iretd 7_2_06F31369
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Code function: 8_2_0190D958 push esp; iretd 8_2_0190D959
Source: Cotizaci#U00f3n#12643283.exe Static PE information: section name: .text entropy: 7.890900297629251
Source: SoEOsZIV.exe.0.dr Static PE information: section name: .text entropy: 7.890900297629251
Source: 0.2.Cotizaci#U00f3n#12643283.exe.2787c50.0.raw.unpack, hrlPDhZiofKOntEGsn.cs High entropy of concatenated method names: 'HW1ErlPDh', 'sofPKOntE', 'SsnflUJon', 'aMB144uHG', 'b2TDraJQL', 'DooTW4SZv', 'e6wSRoREk', 'eiIOxF2Ts', 'n4FpBtydB', 'kDGIyt7hv'
Source: 0.2.Cotizaci#U00f3n#12643283.exe.3b26650.2.raw.unpack, KmMxWwdtUcVDYnuVm6.cs High entropy of concatenated method names: 'Va5POCurro', 'qXcPGTlL6R', 'AKVPdZs0YC', 'krCPpR15EF', 'h7ZPc3JhCZ', 'SSqPu6uBnA', 'G9qP0uU0Nk', 'LRUPm9VNFY', 'fmEP6yjMOP', 'pFLPwEb3h6'
Source: 0.2.Cotizaci#U00f3n#12643283.exe.3b26650.2.raw.unpack, vHJJC5K2tkViAevmvn.cs High entropy of concatenated method names: 'vF7kUDD5S', 'uPBTWIxTy', 'pVGZuCfFJ', 'raCo1Q9Wj', 'wyGbdq4oq', 'Y7O84LPik', 'lK6JgIpMboRXfCqDvw', 'IsY6KeOSoxKPUdqrk4', 'zqpRlWC3C', 'UxOsSXNdj'
Source: 0.2.Cotizaci#U00f3n#12643283.exe.3b26650.2.raw.unpack, QbHdNKqxbkGkrecOev.cs High entropy of concatenated method names: 'tPURY8AlVg', 'Q04RXhxLsb', 'T92RnkNuRA', 'ynnRx1R7nk', 'Hi7R2QoFwI', 'YGwRa0FL7l', 'yRhR1cNBXI', 'RrtRVq1nxm', 'RJwRSEgp7E', 'FSoRgynnLL'
Source: 0.2.Cotizaci#U00f3n#12643283.exe.3b26650.2.raw.unpack, uAN4lGHduACvYLIf1A.cs High entropy of concatenated method names: 'BIUjq2HKfW', 'TGUjMcKjTQ', 'VacRWW1K5o', 'Xb2R4XdqoP', 'soSjD0QldI', 'QxBjGxftVT', 'VdJj9CA0Nq', 'gtsjdqWfBG', 'jUAjpeT0iB', 'hguj5DC3pA'
Source: 0.2.Cotizaci#U00f3n#12643283.exe.3b26650.2.raw.unpack, R8VZhIzTf41kQxEkhy.cs High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'AMuvrQRqqt', 'uWOvPJftXW', 'nVNvLbmsTA', 'uluvjtnkct', 'xwNvR7gt1l', 'ysOvvEPG7R', 'PJwvsf43Z6'
Source: 0.2.Cotizaci#U00f3n#12643283.exe.3b26650.2.raw.unpack, udjcIv0ZJTDs7tAotk.cs High entropy of concatenated method names: 'AlR2QBFtnA', 'jTa2iv6MoE', 'QXy2k71nNK', 'hc72Tw3L5C', 'AHl2Z9sGRX', 'r5T2ogH7aq', 'U0s2bQdGyy', 'FaE28HaG2V', 'pkK8Qpx3JRJY4dPtHBV', 'V110otxcbsu73kW0lIN'
Source: 0.2.Cotizaci#U00f3n#12643283.exe.3b26650.2.raw.unpack, CQlmh8tyhe0P1mxveN.cs High entropy of concatenated method names: 'leD4a6gQHw', 'tUI41kW5Mi', 'UZo4SGdc3O', 'MGW4gJyZtH', 'IXR4POP3sV', 'O7p4LGcJlb', 'VaxxroHD6Mfk3HdKFa', 'GWxdQVow58qY81kZB1', 'RGu449Gtap', 'k0u4ecE4QN'
Source: 0.2.Cotizaci#U00f3n#12643283.exe.3b26650.2.raw.unpack, FiU0TP4eTmYM2TDeF7T.cs High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'tcnsdZCPm6', 'ko7spSSK4N', 'Vq0s5WgaFV', 'sdUsyOsZtD', 'hBAs3Rlr8B', 'RtqsHNnpmU', 'edPsE3QaYe'
Source: 0.2.Cotizaci#U00f3n#12643283.exe.3b26650.2.raw.unpack, UsVD7pFGcJlbMYMWlC.cs High entropy of concatenated method names: 'FdS2l25BU4', 'JRw2XlFnV0', 'ERt2xeFZHv', 'nX22amB96b', 'tWa21FmSpi', 'Ridx3u3b8c', 's8QxHC91Mh', 'IbXxEU13nP', 'cpQxqYKPIa', 'OcHxJuJIyb'
Source: 0.2.Cotizaci#U00f3n#12643283.exe.3b26650.2.raw.unpack, yFYUTH9dQCSihIrfN8.cs High entropy of concatenated method names: 'YwSrNVtAdC', 'BGxrbdZu93', 'qdgrF8tAjb', 'mJIrcPp3aa', 'sKTr0MDwym', 'QMNrmDEICw', 'wWqrw3QVJ6', 'pcdrfOecUT', 'btNrOd5e0j', 'KxFrDkmbrY'
Source: 0.2.Cotizaci#U00f3n#12643283.exe.3b26650.2.raw.unpack, I2ndhq4W97PQL4Zt1A3.cs High entropy of concatenated method names: 'FYwviwHB8i', 'Mh8vA8aIZU', 'LHvvkUuerj', 'pf6vTmeTka', 'rXOvCGhtyu', 'hOjvZpO7KE', 'CJJvoWSwtS', 'oGSvN3yQiW', 'OjOvbPJYmJ', 'Yn6v8kmGNs'
Source: 0.2.Cotizaci#U00f3n#12643283.exe.3b26650.2.raw.unpack, TNwhmrJA7QUJEq8IpZ.cs High entropy of concatenated method names: 'uDGRFMWkjP', 'Rd2RcLcfdX', 'QXlRuNkdAl', 'QYJR0RH88G', 'pOXRdQVa25', 'BctRmR8X7O', 'Next', 'Next', 'Next', 'NextBytes'
Source: 0.2.Cotizaci#U00f3n#12643283.exe.3b26650.2.raw.unpack, fen0wCMSaQ3bSmWfmi.cs High entropy of concatenated method names: 'oQLv4YAehA', 'LUVveqfn38', 'joyvtDYoXP', 'j6KvYOhL3R', 'gX6vXtJUH6', 'F1SvxtQHIe', 'ATDv2IWj92', 'o6RREiLioC', 'hLpRqX5Ode', 'XqcRJddLU7'
Source: 0.2.Cotizaci#U00f3n#12643283.exe.3b26650.2.raw.unpack, TZtHoF8fslOLl0XROP.cs High entropy of concatenated method names: 'yblxC9POl0', 'PKXxooB5L9', 'cJ2nuyAGrI', 'X52n0wFwJC', 'PIynmBwXvt', 'krwn6MAdRs', 'rh8nw2xd9b', 'DVenf7Z6oW', 'Ts7nBtHHNE', 'bJEnOrGGbw'
Source: 0.2.Cotizaci#U00f3n#12643283.exe.3b26650.2.raw.unpack, O6gQHwN7UIkW5MiRmW.cs High entropy of concatenated method names: 'gOFXd3lGW0', 'aYNXptvlMo', 'npYX5tJ0eY', 'VneXy32l5T', 'mlQX3LQDak', 'M8yXHOd8BB', 's6hXEGyOpG', 'XbRXqsyK95', 'LeGXJgdeaa', 'AdJXM0GQdw'
Source: 0.2.Cotizaci#U00f3n#12643283.exe.3b26650.2.raw.unpack, X64Lfi1jtVl3jyEt1i.cs High entropy of concatenated method names: 'gtJelSBVwC', 'iUOeYbaPPm', 'Vd8eX83icW', 'xe0enfv5Tg', 'iwhexnxAUo', 'aFWe2twW6h', 'mXEearZTiv', 'yW0e1q5q0o', 'VkTeVO6ije', 'te4eS2pBrB'
Source: 0.2.Cotizaci#U00f3n#12643283.exe.3b26650.2.raw.unpack, Pk5KK3bZoGdc3OfGWJ.cs High entropy of concatenated method names: 'E1CnT4R3Lb', 'ds8nZcJyLU', 'iaCnNuHfW8', 'JcHnbyrf1r', 'gDenPj2DwS', 'iE9nLmC8id', 'ioXnjJZ9to', 'jwunRltyMT', 'nsgnvE8W2G', 'CLdnsIUVVr'
Source: 0.2.Cotizaci#U00f3n#12643283.exe.3b26650.2.raw.unpack, rkjV03XSm4YnJI5K1S.cs High entropy of concatenated method names: 'Dispose', 'bGY4JmC5rt', 'WFoKcZQ5oM', 'UPcVVpljWh', 'G9b4MHdNKx', 'EkG4zkrecO', 'ProcessDialogKey', 'cvyKWNwhmr', 'y7QK4UJEq8', 'upZKKXen0w'
Source: 0.2.Cotizaci#U00f3n#12643283.exe.3b26650.2.raw.unpack, bNq9YewEONQ0p6tZpQ.cs High entropy of concatenated method names: 'bsiaYUnFLJ', 'Fn1anqe7O5', 'NSKa2tvdgn', 'VhQ2MZ1OMS', 'zVC2z8UFKY', 'xmDaWfXjXs', 'M4na4yafAM', 'fPjaKXXS6r', 'pZ4aeMW6O7', 'eMIatxG3v7'
Source: 0.2.Cotizaci#U00f3n#12643283.exe.3b26650.2.raw.unpack, XK7PdiBrxU3m1lOQsS.cs High entropy of concatenated method names: 'NVBaiF2lyn', 'qJRaAxtiI4', 'Ry3akcScvE', 'dcUaTqgDBb', 'd74aCMNJkM', 'w3caZb4AHa', 'kEmaoDOCFw', 'uqBaNf5o0w', 'sXWabd7ssS', 'w7Ra8OqrUR'
Source: 0.2.Cotizaci#U00f3n#12643283.exe.51b0000.4.raw.unpack, hrlPDhZiofKOntEGsn.cs High entropy of concatenated method names: 'HW1ErlPDh', 'sofPKOntE', 'SsnflUJon', 'aMB144uHG', 'b2TDraJQL', 'DooTW4SZv', 'e6wSRoREk', 'eiIOxF2Ts', 'n4FpBtydB', 'kDGIyt7hv'
Source: 0.2.Cotizaci#U00f3n#12643283.exe.6a90000.6.raw.unpack, KmMxWwdtUcVDYnuVm6.cs High entropy of concatenated method names: 'Va5POCurro', 'qXcPGTlL6R', 'AKVPdZs0YC', 'krCPpR15EF', 'h7ZPc3JhCZ', 'SSqPu6uBnA', 'G9qP0uU0Nk', 'LRUPm9VNFY', 'fmEP6yjMOP', 'pFLPwEb3h6'
Source: 0.2.Cotizaci#U00f3n#12643283.exe.6a90000.6.raw.unpack, vHJJC5K2tkViAevmvn.cs High entropy of concatenated method names: 'vF7kUDD5S', 'uPBTWIxTy', 'pVGZuCfFJ', 'raCo1Q9Wj', 'wyGbdq4oq', 'Y7O84LPik', 'lK6JgIpMboRXfCqDvw', 'IsY6KeOSoxKPUdqrk4', 'zqpRlWC3C', 'UxOsSXNdj'
Source: 0.2.Cotizaci#U00f3n#12643283.exe.6a90000.6.raw.unpack, QbHdNKqxbkGkrecOev.cs High entropy of concatenated method names: 'tPURY8AlVg', 'Q04RXhxLsb', 'T92RnkNuRA', 'ynnRx1R7nk', 'Hi7R2QoFwI', 'YGwRa0FL7l', 'yRhR1cNBXI', 'RrtRVq1nxm', 'RJwRSEgp7E', 'FSoRgynnLL'
Source: 0.2.Cotizaci#U00f3n#12643283.exe.6a90000.6.raw.unpack, uAN4lGHduACvYLIf1A.cs High entropy of concatenated method names: 'BIUjq2HKfW', 'TGUjMcKjTQ', 'VacRWW1K5o', 'Xb2R4XdqoP', 'soSjD0QldI', 'QxBjGxftVT', 'VdJj9CA0Nq', 'gtsjdqWfBG', 'jUAjpeT0iB', 'hguj5DC3pA'
Source: 0.2.Cotizaci#U00f3n#12643283.exe.6a90000.6.raw.unpack, R8VZhIzTf41kQxEkhy.cs High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'AMuvrQRqqt', 'uWOvPJftXW', 'nVNvLbmsTA', 'uluvjtnkct', 'xwNvR7gt1l', 'ysOvvEPG7R', 'PJwvsf43Z6'
Source: 0.2.Cotizaci#U00f3n#12643283.exe.6a90000.6.raw.unpack, udjcIv0ZJTDs7tAotk.cs High entropy of concatenated method names: 'AlR2QBFtnA', 'jTa2iv6MoE', 'QXy2k71nNK', 'hc72Tw3L5C', 'AHl2Z9sGRX', 'r5T2ogH7aq', 'U0s2bQdGyy', 'FaE28HaG2V', 'pkK8Qpx3JRJY4dPtHBV', 'V110otxcbsu73kW0lIN'
Source: 0.2.Cotizaci#U00f3n#12643283.exe.6a90000.6.raw.unpack, CQlmh8tyhe0P1mxveN.cs High entropy of concatenated method names: 'leD4a6gQHw', 'tUI41kW5Mi', 'UZo4SGdc3O', 'MGW4gJyZtH', 'IXR4POP3sV', 'O7p4LGcJlb', 'VaxxroHD6Mfk3HdKFa', 'GWxdQVow58qY81kZB1', 'RGu449Gtap', 'k0u4ecE4QN'
Source: 0.2.Cotizaci#U00f3n#12643283.exe.6a90000.6.raw.unpack, FiU0TP4eTmYM2TDeF7T.cs High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'tcnsdZCPm6', 'ko7spSSK4N', 'Vq0s5WgaFV', 'sdUsyOsZtD', 'hBAs3Rlr8B', 'RtqsHNnpmU', 'edPsE3QaYe'
Source: 0.2.Cotizaci#U00f3n#12643283.exe.6a90000.6.raw.unpack, UsVD7pFGcJlbMYMWlC.cs High entropy of concatenated method names: 'FdS2l25BU4', 'JRw2XlFnV0', 'ERt2xeFZHv', 'nX22amB96b', 'tWa21FmSpi', 'Ridx3u3b8c', 's8QxHC91Mh', 'IbXxEU13nP', 'cpQxqYKPIa', 'OcHxJuJIyb'
Source: 0.2.Cotizaci#U00f3n#12643283.exe.6a90000.6.raw.unpack, yFYUTH9dQCSihIrfN8.cs High entropy of concatenated method names: 'YwSrNVtAdC', 'BGxrbdZu93', 'qdgrF8tAjb', 'mJIrcPp3aa', 'sKTr0MDwym', 'QMNrmDEICw', 'wWqrw3QVJ6', 'pcdrfOecUT', 'btNrOd5e0j', 'KxFrDkmbrY'
Source: 0.2.Cotizaci#U00f3n#12643283.exe.6a90000.6.raw.unpack, I2ndhq4W97PQL4Zt1A3.cs High entropy of concatenated method names: 'FYwviwHB8i', 'Mh8vA8aIZU', 'LHvvkUuerj', 'pf6vTmeTka', 'rXOvCGhtyu', 'hOjvZpO7KE', 'CJJvoWSwtS', 'oGSvN3yQiW', 'OjOvbPJYmJ', 'Yn6v8kmGNs'
Source: 0.2.Cotizaci#U00f3n#12643283.exe.6a90000.6.raw.unpack, TNwhmrJA7QUJEq8IpZ.cs High entropy of concatenated method names: 'uDGRFMWkjP', 'Rd2RcLcfdX', 'QXlRuNkdAl', 'QYJR0RH88G', 'pOXRdQVa25', 'BctRmR8X7O', 'Next', 'Next', 'Next', 'NextBytes'
Source: 0.2.Cotizaci#U00f3n#12643283.exe.6a90000.6.raw.unpack, fen0wCMSaQ3bSmWfmi.cs High entropy of concatenated method names: 'oQLv4YAehA', 'LUVveqfn38', 'joyvtDYoXP', 'j6KvYOhL3R', 'gX6vXtJUH6', 'F1SvxtQHIe', 'ATDv2IWj92', 'o6RREiLioC', 'hLpRqX5Ode', 'XqcRJddLU7'
Source: 0.2.Cotizaci#U00f3n#12643283.exe.6a90000.6.raw.unpack, TZtHoF8fslOLl0XROP.cs High entropy of concatenated method names: 'yblxC9POl0', 'PKXxooB5L9', 'cJ2nuyAGrI', 'X52n0wFwJC', 'PIynmBwXvt', 'krwn6MAdRs', 'rh8nw2xd9b', 'DVenf7Z6oW', 'Ts7nBtHHNE', 'bJEnOrGGbw'
Source: 0.2.Cotizaci#U00f3n#12643283.exe.6a90000.6.raw.unpack, O6gQHwN7UIkW5MiRmW.cs High entropy of concatenated method names: 'gOFXd3lGW0', 'aYNXptvlMo', 'npYX5tJ0eY', 'VneXy32l5T', 'mlQX3LQDak', 'M8yXHOd8BB', 's6hXEGyOpG', 'XbRXqsyK95', 'LeGXJgdeaa', 'AdJXM0GQdw'
Source: 0.2.Cotizaci#U00f3n#12643283.exe.6a90000.6.raw.unpack, X64Lfi1jtVl3jyEt1i.cs High entropy of concatenated method names: 'gtJelSBVwC', 'iUOeYbaPPm', 'Vd8eX83icW', 'xe0enfv5Tg', 'iwhexnxAUo', 'aFWe2twW6h', 'mXEearZTiv', 'yW0e1q5q0o', 'VkTeVO6ije', 'te4eS2pBrB'
Source: 0.2.Cotizaci#U00f3n#12643283.exe.6a90000.6.raw.unpack, Pk5KK3bZoGdc3OfGWJ.cs High entropy of concatenated method names: 'E1CnT4R3Lb', 'ds8nZcJyLU', 'iaCnNuHfW8', 'JcHnbyrf1r', 'gDenPj2DwS', 'iE9nLmC8id', 'ioXnjJZ9to', 'jwunRltyMT', 'nsgnvE8W2G', 'CLdnsIUVVr'
Source: 0.2.Cotizaci#U00f3n#12643283.exe.6a90000.6.raw.unpack, rkjV03XSm4YnJI5K1S.cs High entropy of concatenated method names: 'Dispose', 'bGY4JmC5rt', 'WFoKcZQ5oM', 'UPcVVpljWh', 'G9b4MHdNKx', 'EkG4zkrecO', 'ProcessDialogKey', 'cvyKWNwhmr', 'y7QK4UJEq8', 'upZKKXen0w'
Source: 0.2.Cotizaci#U00f3n#12643283.exe.6a90000.6.raw.unpack, bNq9YewEONQ0p6tZpQ.cs High entropy of concatenated method names: 'bsiaYUnFLJ', 'Fn1anqe7O5', 'NSKa2tvdgn', 'VhQ2MZ1OMS', 'zVC2z8UFKY', 'xmDaWfXjXs', 'M4na4yafAM', 'fPjaKXXS6r', 'pZ4aeMW6O7', 'eMIatxG3v7'
Source: 0.2.Cotizaci#U00f3n#12643283.exe.6a90000.6.raw.unpack, XK7PdiBrxU3m1lOQsS.cs High entropy of concatenated method names: 'NVBaiF2lyn', 'qJRaAxtiI4', 'Ry3akcScvE', 'dcUaTqgDBb', 'd74aCMNJkM', 'w3caZb4AHa', 'kEmaoDOCFw', 'uqBaNf5o0w', 'sXWabd7ssS', 'w7Ra8OqrUR'
Source: 8.2.SoEOsZIV.exe.3167c08.0.raw.unpack, hrlPDhZiofKOntEGsn.cs High entropy of concatenated method names: 'HW1ErlPDh', 'sofPKOntE', 'SsnflUJon', 'aMB144uHG', 'b2TDraJQL', 'DooTW4SZv', 'e6wSRoREk', 'eiIOxF2Ts', 'n4FpBtydB', 'kDGIyt7hv'
Source: C:\Users\user\Desktop\Cotizaci#U00f3n#12643283.exe File created: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Jump to dropped file

Boot Survival

barindex
Source: C:\Users\user\Desktop\Cotizaci#U00f3n#12643283.exe Process created: C:\Windows\SysWOW64\schtasks.exe "C:\Windows\System32\schtasks.exe" /Create /TN "Updates\SoEOsZIV" /XML "C:\Users\user\AppData\Local\Temp\tmpAC01.tmp"

Hooking and other Techniques for Hiding and Protection

barindex
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe File opened: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\BitLocker\BitLocker.psd1 Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe File opened: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\BitLocker\BitLocker.psd1 Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe File opened: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\BitLocker\BitLocker.psd1 Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe File opened: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\BitLocker\en-US\BitLocker.psd1 Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe File opened: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\BitLocker\en-US\BitLocker.psd1 Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe File opened: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\BitLocker\BitLocker.psd1 Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe File opened: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\BitLocker\en-US\BitLocker.psd1 Jump to behavior
Source: C:\Users\user\Desktop\Cotizaci#U00f3n#12643283.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Cotizaci#U00f3n#12643283.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Cotizaci#U00f3n#12643283.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Cotizaci#U00f3n#12643283.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Cotizaci#U00f3n#12643283.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Cotizaci#U00f3n#12643283.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Cotizaci#U00f3n#12643283.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Cotizaci#U00f3n#12643283.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Cotizaci#U00f3n#12643283.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Cotizaci#U00f3n#12643283.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Cotizaci#U00f3n#12643283.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Cotizaci#U00f3n#12643283.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Cotizaci#U00f3n#12643283.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Cotizaci#U00f3n#12643283.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Cotizaci#U00f3n#12643283.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Cotizaci#U00f3n#12643283.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Cotizaci#U00f3n#12643283.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Cotizaci#U00f3n#12643283.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Cotizaci#U00f3n#12643283.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Cotizaci#U00f3n#12643283.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Cotizaci#U00f3n#12643283.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Cotizaci#U00f3n#12643283.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Cotizaci#U00f3n#12643283.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Cotizaci#U00f3n#12643283.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Cotizaci#U00f3n#12643283.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Cotizaci#U00f3n#12643283.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Cotizaci#U00f3n#12643283.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Cotizaci#U00f3n#12643283.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Cotizaci#U00f3n#12643283.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Cotizaci#U00f3n#12643283.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Cotizaci#U00f3n#12643283.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Cotizaci#U00f3n#12643283.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Cotizaci#U00f3n#12643283.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Cotizaci#U00f3n#12643283.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Cotizaci#U00f3n#12643283.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Cotizaci#U00f3n#12643283.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Cotizaci#U00f3n#12643283.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Cotizaci#U00f3n#12643283.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Cotizaci#U00f3n#12643283.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Cotizaci#U00f3n#12643283.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Cotizaci#U00f3n#12643283.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Cotizaci#U00f3n#12643283.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Process information set: NOOPENFILEERRORBOX Jump to behavior

Malware Analysis System Evasion

barindex
Source: Yara match File source: Process Memory Space: Cotizaci#U00f3n#12643283.exe PID: 2968, type: MEMORYSTR
Source: Yara match File source: Process Memory Space: SoEOsZIV.exe PID: 4788, type: MEMORYSTR
Source: C:\Users\user\Desktop\Cotizaci#U00f3n#12643283.exe Memory allocated: C20000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\Desktop\Cotizaci#U00f3n#12643283.exe Memory allocated: 2750000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\Desktop\Cotizaci#U00f3n#12643283.exe Memory allocated: 4750000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\Desktop\Cotizaci#U00f3n#12643283.exe Memory allocated: 7270000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\Desktop\Cotizaci#U00f3n#12643283.exe Memory allocated: 8270000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\Desktop\Cotizaci#U00f3n#12643283.exe Memory allocated: 8410000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\Desktop\Cotizaci#U00f3n#12643283.exe Memory allocated: 9410000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Memory allocated: 1900000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Memory allocated: 3130000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Memory allocated: 5230000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Memory allocated: 79B0000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Memory allocated: 89B0000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Memory allocated: 8B40000 memory reserve | memory write watch Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Memory allocated: 9B40000 memory reserve | memory write watch Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FA096E rdtsc 7_2_06FA096E
Source: C:\Users\user\Desktop\Cotizaci#U00f3n#12643283.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Window / User API: threadDelayed 6126 Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Window / User API: threadDelayed 1716 Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe API coverage: 0.6 %
Source: C:\Users\user\Desktop\Cotizaci#U00f3n#12643283.exe TID: 4996 Thread sleep time: -922337203685477s >= -30000s Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe TID: 1032 Thread sleep time: -3689348814741908s >= -30000s Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe TID: 5764 Thread sleep time: -922337203685477s >= -30000s Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe TID: 2736 Thread sleep time: -30000s >= -30000s Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe TID: 6992 Thread sleep time: -922337203685477s >= -30000s Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Last function: Thread delayed
Source: C:\Windows\System32\conhost.exe Last function: Thread delayed
Source: C:\Windows\System32\conhost.exe Last function: Thread delayed
Source: C:\Users\user\Desktop\Cotizaci#U00f3n#12643283.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information queried: ProcessInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Process queried: DebugPort Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FA096E rdtsc 7_2_06FA096E
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_00417D63 LdrLoadDll, 7_2_00417D63
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_004469B8 IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess, 7_2_004469B8
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_004489BB LoadLibraryW,GetProcAddress,GetProcAddress,EncodePointer,EncodePointer,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,GetProcAddress,EncodePointer,DecodePointer,DecodePointer,DecodePointer,DecodePointer,DecodePointer,DecodePointer, 7_2_004489BB
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FDE6F2 mov eax, dword ptr fs:[00000030h] 7_2_06FDE6F2
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FDE6F2 mov eax, dword ptr fs:[00000030h] 7_2_06FDE6F2
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FDE6F2 mov eax, dword ptr fs:[00000030h] 7_2_06FDE6F2
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FDE6F2 mov eax, dword ptr fs:[00000030h] 7_2_06FDE6F2
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FE06F1 mov eax, dword ptr fs:[00000030h] 7_2_06FE06F1
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FE06F1 mov eax, dword ptr fs:[00000030h] 7_2_06FE06F1
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F9A6C7 mov ebx, dword ptr fs:[00000030h] 7_2_06F9A6C7
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F9A6C7 mov eax, dword ptr fs:[00000030h] 7_2_06F9A6C7
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F966B0 mov eax, dword ptr fs:[00000030h] 7_2_06F966B0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F9C6A6 mov eax, dword ptr fs:[00000030h] 7_2_06F9C6A6
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F64690 mov eax, dword ptr fs:[00000030h] 7_2_06F64690
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F64690 mov eax, dword ptr fs:[00000030h] 7_2_06F64690
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F92674 mov eax, dword ptr fs:[00000030h] 7_2_06F92674
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_0700678E mov eax, dword ptr fs:[00000030h] 7_2_0700678E
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F9A660 mov eax, dword ptr fs:[00000030h] 7_2_06F9A660
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F9A660 mov eax, dword ptr fs:[00000030h] 7_2_06F9A660
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_070147A0 mov eax, dword ptr fs:[00000030h] 7_2_070147A0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F7C640 mov eax, dword ptr fs:[00000030h] 7_2_06F7C640
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F7E627 mov eax, dword ptr fs:[00000030h] 7_2_06F7E627
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F96620 mov eax, dword ptr fs:[00000030h] 7_2_06F96620
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F98620 mov eax, dword ptr fs:[00000030h] 7_2_06F98620
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F6262C mov eax, dword ptr fs:[00000030h] 7_2_06F6262C
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FA2619 mov eax, dword ptr fs:[00000030h] 7_2_06FA2619
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FDE609 mov eax, dword ptr fs:[00000030h] 7_2_06FDE609
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F7260B mov eax, dword ptr fs:[00000030h] 7_2_06F7260B
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F7260B mov eax, dword ptr fs:[00000030h] 7_2_06F7260B
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F7260B mov eax, dword ptr fs:[00000030h] 7_2_06F7260B
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F7260B mov eax, dword ptr fs:[00000030h] 7_2_06F7260B
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F7260B mov eax, dword ptr fs:[00000030h] 7_2_06F7260B
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F7260B mov eax, dword ptr fs:[00000030h] 7_2_06F7260B
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F7260B mov eax, dword ptr fs:[00000030h] 7_2_06F7260B
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F647FB mov eax, dword ptr fs:[00000030h] 7_2_06F647FB
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F647FB mov eax, dword ptr fs:[00000030h] 7_2_06F647FB
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F827ED mov eax, dword ptr fs:[00000030h] 7_2_06F827ED
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F827ED mov eax, dword ptr fs:[00000030h] 7_2_06F827ED
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F827ED mov eax, dword ptr fs:[00000030h] 7_2_06F827ED
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FEE7E1 mov eax, dword ptr fs:[00000030h] 7_2_06FEE7E1
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F6C7C0 mov eax, dword ptr fs:[00000030h] 7_2_06F6C7C0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FE07C3 mov eax, dword ptr fs:[00000030h] 7_2_06FE07C3
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F607AF mov eax, dword ptr fs:[00000030h] 7_2_06F607AF
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_0702866E mov eax, dword ptr fs:[00000030h] 7_2_0702866E
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_0702866E mov eax, dword ptr fs:[00000030h] 7_2_0702866E
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F68770 mov eax, dword ptr fs:[00000030h] 7_2_06F68770
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F70770 mov eax, dword ptr fs:[00000030h] 7_2_06F70770
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F70770 mov eax, dword ptr fs:[00000030h] 7_2_06F70770
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F70770 mov eax, dword ptr fs:[00000030h] 7_2_06F70770
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F70770 mov eax, dword ptr fs:[00000030h] 7_2_06F70770
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F70770 mov eax, dword ptr fs:[00000030h] 7_2_06F70770
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F70770 mov eax, dword ptr fs:[00000030h] 7_2_06F70770
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F70770 mov eax, dword ptr fs:[00000030h] 7_2_06F70770
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F70770 mov eax, dword ptr fs:[00000030h] 7_2_06F70770
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F70770 mov eax, dword ptr fs:[00000030h] 7_2_06F70770
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F70770 mov eax, dword ptr fs:[00000030h] 7_2_06F70770
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F70770 mov eax, dword ptr fs:[00000030h] 7_2_06F70770
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F70770 mov eax, dword ptr fs:[00000030h] 7_2_06F70770
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FEE75D mov eax, dword ptr fs:[00000030h] 7_2_06FEE75D
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F60750 mov eax, dword ptr fs:[00000030h] 7_2_06F60750
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FA2750 mov eax, dword ptr fs:[00000030h] 7_2_06FA2750
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FA2750 mov eax, dword ptr fs:[00000030h] 7_2_06FA2750
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FE4755 mov eax, dword ptr fs:[00000030h] 7_2_06FE4755
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F9674D mov esi, dword ptr fs:[00000030h] 7_2_06F9674D
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F9674D mov eax, dword ptr fs:[00000030h] 7_2_06F9674D
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F9674D mov eax, dword ptr fs:[00000030h] 7_2_06F9674D
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F9273C mov eax, dword ptr fs:[00000030h] 7_2_06F9273C
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F9273C mov ecx, dword ptr fs:[00000030h] 7_2_06F9273C
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F9273C mov eax, dword ptr fs:[00000030h] 7_2_06F9273C
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FDC730 mov eax, dword ptr fs:[00000030h] 7_2_06FDC730
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F9C720 mov eax, dword ptr fs:[00000030h] 7_2_06F9C720
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F9C720 mov eax, dword ptr fs:[00000030h] 7_2_06F9C720
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F60710 mov eax, dword ptr fs:[00000030h] 7_2_06F60710
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F90710 mov eax, dword ptr fs:[00000030h] 7_2_06F90710
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F9C700 mov eax, dword ptr fs:[00000030h] 7_2_06F9C700
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_07034500 mov eax, dword ptr fs:[00000030h] 7_2_07034500
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_07034500 mov eax, dword ptr fs:[00000030h] 7_2_07034500
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_07034500 mov eax, dword ptr fs:[00000030h] 7_2_07034500
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_07034500 mov eax, dword ptr fs:[00000030h] 7_2_07034500
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_07034500 mov eax, dword ptr fs:[00000030h] 7_2_07034500
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_07034500 mov eax, dword ptr fs:[00000030h] 7_2_07034500
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_07034500 mov eax, dword ptr fs:[00000030h] 7_2_07034500
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F604E5 mov ecx, dword ptr fs:[00000030h] 7_2_06F604E5
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F944B0 mov ecx, dword ptr fs:[00000030h] 7_2_06F944B0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FEA4B0 mov eax, dword ptr fs:[00000030h] 7_2_06FEA4B0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F664AB mov eax, dword ptr fs:[00000030h] 7_2_06F664AB
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F8A470 mov eax, dword ptr fs:[00000030h] 7_2_06F8A470
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F8A470 mov eax, dword ptr fs:[00000030h] 7_2_06F8A470
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F8A470 mov eax, dword ptr fs:[00000030h] 7_2_06F8A470
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FEC460 mov ecx, dword ptr fs:[00000030h] 7_2_06FEC460
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F8245A mov eax, dword ptr fs:[00000030h] 7_2_06F8245A
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F5645D mov eax, dword ptr fs:[00000030h] 7_2_06F5645D
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F9E443 mov eax, dword ptr fs:[00000030h] 7_2_06F9E443
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F9E443 mov eax, dword ptr fs:[00000030h] 7_2_06F9E443
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F9E443 mov eax, dword ptr fs:[00000030h] 7_2_06F9E443
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F9E443 mov eax, dword ptr fs:[00000030h] 7_2_06F9E443
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F9E443 mov eax, dword ptr fs:[00000030h] 7_2_06F9E443
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F9E443 mov eax, dword ptr fs:[00000030h] 7_2_06F9E443
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F9E443 mov eax, dword ptr fs:[00000030h] 7_2_06F9E443
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F9E443 mov eax, dword ptr fs:[00000030h] 7_2_06F9E443
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F9A430 mov eax, dword ptr fs:[00000030h] 7_2_06F9A430
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F5C427 mov eax, dword ptr fs:[00000030h] 7_2_06F5C427
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F5E420 mov eax, dword ptr fs:[00000030h] 7_2_06F5E420
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F5E420 mov eax, dword ptr fs:[00000030h] 7_2_06F5E420
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F5E420 mov eax, dword ptr fs:[00000030h] 7_2_06F5E420
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FE6420 mov eax, dword ptr fs:[00000030h] 7_2_06FE6420
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FE6420 mov eax, dword ptr fs:[00000030h] 7_2_06FE6420
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FE6420 mov eax, dword ptr fs:[00000030h] 7_2_06FE6420
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FE6420 mov eax, dword ptr fs:[00000030h] 7_2_06FE6420
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FE6420 mov eax, dword ptr fs:[00000030h] 7_2_06FE6420
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FE6420 mov eax, dword ptr fs:[00000030h] 7_2_06FE6420
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FE6420 mov eax, dword ptr fs:[00000030h] 7_2_06FE6420
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F98402 mov eax, dword ptr fs:[00000030h] 7_2_06F98402
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F98402 mov eax, dword ptr fs:[00000030h] 7_2_06F98402
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F98402 mov eax, dword ptr fs:[00000030h] 7_2_06F98402
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F9C5ED mov eax, dword ptr fs:[00000030h] 7_2_06F9C5ED
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F9C5ED mov eax, dword ptr fs:[00000030h] 7_2_06F9C5ED
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F625E0 mov eax, dword ptr fs:[00000030h] 7_2_06F625E0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F8E5E7 mov eax, dword ptr fs:[00000030h] 7_2_06F8E5E7
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F8E5E7 mov eax, dword ptr fs:[00000030h] 7_2_06F8E5E7
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F8E5E7 mov eax, dword ptr fs:[00000030h] 7_2_06F8E5E7
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F8E5E7 mov eax, dword ptr fs:[00000030h] 7_2_06F8E5E7
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F8E5E7 mov eax, dword ptr fs:[00000030h] 7_2_06F8E5E7
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F8E5E7 mov eax, dword ptr fs:[00000030h] 7_2_06F8E5E7
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F8E5E7 mov eax, dword ptr fs:[00000030h] 7_2_06F8E5E7
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F8E5E7 mov eax, dword ptr fs:[00000030h] 7_2_06F8E5E7
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F665D0 mov eax, dword ptr fs:[00000030h] 7_2_06F665D0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F9A5D0 mov eax, dword ptr fs:[00000030h] 7_2_06F9A5D0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F9A5D0 mov eax, dword ptr fs:[00000030h] 7_2_06F9A5D0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F9E5CF mov eax, dword ptr fs:[00000030h] 7_2_06F9E5CF
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F9E5CF mov eax, dword ptr fs:[00000030h] 7_2_06F9E5CF
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F845B1 mov eax, dword ptr fs:[00000030h] 7_2_06F845B1
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F845B1 mov eax, dword ptr fs:[00000030h] 7_2_06F845B1
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_0701A456 mov eax, dword ptr fs:[00000030h] 7_2_0701A456
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FE05A7 mov eax, dword ptr fs:[00000030h] 7_2_06FE05A7
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FE05A7 mov eax, dword ptr fs:[00000030h] 7_2_06FE05A7
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FE05A7 mov eax, dword ptr fs:[00000030h] 7_2_06FE05A7
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F9E59C mov eax, dword ptr fs:[00000030h] 7_2_06F9E59C
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F94588 mov eax, dword ptr fs:[00000030h] 7_2_06F94588
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F62582 mov eax, dword ptr fs:[00000030h] 7_2_06F62582
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F62582 mov ecx, dword ptr fs:[00000030h] 7_2_06F62582
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F9656A mov eax, dword ptr fs:[00000030h] 7_2_06F9656A
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F9656A mov eax, dword ptr fs:[00000030h] 7_2_06F9656A
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F9656A mov eax, dword ptr fs:[00000030h] 7_2_06F9656A
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_0701A49A mov eax, dword ptr fs:[00000030h] 7_2_0701A49A
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F68550 mov eax, dword ptr fs:[00000030h] 7_2_06F68550
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F68550 mov eax, dword ptr fs:[00000030h] 7_2_06F68550
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F70535 mov eax, dword ptr fs:[00000030h] 7_2_06F70535
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F70535 mov eax, dword ptr fs:[00000030h] 7_2_06F70535
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F70535 mov eax, dword ptr fs:[00000030h] 7_2_06F70535
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F70535 mov eax, dword ptr fs:[00000030h] 7_2_06F70535
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F70535 mov eax, dword ptr fs:[00000030h] 7_2_06F70535
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F70535 mov eax, dword ptr fs:[00000030h] 7_2_06F70535
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F8E53E mov eax, dword ptr fs:[00000030h] 7_2_06F8E53E
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F8E53E mov eax, dword ptr fs:[00000030h] 7_2_06F8E53E
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F8E53E mov eax, dword ptr fs:[00000030h] 7_2_06F8E53E
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F8E53E mov eax, dword ptr fs:[00000030h] 7_2_06F8E53E
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F8E53E mov eax, dword ptr fs:[00000030h] 7_2_06F8E53E
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FF6500 mov eax, dword ptr fs:[00000030h] 7_2_06FF6500
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F702E1 mov eax, dword ptr fs:[00000030h] 7_2_06F702E1
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F702E1 mov eax, dword ptr fs:[00000030h] 7_2_06F702E1
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F702E1 mov eax, dword ptr fs:[00000030h] 7_2_06F702E1
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_07038324 mov eax, dword ptr fs:[00000030h] 7_2_07038324
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_07038324 mov ecx, dword ptr fs:[00000030h] 7_2_07038324
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_07038324 mov eax, dword ptr fs:[00000030h] 7_2_07038324
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_07038324 mov eax, dword ptr fs:[00000030h] 7_2_07038324
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F6A2C3 mov eax, dword ptr fs:[00000030h] 7_2_06F6A2C3
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F6A2C3 mov eax, dword ptr fs:[00000030h] 7_2_06F6A2C3
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F6A2C3 mov eax, dword ptr fs:[00000030h] 7_2_06F6A2C3
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F6A2C3 mov eax, dword ptr fs:[00000030h] 7_2_06F6A2C3
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F6A2C3 mov eax, dword ptr fs:[00000030h] 7_2_06F6A2C3
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_0703634F mov eax, dword ptr fs:[00000030h] 7_2_0703634F
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_0702A352 mov eax, dword ptr fs:[00000030h] 7_2_0702A352
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_07008350 mov ecx, dword ptr fs:[00000030h] 7_2_07008350
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FF62A0 mov eax, dword ptr fs:[00000030h] 7_2_06FF62A0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FF62A0 mov ecx, dword ptr fs:[00000030h] 7_2_06FF62A0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FF62A0 mov eax, dword ptr fs:[00000030h] 7_2_06FF62A0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FF62A0 mov eax, dword ptr fs:[00000030h] 7_2_06FF62A0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FF62A0 mov eax, dword ptr fs:[00000030h] 7_2_06FF62A0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FF62A0 mov eax, dword ptr fs:[00000030h] 7_2_06FF62A0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_0700437C mov eax, dword ptr fs:[00000030h] 7_2_0700437C
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FE0283 mov eax, dword ptr fs:[00000030h] 7_2_06FE0283
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FE0283 mov eax, dword ptr fs:[00000030h] 7_2_06FE0283
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FE0283 mov eax, dword ptr fs:[00000030h] 7_2_06FE0283
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F9E284 mov eax, dword ptr fs:[00000030h] 7_2_06F9E284
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F9E284 mov eax, dword ptr fs:[00000030h] 7_2_06F9E284
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F64260 mov eax, dword ptr fs:[00000030h] 7_2_06F64260
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F64260 mov eax, dword ptr fs:[00000030h] 7_2_06F64260
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F64260 mov eax, dword ptr fs:[00000030h] 7_2_06F64260
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F5826B mov eax, dword ptr fs:[00000030h] 7_2_06F5826B
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F5A250 mov eax, dword ptr fs:[00000030h] 7_2_06F5A250
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F66259 mov eax, dword ptr fs:[00000030h] 7_2_06F66259
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FE8243 mov eax, dword ptr fs:[00000030h] 7_2_06FE8243
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FE8243 mov ecx, dword ptr fs:[00000030h] 7_2_06FE8243
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_0701C3CD mov eax, dword ptr fs:[00000030h] 7_2_0701C3CD
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F5823B mov eax, dword ptr fs:[00000030h] 7_2_06F5823B
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_070043D4 mov eax, dword ptr fs:[00000030h] 7_2_070043D4
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_070043D4 mov eax, dword ptr fs:[00000030h] 7_2_070043D4
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_0700E3DB mov eax, dword ptr fs:[00000030h] 7_2_0700E3DB
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_0700E3DB mov eax, dword ptr fs:[00000030h] 7_2_0700E3DB
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_0700E3DB mov ecx, dword ptr fs:[00000030h] 7_2_0700E3DB
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_0700E3DB mov eax, dword ptr fs:[00000030h] 7_2_0700E3DB
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F963FF mov eax, dword ptr fs:[00000030h] 7_2_06F963FF
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F7E3F0 mov eax, dword ptr fs:[00000030h] 7_2_06F7E3F0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F7E3F0 mov eax, dword ptr fs:[00000030h] 7_2_06F7E3F0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F7E3F0 mov eax, dword ptr fs:[00000030h] 7_2_06F7E3F0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F703E9 mov eax, dword ptr fs:[00000030h] 7_2_06F703E9
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F703E9 mov eax, dword ptr fs:[00000030h] 7_2_06F703E9
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F703E9 mov eax, dword ptr fs:[00000030h] 7_2_06F703E9
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F703E9 mov eax, dword ptr fs:[00000030h] 7_2_06F703E9
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F703E9 mov eax, dword ptr fs:[00000030h] 7_2_06F703E9
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F703E9 mov eax, dword ptr fs:[00000030h] 7_2_06F703E9
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F703E9 mov eax, dword ptr fs:[00000030h] 7_2_06F703E9
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F703E9 mov eax, dword ptr fs:[00000030h] 7_2_06F703E9
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F683C0 mov eax, dword ptr fs:[00000030h] 7_2_06F683C0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F683C0 mov eax, dword ptr fs:[00000030h] 7_2_06F683C0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F683C0 mov eax, dword ptr fs:[00000030h] 7_2_06F683C0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F683C0 mov eax, dword ptr fs:[00000030h] 7_2_06F683C0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F6A3C0 mov eax, dword ptr fs:[00000030h] 7_2_06F6A3C0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F6A3C0 mov eax, dword ptr fs:[00000030h] 7_2_06F6A3C0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F6A3C0 mov eax, dword ptr fs:[00000030h] 7_2_06F6A3C0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F6A3C0 mov eax, dword ptr fs:[00000030h] 7_2_06F6A3C0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F6A3C0 mov eax, dword ptr fs:[00000030h] 7_2_06F6A3C0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F6A3C0 mov eax, dword ptr fs:[00000030h] 7_2_06F6A3C0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FE63C0 mov eax, dword ptr fs:[00000030h] 7_2_06FE63C0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_0701A250 mov eax, dword ptr fs:[00000030h] 7_2_0701A250
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_0701A250 mov eax, dword ptr fs:[00000030h] 7_2_0701A250
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_0703625D mov eax, dword ptr fs:[00000030h] 7_2_0703625D
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F58397 mov eax, dword ptr fs:[00000030h] 7_2_06F58397
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F58397 mov eax, dword ptr fs:[00000030h] 7_2_06F58397
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F58397 mov eax, dword ptr fs:[00000030h] 7_2_06F58397
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_07010274 mov eax, dword ptr fs:[00000030h] 7_2_07010274
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_07010274 mov eax, dword ptr fs:[00000030h] 7_2_07010274
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_07010274 mov eax, dword ptr fs:[00000030h] 7_2_07010274
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_07010274 mov eax, dword ptr fs:[00000030h] 7_2_07010274
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_07010274 mov eax, dword ptr fs:[00000030h] 7_2_07010274
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_07010274 mov eax, dword ptr fs:[00000030h] 7_2_07010274
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_07010274 mov eax, dword ptr fs:[00000030h] 7_2_07010274
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_07010274 mov eax, dword ptr fs:[00000030h] 7_2_07010274
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_07010274 mov eax, dword ptr fs:[00000030h] 7_2_07010274
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_07010274 mov eax, dword ptr fs:[00000030h] 7_2_07010274
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_07010274 mov eax, dword ptr fs:[00000030h] 7_2_07010274
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_07010274 mov eax, dword ptr fs:[00000030h] 7_2_07010274
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F8438F mov eax, dword ptr fs:[00000030h] 7_2_06F8438F
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F8438F mov eax, dword ptr fs:[00000030h] 7_2_06F8438F
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F5E388 mov eax, dword ptr fs:[00000030h] 7_2_06F5E388
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F5E388 mov eax, dword ptr fs:[00000030h] 7_2_06F5E388
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F5E388 mov eax, dword ptr fs:[00000030h] 7_2_06F5E388
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FE035C mov eax, dword ptr fs:[00000030h] 7_2_06FE035C
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FE035C mov eax, dword ptr fs:[00000030h] 7_2_06FE035C
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FE035C mov eax, dword ptr fs:[00000030h] 7_2_06FE035C
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FE035C mov ecx, dword ptr fs:[00000030h] 7_2_06FE035C
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FE035C mov eax, dword ptr fs:[00000030h] 7_2_06FE035C
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FE035C mov eax, dword ptr fs:[00000030h] 7_2_06FE035C
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FE2349 mov eax, dword ptr fs:[00000030h] 7_2_06FE2349
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FE2349 mov eax, dword ptr fs:[00000030h] 7_2_06FE2349
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FE2349 mov eax, dword ptr fs:[00000030h] 7_2_06FE2349
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FE2349 mov eax, dword ptr fs:[00000030h] 7_2_06FE2349
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FE2349 mov eax, dword ptr fs:[00000030h] 7_2_06FE2349
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FE2349 mov eax, dword ptr fs:[00000030h] 7_2_06FE2349
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FE2349 mov eax, dword ptr fs:[00000030h] 7_2_06FE2349
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FE2349 mov eax, dword ptr fs:[00000030h] 7_2_06FE2349
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FE2349 mov eax, dword ptr fs:[00000030h] 7_2_06FE2349
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FE2349 mov eax, dword ptr fs:[00000030h] 7_2_06FE2349
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FE2349 mov eax, dword ptr fs:[00000030h] 7_2_06FE2349
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FE2349 mov eax, dword ptr fs:[00000030h] 7_2_06FE2349
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FE2349 mov eax, dword ptr fs:[00000030h] 7_2_06FE2349
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FE2349 mov eax, dword ptr fs:[00000030h] 7_2_06FE2349
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FE2349 mov eax, dword ptr fs:[00000030h] 7_2_06FE2349
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_070362D6 mov eax, dword ptr fs:[00000030h] 7_2_070362D6
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F5C310 mov ecx, dword ptr fs:[00000030h] 7_2_06F5C310
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F80310 mov ecx, dword ptr fs:[00000030h] 7_2_06F80310
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F9A30B mov eax, dword ptr fs:[00000030h] 7_2_06F9A30B
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F9A30B mov eax, dword ptr fs:[00000030h] 7_2_06F9A30B
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F9A30B mov eax, dword ptr fs:[00000030h] 7_2_06F9A30B
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F5C0F0 mov eax, dword ptr fs:[00000030h] 7_2_06F5C0F0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FA20F0 mov ecx, dword ptr fs:[00000030h] 7_2_06FA20F0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_0700E10E mov eax, dword ptr fs:[00000030h] 7_2_0700E10E
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_0700E10E mov ecx, dword ptr fs:[00000030h] 7_2_0700E10E
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_0700E10E mov eax, dword ptr fs:[00000030h] 7_2_0700E10E
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_0700E10E mov eax, dword ptr fs:[00000030h] 7_2_0700E10E
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_0700E10E mov ecx, dword ptr fs:[00000030h] 7_2_0700E10E
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_0700E10E mov eax, dword ptr fs:[00000030h] 7_2_0700E10E
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_0700E10E mov eax, dword ptr fs:[00000030h] 7_2_0700E10E
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_0700E10E mov ecx, dword ptr fs:[00000030h] 7_2_0700E10E
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_0700E10E mov eax, dword ptr fs:[00000030h] 7_2_0700E10E
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_0700E10E mov ecx, dword ptr fs:[00000030h] 7_2_0700E10E
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F5A0E3 mov ecx, dword ptr fs:[00000030h] 7_2_06F5A0E3
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_07020115 mov eax, dword ptr fs:[00000030h] 7_2_07020115
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_0700A118 mov ecx, dword ptr fs:[00000030h] 7_2_0700A118
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_0700A118 mov eax, dword ptr fs:[00000030h] 7_2_0700A118
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_0700A118 mov eax, dword ptr fs:[00000030h] 7_2_0700A118
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_0700A118 mov eax, dword ptr fs:[00000030h] 7_2_0700A118
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FE60E0 mov eax, dword ptr fs:[00000030h] 7_2_06FE60E0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F680E9 mov eax, dword ptr fs:[00000030h] 7_2_06F680E9
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FE20DE mov eax, dword ptr fs:[00000030h] 7_2_06FE20DE
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F580A0 mov eax, dword ptr fs:[00000030h] 7_2_06F580A0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FF80A8 mov eax, dword ptr fs:[00000030h] 7_2_06FF80A8
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_07034164 mov eax, dword ptr fs:[00000030h] 7_2_07034164
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_07034164 mov eax, dword ptr fs:[00000030h] 7_2_07034164
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F6208A mov eax, dword ptr fs:[00000030h] 7_2_06F6208A
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_07004180 mov eax, dword ptr fs:[00000030h] 7_2_07004180
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_07004180 mov eax, dword ptr fs:[00000030h] 7_2_07004180
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_0701C188 mov eax, dword ptr fs:[00000030h] 7_2_0701C188
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_0701C188 mov eax, dword ptr fs:[00000030h] 7_2_0701C188
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F8C073 mov eax, dword ptr fs:[00000030h] 7_2_06F8C073
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F62050 mov eax, dword ptr fs:[00000030h] 7_2_06F62050
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FE6050 mov eax, dword ptr fs:[00000030h] 7_2_06FE6050
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_070261C3 mov eax, dword ptr fs:[00000030h] 7_2_070261C3
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_070261C3 mov eax, dword ptr fs:[00000030h] 7_2_070261C3
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FF6030 mov eax, dword ptr fs:[00000030h] 7_2_06FF6030
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F5A020 mov eax, dword ptr fs:[00000030h] 7_2_06F5A020
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F5C020 mov eax, dword ptr fs:[00000030h] 7_2_06F5C020
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F7E016 mov eax, dword ptr fs:[00000030h] 7_2_06F7E016
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F7E016 mov eax, dword ptr fs:[00000030h] 7_2_06F7E016
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F7E016 mov eax, dword ptr fs:[00000030h] 7_2_06F7E016
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F7E016 mov eax, dword ptr fs:[00000030h] 7_2_06F7E016
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_070361E5 mov eax, dword ptr fs:[00000030h] 7_2_070361E5
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FE4000 mov ecx, dword ptr fs:[00000030h] 7_2_06FE4000
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_07002000 mov eax, dword ptr fs:[00000030h] 7_2_07002000
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_07002000 mov eax, dword ptr fs:[00000030h] 7_2_07002000
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_07002000 mov eax, dword ptr fs:[00000030h] 7_2_07002000
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_07002000 mov eax, dword ptr fs:[00000030h] 7_2_07002000
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_07002000 mov eax, dword ptr fs:[00000030h] 7_2_07002000
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_07002000 mov eax, dword ptr fs:[00000030h] 7_2_07002000
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_07002000 mov eax, dword ptr fs:[00000030h] 7_2_07002000
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_07002000 mov eax, dword ptr fs:[00000030h] 7_2_07002000
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F901F8 mov eax, dword ptr fs:[00000030h] 7_2_06F901F8
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FDE1D0 mov eax, dword ptr fs:[00000030h] 7_2_06FDE1D0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FDE1D0 mov eax, dword ptr fs:[00000030h] 7_2_06FDE1D0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FDE1D0 mov ecx, dword ptr fs:[00000030h] 7_2_06FDE1D0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FDE1D0 mov eax, dword ptr fs:[00000030h] 7_2_06FDE1D0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FDE1D0 mov eax, dword ptr fs:[00000030h] 7_2_06FDE1D0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FE019F mov eax, dword ptr fs:[00000030h] 7_2_06FE019F
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FE019F mov eax, dword ptr fs:[00000030h] 7_2_06FE019F
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FE019F mov eax, dword ptr fs:[00000030h] 7_2_06FE019F
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FE019F mov eax, dword ptr fs:[00000030h] 7_2_06FE019F
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F5A197 mov eax, dword ptr fs:[00000030h] 7_2_06F5A197
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F5A197 mov eax, dword ptr fs:[00000030h] 7_2_06F5A197
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F5A197 mov eax, dword ptr fs:[00000030h] 7_2_06F5A197
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FA0185 mov eax, dword ptr fs:[00000030h] 7_2_06FA0185
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F66154 mov eax, dword ptr fs:[00000030h] 7_2_06F66154
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F66154 mov eax, dword ptr fs:[00000030h] 7_2_06F66154
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F5C156 mov eax, dword ptr fs:[00000030h] 7_2_06F5C156
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FF8158 mov eax, dword ptr fs:[00000030h] 7_2_06FF8158
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_070260B8 mov eax, dword ptr fs:[00000030h] 7_2_070260B8
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_070260B8 mov ecx, dword ptr fs:[00000030h] 7_2_070260B8
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FF4144 mov eax, dword ptr fs:[00000030h] 7_2_06FF4144
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FF4144 mov eax, dword ptr fs:[00000030h] 7_2_06FF4144
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FF4144 mov ecx, dword ptr fs:[00000030h] 7_2_06FF4144
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FF4144 mov eax, dword ptr fs:[00000030h] 7_2_06FF4144
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FF4144 mov eax, dword ptr fs:[00000030h] 7_2_06FF4144
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F90124 mov eax, dword ptr fs:[00000030h] 7_2_06F90124
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_07016F00 mov eax, dword ptr fs:[00000030h] 7_2_07016F00
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F98EF5 mov eax, dword ptr fs:[00000030h] 7_2_06F98EF5
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F66EE0 mov eax, dword ptr fs:[00000030h] 7_2_06F66EE0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F66EE0 mov eax, dword ptr fs:[00000030h] 7_2_06F66EE0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F66EE0 mov eax, dword ptr fs:[00000030h] 7_2_06F66EE0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F66EE0 mov eax, dword ptr fs:[00000030h] 7_2_06F66EE0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_07004F42 mov eax, dword ptr fs:[00000030h] 7_2_07004F42
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FFAEB0 mov eax, dword ptr fs:[00000030h] 7_2_06FFAEB0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FFAEB0 mov eax, dword ptr fs:[00000030h] 7_2_06FFAEB0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_07000F50 mov eax, dword ptr fs:[00000030h] 7_2_07000F50
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FECEA0 mov eax, dword ptr fs:[00000030h] 7_2_06FECEA0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FECEA0 mov eax, dword ptr fs:[00000030h] 7_2_06FECEA0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FECEA0 mov eax, dword ptr fs:[00000030h] 7_2_06FECEA0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_07002F60 mov eax, dword ptr fs:[00000030h] 7_2_07002F60
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_07002F60 mov eax, dword ptr fs:[00000030h] 7_2_07002F60
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F92E9C mov eax, dword ptr fs:[00000030h] 7_2_06F92E9C
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F92E9C mov ecx, dword ptr fs:[00000030h] 7_2_06F92E9C
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F5AE90 mov eax, dword ptr fs:[00000030h] 7_2_06F5AE90
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F5AE90 mov eax, dword ptr fs:[00000030h] 7_2_06F5AE90
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F5AE90 mov eax, dword ptr fs:[00000030h] 7_2_06F5AE90
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_07034F68 mov eax, dword ptr fs:[00000030h] 7_2_07034F68
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FE0E7F mov eax, dword ptr fs:[00000030h] 7_2_06FE0E7F
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FE0E7F mov eax, dword ptr fs:[00000030h] 7_2_06FE0E7F
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FE0E7F mov eax, dword ptr fs:[00000030h] 7_2_06FE0E7F
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F66E71 mov eax, dword ptr fs:[00000030h] 7_2_06F66E71
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F5EE5A mov eax, dword ptr fs:[00000030h] 7_2_06F5EE5A
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FF6E20 mov eax, dword ptr fs:[00000030h] 7_2_06FF6E20
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FF6E20 mov eax, dword ptr fs:[00000030h] 7_2_06FF6E20
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FF6E20 mov ecx, dword ptr fs:[00000030h] 7_2_06FF6E20
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_07034FE7 mov eax, dword ptr fs:[00000030h] 7_2_07034FE7
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F58E1D mov eax, dword ptr fs:[00000030h] 7_2_06F58E1D
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_07016FF7 mov eax, dword ptr fs:[00000030h] 7_2_07016FF7
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F8AE00 mov eax, dword ptr fs:[00000030h] 7_2_06F8AE00
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F8AE00 mov eax, dword ptr fs:[00000030h] 7_2_06F8AE00
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F8AE00 mov eax, dword ptr fs:[00000030h] 7_2_06F8AE00
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F8AE00 mov ecx, dword ptr fs:[00000030h] 7_2_06F8AE00
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F8AE00 mov eax, dword ptr fs:[00000030h] 7_2_06F8AE00
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F8AE00 mov eax, dword ptr fs:[00000030h] 7_2_06F8AE00
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F8AE00 mov eax, dword ptr fs:[00000030h] 7_2_06F8AE00
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F8AE00 mov eax, dword ptr fs:[00000030h] 7_2_06F8AE00
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F8AE00 mov eax, dword ptr fs:[00000030h] 7_2_06F8AE00
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F8AE00 mov eax, dword ptr fs:[00000030h] 7_2_06F8AE00
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FA0FF6 mov eax, dword ptr fs:[00000030h] 7_2_06FA0FF6
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FA0FF6 mov eax, dword ptr fs:[00000030h] 7_2_06FA0FF6
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FA0FF6 mov eax, dword ptr fs:[00000030h] 7_2_06FA0FF6
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FA0FF6 mov eax, dword ptr fs:[00000030h] 7_2_06FA0FF6
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F7CFE0 mov eax, dword ptr fs:[00000030h] 7_2_06F7CFE0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F7CFE0 mov eax, dword ptr fs:[00000030h] 7_2_06F7CFE0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F5EFD8 mov eax, dword ptr fs:[00000030h] 7_2_06F5EFD8
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F5EFD8 mov eax, dword ptr fs:[00000030h] 7_2_06F5EFD8
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F5EFD8 mov eax, dword ptr fs:[00000030h] 7_2_06F5EFD8
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F62FC8 mov eax, dword ptr fs:[00000030h] 7_2_06F62FC8
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F62FC8 mov eax, dword ptr fs:[00000030h] 7_2_06F62FC8
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F62FC8 mov eax, dword ptr fs:[00000030h] 7_2_06F62FC8
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F62FC8 mov eax, dword ptr fs:[00000030h] 7_2_06F62FC8
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_07032E4F mov eax, dword ptr fs:[00000030h] 7_2_07032E4F
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_07032E4F mov eax, dword ptr fs:[00000030h] 7_2_07032E4F
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F92F98 mov eax, dword ptr fs:[00000030h] 7_2_06F92F98
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F92F98 mov eax, dword ptr fs:[00000030h] 7_2_06F92F98
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F9CF80 mov eax, dword ptr fs:[00000030h] 7_2_06F9CF80
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F8AF69 mov eax, dword ptr fs:[00000030h] 7_2_06F8AF69
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F8AF69 mov eax, dword ptr fs:[00000030h] 7_2_06F8AF69
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F5CF50 mov eax, dword ptr fs:[00000030h] 7_2_06F5CF50
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F5CF50 mov eax, dword ptr fs:[00000030h] 7_2_06F5CF50
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F5CF50 mov eax, dword ptr fs:[00000030h] 7_2_06F5CF50
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F5CF50 mov eax, dword ptr fs:[00000030h] 7_2_06F5CF50
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F5CF50 mov eax, dword ptr fs:[00000030h] 7_2_06F5CF50
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F5CF50 mov eax, dword ptr fs:[00000030h] 7_2_06F5CF50
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F9CF50 mov eax, dword ptr fs:[00000030h] 7_2_06F9CF50
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FE4F40 mov eax, dword ptr fs:[00000030h] 7_2_06FE4F40
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FE4F40 mov eax, dword ptr fs:[00000030h] 7_2_06FE4F40
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FE4F40 mov eax, dword ptr fs:[00000030h] 7_2_06FE4F40
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FE4F40 mov eax, dword ptr fs:[00000030h] 7_2_06FE4F40
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F8EF28 mov eax, dword ptr fs:[00000030h] 7_2_06F8EF28
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_07016ED0 mov ecx, dword ptr fs:[00000030h] 7_2_07016ED0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F62F12 mov eax, dword ptr fs:[00000030h] 7_2_06F62F12
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F9CF1F mov eax, dword ptr fs:[00000030h] 7_2_06F9CF1F
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F92CF0 mov eax, dword ptr fs:[00000030h] 7_2_06F92CF0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F92CF0 mov eax, dword ptr fs:[00000030h] 7_2_06F92CF0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F92CF0 mov eax, dword ptr fs:[00000030h] 7_2_06F92CF0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F92CF0 mov eax, dword ptr fs:[00000030h] 7_2_06F92CF0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_07018D10 mov eax, dword ptr fs:[00000030h] 7_2_07018D10
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_07018D10 mov eax, dword ptr fs:[00000030h] 7_2_07018D10
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F58CD0 mov eax, dword ptr fs:[00000030h] 7_2_06F58CD0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_07034D30 mov eax, dword ptr fs:[00000030h] 7_2_07034D30
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F5CCC8 mov eax, dword ptr fs:[00000030h] 7_2_06F5CCC8
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F88CB1 mov eax, dword ptr fs:[00000030h] 7_2_06F88CB1
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F88CB1 mov eax, dword ptr fs:[00000030h] 7_2_06F88CB1
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FDCCA0 mov ecx, dword ptr fs:[00000030h] 7_2_06FDCCA0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FDCCA0 mov eax, dword ptr fs:[00000030h] 7_2_06FDCCA0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FDCCA0 mov eax, dword ptr fs:[00000030h] 7_2_06FDCCA0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FDCCA0 mov eax, dword ptr fs:[00000030h] 7_2_06FDCCA0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F58C8D mov eax, dword ptr fs:[00000030h] 7_2_06F58C8D
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F94C59 mov eax, dword ptr fs:[00000030h] 7_2_06F94C59
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F6AC50 mov eax, dword ptr fs:[00000030h] 7_2_06F6AC50
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F6AC50 mov eax, dword ptr fs:[00000030h] 7_2_06F6AC50
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F6AC50 mov eax, dword ptr fs:[00000030h] 7_2_06F6AC50
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F6AC50 mov eax, dword ptr fs:[00000030h] 7_2_06F6AC50
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F6AC50 mov eax, dword ptr fs:[00000030h] 7_2_06F6AC50
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F6AC50 mov eax, dword ptr fs:[00000030h] 7_2_06F6AC50
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F66C50 mov eax, dword ptr fs:[00000030h] 7_2_06F66C50
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F66C50 mov eax, dword ptr fs:[00000030h] 7_2_06F66C50
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F66C50 mov eax, dword ptr fs:[00000030h] 7_2_06F66C50
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_07028DAE mov eax, dword ptr fs:[00000030h] 7_2_07028DAE
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_07028DAE mov eax, dword ptr fs:[00000030h] 7_2_07028DAE
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_07034DAD mov eax, dword ptr fs:[00000030h] 7_2_07034DAD
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F5EC20 mov eax, dword ptr fs:[00000030h] 7_2_06F5EC20
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FFCC20 mov eax, dword ptr fs:[00000030h] 7_2_06FFCC20
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FFCC20 mov eax, dword ptr fs:[00000030h] 7_2_06FFCC20
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_07000DF0 mov eax, dword ptr fs:[00000030h] 7_2_07000DF0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_07000DF0 mov eax, dword ptr fs:[00000030h] 7_2_07000DF0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FE4C0F mov eax, dword ptr fs:[00000030h] 7_2_06FE4C0F
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F70C00 mov eax, dword ptr fs:[00000030h] 7_2_06F70C00
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F70C00 mov eax, dword ptr fs:[00000030h] 7_2_06F70C00
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F70C00 mov eax, dword ptr fs:[00000030h] 7_2_06F70C00
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F70C00 mov eax, dword ptr fs:[00000030h] 7_2_06F70C00
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F9CC00 mov eax, dword ptr fs:[00000030h] 7_2_06F9CC00
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F56DF6 mov eax, dword ptr fs:[00000030h] 7_2_06F56DF6
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F8CDF0 mov eax, dword ptr fs:[00000030h] 7_2_06F8CDF0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F8CDF0 mov ecx, dword ptr fs:[00000030h] 7_2_06F8CDF0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F6ADE0 mov eax, dword ptr fs:[00000030h] 7_2_06F6ADE0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F6ADE0 mov eax, dword ptr fs:[00000030h] 7_2_06F6ADE0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F6ADE0 mov eax, dword ptr fs:[00000030h] 7_2_06F6ADE0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F6ADE0 mov eax, dword ptr fs:[00000030h] 7_2_06F6ADE0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F6ADE0 mov eax, dword ptr fs:[00000030h] 7_2_06F6ADE0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F6ADE0 mov eax, dword ptr fs:[00000030h] 7_2_06F6ADE0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F80DE1 mov eax, dword ptr fs:[00000030h] 7_2_06F80DE1
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F5CDEA mov eax, dword ptr fs:[00000030h] 7_2_06F5CDEA
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F5CDEA mov eax, dword ptr fs:[00000030h] 7_2_06F5CDEA
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FE4DD7 mov eax, dword ptr fs:[00000030h] 7_2_06FE4DD7
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FE4DD7 mov eax, dword ptr fs:[00000030h] 7_2_06FE4DD7
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F8EDD3 mov eax, dword ptr fs:[00000030h] 7_2_06F8EDD3
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F8EDD3 mov eax, dword ptr fs:[00000030h] 7_2_06F8EDD3
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_07004C34 mov eax, dword ptr fs:[00000030h] 7_2_07004C34
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_07004C34 mov eax, dword ptr fs:[00000030h] 7_2_07004C34
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_07004C34 mov eax, dword ptr fs:[00000030h] 7_2_07004C34
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_07004C34 mov eax, dword ptr fs:[00000030h] 7_2_07004C34
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_07004C34 mov eax, dword ptr fs:[00000030h] 7_2_07004C34
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_07004C34 mov eax, dword ptr fs:[00000030h] 7_2_07004C34
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_07004C34 mov ecx, dword ptr fs:[00000030h] 7_2_07004C34
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F88DBF mov eax, dword ptr fs:[00000030h] 7_2_06F88DBF
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F88DBF mov eax, dword ptr fs:[00000030h] 7_2_06F88DBF
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F9CDB1 mov ecx, dword ptr fs:[00000030h] 7_2_06F9CDB1
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F9CDB1 mov eax, dword ptr fs:[00000030h] 7_2_06F9CDB1
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F9CDB1 mov eax, dword ptr fs:[00000030h] 7_2_06F9CDB1
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F96DA0 mov eax, dword ptr fs:[00000030h] 7_2_06F96DA0
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06FF8D6B mov eax, dword ptr fs:[00000030h] 7_2_06FF8D6B
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F60D59 mov eax, dword ptr fs:[00000030h] 7_2_06F60D59
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F60D59 mov eax, dword ptr fs:[00000030h] 7_2_06F60D59
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_06F60D59 mov eax, dword ptr fs:[00000030h] 7_2_06F60D59
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process token adjusted: Debug Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_004469B8 IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess, 7_2_004469B8
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_0044846B _memset,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, 7_2_0044846B
Source: C:\Users\user\Desktop\Cotizaci#U00f3n#12643283.exe Memory allocated: page read and write | page guard Jump to behavior

HIPS / PFW / Operating System Protection Evasion

barindex
Source: C:\Users\user\Desktop\Cotizaci#U00f3n#12643283.exe Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath "C:\Users\user\AppData\Roaming\SoEOsZIV.exe"
Source: C:\Users\user\Desktop\Cotizaci#U00f3n#12643283.exe Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath "C:\Users\user\AppData\Roaming\SoEOsZIV.exe" Jump to behavior
Source: C:\Users\user\Desktop\Cotizaci#U00f3n#12643283.exe Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath "C:\Users\user\AppData\Roaming\SoEOsZIV.exe" Jump to behavior
Source: C:\Users\user\Desktop\Cotizaci#U00f3n#12643283.exe Process created: C:\Windows\SysWOW64\schtasks.exe "C:\Windows\System32\schtasks.exe" /Create /TN "Updates\SoEOsZIV" /XML "C:\Users\user\AppData\Local\Temp\tmpAC01.tmp" Jump to behavior
Source: C:\Users\user\Desktop\Cotizaci#U00f3n#12643283.exe Process created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe" Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Process created: C:\Windows\SysWOW64\schtasks.exe "C:\Windows\System32\schtasks.exe" /Create /TN "Updates\SoEOsZIV" /XML "C:\Users\user\AppData\Local\Temp\tmpBE22.tmp" Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Process created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe" Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Process created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe" Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Process created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe" Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Process created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe" Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Process created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe" Jump to behavior
Source: C:\Users\user\Desktop\Cotizaci#U00f3n#12643283.exe Queries volume information: C:\Users\user\Desktop\Cotizaci#U00f3n#12643283.exe VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cotizaci#U00f3n#12643283.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cotizaci#U00f3n#12643283.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cotizaci#U00f3n#12643283.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cotizaci#U00f3n#12643283.exe Queries volume information: C:\Windows\Fonts\micross.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\Cotizaci#U00f3n#12643283.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-GroupPolicy-ClientTools-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\Microsoft.Management.Infrastructure.Native\v4.0_1.0.0.0__31bf3856ad364e35\Microsoft.Management.Infrastructure.Native.dll VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\AppvClient\Microsoft.AppV.AppVClientPowerShell.dll VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1865.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-WOW64-Package~31bf3856ad364e35~amd64~en-GB~10.0.19041.1.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\BitLocker\Microsoft.BitLocker.Structures.dll VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management\v4.0_3.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Management.dll VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Queries volume information: C:\Users\user\AppData\Roaming\SoEOsZIV.exe VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Roaming\SoEOsZIV.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe Code function: 7_2_00447F9F GetSystemTimeAsFileTime,GetCurrentProcessId,GetCurrentThreadId,GetTickCount,QueryPerformanceCounter, 7_2_00447F9F
Source: C:\Users\user\Desktop\Cotizaci#U00f3n#12643283.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuid Jump to behavior

Stealing of Sensitive Information

barindex
Source: Yara match File source: 7.2.vbc.exe.400000.0.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 7.2.vbc.exe.400000.0.unpack, type: UNPACKEDPE
Source: Yara match File source: 00000007.00000002.2862181424.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000007.00000002.2862655444.0000000000E50000.00000004.00001000.00020000.00000000.sdmp, type: MEMORY

Remote Access Functionality

barindex
Source: Yara match File source: 7.2.vbc.exe.400000.0.raw.unpack, type: UNPACKEDPE
Source: Yara match File source: 7.2.vbc.exe.400000.0.unpack, type: UNPACKEDPE
Source: Yara match File source: 00000007.00000002.2862181424.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000007.00000002.2862655444.0000000000E50000.00000004.00001000.00020000.00000000.sdmp, type: MEMORY
No contacted IP infos