Source: | Binary string: D:\a\_work\e\src\out\Release_x64\pwahelper.exe.pdb source: pwahelper.exe1.10.dr, pwahelper.exe0.10.dr, pwahelper.exe.10.dr |
Source: | Binary string: c:\jenkins\workspace\8-2-build-windows-i586-cygwin-sans-NAS\jdk8u381\237\build\windows-i586\deploy\tmp\jp2launcher\obj\jp2launcher.pdb@@4 source: jp2launcher.exe.10.dr |
Source: | Binary string: NisSrv.pdb source: NisSrv.exe0.10.dr |
Source: | Binary string: D:\dbs\el\omr\Target\x86\ship\postc2rcross\x-none\appsharinghookcontroller.pdb source: AppSharingHookController.exe.10.dr |
Source: | Binary string: D:\dbs\el\omr\Target\x86\ship\postc2r\x-none\selfcert.pdb source: SELFCERT.EXE.10.dr |
Source: | Binary string: \??\C:\Windows\dll\mscorlib.pdb source: iKHPXKiqI.exe, 0000000B.00000002.2334957405.0000000007B0E000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: WmQc.pdbs\WmQc.pdbpdbmQc.pdbg\WmQc.pdb source: iKHPXKiqI.exe, 0000000B.00000002.2317304776.0000000000DD7000.00000004.00000010.00020000.00000000.sdmp |
Source: | Binary string: HP^o(C:\Windows\WmQc.pdb source: iKHPXKiqI.exe, 0000000B.00000002.2317304776.0000000000DD7000.00000004.00000010.00020000.00000000.sdmp |
Source: | Binary string: D:\dbs\el\ja2\Target\x86\ship\dcf\x-none\SpreadsheetCompare.pdb source: SPREADSHEETCOMPARE.EXE.10.dr |
Source: | Binary string: d:\dbs\el\ja2\target\x86\ship\delivery\x-none\ose.pdb000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000S source: OSE.EXE.10.dr |
Source: | Binary string: D:\dbs\el\omr\Target\x86\ship\postc2r\x-none\officeappguardwin32.pdb source: officeappguardwin32.exe.10.dr |
Source: | Binary string: \??\C:\Windows\exe\WmQc.pdb source: iKHPXKiqI.exe, 0000000B.00000002.2334957405.0000000007AF5000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: D:\a\_work\e\src\out\Release_x64\setup.exe.pdbOGP source: setup.exe.10.dr |
Source: | Binary string: C:\Windows\WmQc.pdbpdbmQc.pdb source: iKHPXKiqI.exe, 0000000B.00000002.2334957405.0000000007B0E000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: !!.pdb source: iKHPXKiqI.exe, 0000000B.00000002.2317304776.0000000000DD7000.00000004.00000010.00020000.00000000.sdmp |
Source: | Binary string: WmQc.pdb^1w^ source: iKHPXKiqI.exe, 0000000B.00000002.2317304776.0000000000DD7000.00000004.00000010.00020000.00000000.sdmp |
Source: | Binary string: d:\dbs\el\omr\target\x86\ship\graphics_filterloader\x-none\FLTLDR.pdb source: FLTLDR.EXE.10.dr |
Source: | Binary string: D:\dbs\el\omr\Target\x86\ship\postc2r\x-none\namecontrolserver.pdb source: NAMECONTROLSERVER.EXE.10.dr |
Source: | Binary string: D:\dbs\el\omr\Target\x86\ship\postc2r\x-none\cnfnot32.pdb00000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000S source: CNFNOT32.EXE.10.dr |
Source: | Binary string: WmQc.pdb21-2246122658-3693405117-2476756634-1003_Classes\WOW6432Node\CLSID\{0A29FF9E-7F9C-4437-8B11-F424491E3931}\InprocServer32EW source: iKHPXKiqI.exe, 0000000B.00000002.2334957405.0000000007B0E000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Windows\System.pdbE source: iKHPXKiqI.exe, 0000000B.00000002.2334957405.0000000007AF5000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: @jo.pdb source: iKHPXKiqI.exe, 0000000B.00000002.2317304776.0000000000DD7000.00000004.00000010.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System\v4.0_4.0.0.0__b77a5c561934e089\System.pdb} source: iKHPXKiqI.exe, 0000000B.00000002.2318435074.0000000001373000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: ker.pdb source: OfficeScrBroker.exe.10.dr |
Source: | Binary string: C:\Data\svn\autoit\branch_3.3.16\bin\Aut2Exe\Aut2Exe.pdb source: Aut2exe.exe.10.dr |
Source: | Binary string: C:\Windows\mscorlib.pdbpdblib.pdbZ source: iKHPXKiqI.exe, 0000000B.00000002.2334957405.0000000007B0E000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: R:\JoeSecurity\trunk\src\windows\usermode\tools\FakeChrome\Release\Chrome.pdb source: chrome.exe.10.dr |
Source: | Binary string: WmQc.pdbSHA256 source: iKHPXKiqI.exe, 0000000B.00000002.2318435074.0000000001405000.00000004.00000020.00020000.00000000.sdmp, Plat#U0103 revizuit#U0103_shrunk.exe |
Source: | Binary string: symbols\exe\WmQc.pdbjo source: iKHPXKiqI.exe, 0000000B.00000002.2317304776.0000000000DD7000.00000004.00000010.00020000.00000000.sdmp |
Source: | Binary string: C:\Users\user\AppData\Roaming\iKHPXKiqI.PDB source: iKHPXKiqI.exe, 0000000B.00000002.2317304776.0000000000DD7000.00000004.00000010.00020000.00000000.sdmp |
Source: | Binary string: r.pdb source: AppSharingHookController.exe.10.dr |
Source: | Binary string: D:\dbs\el\omr\Target\x86\ship\postc2r\x-none\ocpubmgr.pdb source: OcPubMgr.exe.10.dr |
Source: | Binary string: d:\dbs\el\ja2\target\x86\ship\dcf\x-none\FileCompare.pdb000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000S source: filecompare.exe.10.dr |
Source: | Binary string: \??\C:\Windows\mscorlib.pdb source: iKHPXKiqI.exe, 0000000B.00000002.2334957405.0000000007AF5000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: MsMpEng.pdbGCTL source: MsMpEng.exe0.10.dr, MsMpEng.exe.10.dr |
Source: | Binary string: c:\jenkins\workspace\8-2-build-windows-i586-cygwin-sans-NAS\jdk8u381\237\build\windows-i586\deploy\tmp\jp2launcher\obj\jp2launcher.pdb source: jp2launcher.exe.10.dr |
Source: | Binary string: ?joC:\Users\user\AppData\Roaming\WmQc.pdb source: iKHPXKiqI.exe, 0000000B.00000002.2317304776.0000000000DD7000.00000004.00000010.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Windows\exe\WmQc.pdbe source: iKHPXKiqI.exe, 0000000B.00000002.2334957405.0000000007AF5000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: D:\dbs\el\omr\Target\x86\ship\postc2r\x-none\officescrbroker.pdbker.pdb00000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000S source: OfficeScrBroker.exe.10.dr |
Source: | Binary string: D:\dbs\el\omr\Target\x86\ship\postc2r\x-none\orgchart.pdb source: ORGCHART.EXE.10.dr |
Source: | Binary string: D:\a\_work\e\src\out\Release_x64\setup.exe.pdb source: setup.exe.10.dr |
Source: | Binary string: D:\dbs\el\omr\Target\x86\ship\postc2r\x-none\orgchart.pdb0000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000S source: ORGCHART.EXE.10.dr |
Source: | Binary string: \??\C:\Windows\symbols\dll\System.pdb source: iKHPXKiqI.exe, 0000000B.00000002.2334957405.0000000007B0E000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Windows\dll\mscorlib.pdbP source: iKHPXKiqI.exe, 0000000B.00000002.2334957405.0000000007B0E000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: d:\dbs\el\ja2\target\x86\ship\delivery\x-none\ose.pdb source: OSE.EXE.10.dr |
Source: | Binary string: D:\dbs\el\omr\Target\x86\ship\postc2r\x-none\selfcert.pdbT.pdb00000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000S source: SELFCERT.EXE.10.dr |
Source: | Binary string: MpCmdRun.pdbGCTL source: MpCmdRun.exe1.10.dr, MpCmdRun.exe0.10.dr, MpCmdRun.exe2.10.dr |
Source: | Binary string: \??\C:\Windows\WmQc.pdb source: iKHPXKiqI.exe, 0000000B.00000002.2334957405.0000000007B0E000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: D:\dbs\el\omr\Target\x86\ship\postc2r\x-none\cnfnot32.pdb source: CNFNOT32.EXE.10.dr |
Source: | Binary string: MpCmdRun.pdb source: MpCmdRun.exe1.10.dr, MpCmdRun.exe0.10.dr, MpCmdRun.exe2.10.dr |
Source: | Binary string: C:\Windows\System.pdbpdbtem.pdb.1D source: iKHPXKiqI.exe, 0000000B.00000002.2334957405.0000000007B0E000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Windows\Microsoft.Net\assembly\GAC_32\mscorlib\v4.0_4.0.0.0__b77a5c561934e089\mscorlib.pdb source: iKHPXKiqI.exe, 0000000B.00000002.2334957405.0000000007AD0000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: D:\dbs\el\omr\Target\x86\ship\postc2r\x-none\perfboost.pdb source: PerfBoost.exe.10.dr |
Source: | Binary string: MicrosoftEdgeUpdateCore_unsigned.pdbd source: MicrosoftEdgeUpdateCore.exe.10.dr |
Source: | Binary string: D:\dbs\el\omr\Target\x86\ship\postc2r\x-none\ocpubmgr.pdb00000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000S source: OcPubMgr.exe.10.dr |
Source: | Binary string: \??\C:\Users\user\AppData\Roaming\iKHPXKiqI.PDB source: iKHPXKiqI.exe, 0000000B.00000002.2334957405.0000000007AD0000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: D:\a\_work\1\s\src\ai\windows\dll\Win32\Release\ai.exe.pdb source: ai.exe0.10.dr |
Source: | Binary string: D:\dbs\el\omr\Target\x86\ship\postc2r\x-none\scanpst.pdb000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000S source: SCANPST.EXE.10.dr |
Source: | Binary string: d:\dbs\el\omr\target\x86\ship\graphics_filterloader\x-none\FLTLDR.pdb00000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000S source: FLTLDR.EXE.10.dr |
Source: | Binary string: D:\dbs\el\omr\Target\x86\ship\postc2rcross\x-none\appsharinghookcontroller.pdbr.pdb00000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000S source: AppSharingHookController.exe.10.dr |
Source: | Binary string: T.pdb source: SELFCERT.EXE.10.dr |
Source: | Binary string: in32.pdb source: officeappguardwin32.exe.10.dr |
Source: | Binary string: D:\a\_work\e\src\out\Release_x64\pwahelper.exe.pdbOGP source: pwahelper.exe1.10.dr, pwahelper.exe0.10.dr, pwahelper.exe.10.dr |
Source: | Binary string: WmQc.pdb source: iKHPXKiqI.exe, 0000000B.00000002.2334957405.0000000007B0E000.00000004.00000020.00020000.00000000.sdmp, iKHPXKiqI.exe, 0000000B.00000002.2318435074.0000000001405000.00000004.00000020.00020000.00000000.sdmp, iKHPXKiqI.exe, 0000000B.00000002.2317304776.0000000000DD7000.00000004.00000010.00020000.00000000.sdmp, Plat#U0103 revizuit#U0103_shrunk.exe |
Source: | Binary string: \??\C:\Windows\dll\System.pdb source: iKHPXKiqI.exe, 0000000B.00000002.2334957405.0000000007B0E000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Windows\symbols\exe\WmQc.pdbj source: iKHPXKiqI.exe, 0000000B.00000002.2334957405.0000000007B0E000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Windows\symbols\dll\mscorlib.pdb source: iKHPXKiqI.exe, 0000000B.00000002.2334957405.0000000007B0E000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: D:\dbs\el\omr\Target\x86\ship\postc2r\x-none\officescrbroker.pdb source: OfficeScrBroker.exe.10.dr |
Source: | Binary string: D:\dbs\el\omr\Target\x86\ship\postc2r\x-none\officeappguardwin32.pdbin32.pdb000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000S source: officeappguardwin32.exe.10.dr |
Source: | Binary string: MicrosoftEdgeUpdateCore_unsigned.pdb source: MicrosoftEdgeUpdateCore.exe.10.dr |
Source: | Binary string: NisSrv.pdbGCTL source: NisSrv.exe0.10.dr |
Source: | Binary string: \??\C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System\v4.0_4.0.0.0__b77a5c561934e089\System.pdb source: iKHPXKiqI.exe, 0000000B.00000002.2318435074.0000000001373000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: MsMpEng.pdb source: MsMpEng.exe0.10.dr, MsMpEng.exe.10.dr |
Source: | Binary string: D:\a\_work\1\s\src\ai\windows\dll\Win32\Release\ai.exe.pdb/ source: ai.exe0.10.dr |
Source: | Binary string: D:\dbs\el\omr\Target\x86\ship\postc2r\x-none\perfboost.pdbb00000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000S source: PerfBoost.exe.10.dr |
Source: | Binary string: D:\dbs\el\omr\Target\x86\ship\postc2r\x-none\namecontrolserver.pdbb000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000S source: NAMECONTROLSERVER.EXE.10.dr |
Source: | Binary string: \??\C:\Windows\symbols\exe\WmQc.pdb source: iKHPXKiqI.exe, 0000000B.00000002.2334957405.0000000007B0E000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: D:\dbs\el\omr\Target\x86\ship\postc2r\x-none\scanpst.pdb source: SCANPST.EXE.10.dr |
Source: | Binary string: d:\dbs\el\ja2\target\x86\ship\dcf\x-none\FileCompare.pdb source: filecompare.exe.10.dr |
Source: | Binary string: \??\C:\Users\user\AppData\Roaming\WmQc.pdb source: iKHPXKiqI.exe, 0000000B.00000002.2334957405.0000000007AF5000.00000004.00000020.00020000.00000000.sdmp |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\javaws.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\DCF\DATABASECOMPARE.EXE | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\BHO\ie_to_edge_stub.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\PerfBoost.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MsMpEng.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\X86\MpCmdRun.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesX64\Microsoft Office\Office16\MSOHTMED.EXE | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX86\Microsoft Shared\Office16\MSOXMLED.EXE | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft Office\Office16\OSPPREARM.EXE | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpCopyAccelerator.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Common Files\Java\Java Update\jaureg.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\msedgewebview2.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\SETLANG.EXE | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_749031\javaw.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\msedge_pwa_launcher.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\lync99.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\ssvagent.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\DCF\filecompare.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\SELFCERT.EXE | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\SCANPST.EXE | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\xlicons.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MpCopyAccelerator.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\ConfigSecurityPolicy.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\msedge_proxy.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Common Files\Microsoft Shared\VSTO\10.0\VSTOInstaller.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\AutoIt3\AutoIt3Help.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.55\identity_helper.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Client\AppVDllSurrogate64.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\msoev.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\accicons.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\AutoIt3\Aut2Exe\Aut2exe.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\lyncicon.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Users\user\AppData\Local\Temp\chrome.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\IEContentService.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesX86\Microsoft Analysis Services\AS OLEDB\140\SQLDumper.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Client\AppVLP.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleUpdate.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleUpdateOnDemand.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\wordicon.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\DCF\SPREADSHEETCOMPARE.EXE | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\misc.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\javacpl.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\pwahelper.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleCrashHandler64.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MsMpEng.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\java.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\ConfigSecurityPolicy.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\AutoIt3\Au3Check.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\NisSrv.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleUpdateBroker.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\pj11icon.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\ACCICONS.EXE | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MpDefenderCoreService.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX86\Microsoft Shared\Office16\MSOICONS.EXE | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\misc.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesX64\Microsoft Office\Office16\AppSharingHookController64.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_749031\java.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\visicon.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeComRegisterShellARM64.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\msedge.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.55\elevation_service.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\joticon.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\CLVIEW.EXE | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\SkypeSrv\SKYPESERVER.EXE | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_749031\javaws.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Google\Update\Install\{EB80938B-EC00-4683-A2CC-456206E3A4E1}\117.0.5938.134_117.0.5938.132_chrome_updater.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\mpextms.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\NisSrv.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\XLICONS.EXE | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\AutoIt3\AutoIt3_x64.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Mozilla Maintenance Service\Uninstall.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\Installer\setup.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.55\msedge.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.55\cookie_exporter.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-001F-0409-0000-0000000FF1CE}\misc.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpDlpCmd.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\javaw.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleUpdateComRegisterShell64.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\DCF\Common.DBConnection64.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.55\Installer\setup.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\AutoIt3\Au3Info_x64.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleCrashHandler.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.55\BHO\ie_to_edge_stub.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\pptico.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\outicon.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\jp2launcher.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\dbcicons.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleUpdateCore.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE16\LICLUA.EXE | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\ORGCHART.EXE | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\SDXHelper.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\PPTICO.EXE | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\osmclienticon.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpCmdRun.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\WORDICON.EXE | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\AutoIt3\Aut2Exe\upx.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MpCmdRun.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARMHelper.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\unpack200.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\GRAPH.EXE | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\AutoIt3\Uninstall.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Google\Update\Download\{8A69D345-D564-463C-AFF1-A69D9E530F96}\117.0.5938.134\117.0.5938.134_117.0.5938.132_chrome_updater.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\sscicons.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\X86\MpCmdRun.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\DCF\Common.DBConnection.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\CNFNOT32.EXE | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\msoadfsb.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\pwahelper.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\AutoIt3\Au3Info.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\elevation_service.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\notification_helper.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\cookie_exporter.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\AutoIt3\Aut2Exe\Aut2exe_x64.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\mpextms.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\AppSharingHookController.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\Wordconv.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\ProgramData\Package Cache\{8bdfe669-9705-4184-9368-db9ce581e0e7}\VC_redist.x64.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MpDlpCmd.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\AutoIt3\SciTE\SciTE.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\ADDINS\Microsoft Power Query for Excel Integrated\bin\Microsoft.Mashup.Container.Loader.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\VPREVIEW.EXE | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX86\Microsoft Shared\Office16\OLicenseHeartbeat.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\integrator.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\OLCFG.EXE | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\grv_icons.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\msedge_proxy.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\identity_helper.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\pubs.exe | Jump to behavior |
Source: SELFCERT.EXE.10.dr | String found in binary or memory: http://%s/r/rlidVBASelfCert?clid=%d1.3.6.1.5.5.7.3.32.5.29.372.5.29.11.2.840.113549.1.1.5SelfSignedC |
Source: jp2launcher.exe.10.dr | String found in binary or memory: http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0E |
Source: jp2launcher.exe.10.dr | String found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crt0 |
Source: jp2launcher.exe.10.dr | String found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crt0 |
Source: jp2launcher.exe.10.dr | String found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedRootG4.crt0C |
Source: NisSrv.exe0.10.dr | String found in binary or memory: http://canonicalizer.ucsuri.tcs/68007400740070003a002f002f00https://F |
Source: Aut2exe.exe.10.dr, AutoIt3_x64.exe.10.dr | String found in binary or memory: http://crl.globalsign.com/ca/gstsacasha384g4.crl0 |
Source: Aut2exe.exe.10.dr, AutoIt3_x64.exe.10.dr | String found in binary or memory: http://crl.globalsign.com/gscodesignsha2g3.crl0 |
Source: Aut2exe.exe.10.dr, AutoIt3_x64.exe.10.dr | String found in binary or memory: http://crl.globalsign.com/root-r3.crl0G |
Source: Aut2exe.exe.10.dr, AutoIt3_x64.exe.10.dr | String found in binary or memory: http://crl.globalsign.com/root-r3.crl0c |
Source: Aut2exe.exe.10.dr, AutoIt3_x64.exe.10.dr | String found in binary or memory: http://crl.globalsign.com/root-r6.crl0G |
Source: jp2launcher.exe.10.dr | String found in binary or memory: http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0 |
Source: jp2launcher.exe.10.dr | String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0S |
Source: jp2launcher.exe.10.dr | String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crl0 |
Source: jp2launcher.exe.10.dr | String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedRootG4.crl0 |
Source: jp2launcher.exe.10.dr | String found in binary or memory: http://crl4.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0 |
Source: Plat#U0103 revizuit#U0103_shrunk.exe, 0000000A.00000002.2664741761.0000000001130000.00000004.00000010.00020000.00000000.sdmp | String found in binary or memory: http://nsis.sf.net/NSIS_ErrorError |
Source: jp2launcher.exe.10.dr | String found in binary or memory: http://ocsp.digicert.com0 |
Source: jp2launcher.exe.10.dr | String found in binary or memory: http://ocsp.digicert.com0A |
Source: jp2launcher.exe.10.dr | String found in binary or memory: http://ocsp.digicert.com0C |
Source: jp2launcher.exe.10.dr | String found in binary or memory: http://ocsp.digicert.com0X |
Source: Aut2exe.exe.10.dr, AutoIt3_x64.exe.10.dr | String found in binary or memory: http://ocsp.globalsign.com/ca/gstsacasha384g40C |
Source: Aut2exe.exe.10.dr, AutoIt3_x64.exe.10.dr | String found in binary or memory: http://ocsp2.globalsign.com/gscodesignsha2g30V |
Source: Aut2exe.exe.10.dr, AutoIt3_x64.exe.10.dr | String found in binary or memory: http://ocsp2.globalsign.com/rootr306 |
Source: Aut2exe.exe.10.dr, AutoIt3_x64.exe.10.dr | String found in binary or memory: http://ocsp2.globalsign.com/rootr606 |
Source: officeappguardwin32.exe.10.dr | String found in binary or memory: http://schemas.datacontract.org/2004/07/Microsoft.Office.Web.Roaming.Service |
Source: officeappguardwin32.exe.10.dr | String found in binary or memory: http://schemas.datacontract.org/2004/07/Microsoft.Office.Web.Roaming.SoapObjects |
Source: officeappguardwin32.exe.10.dr | String found in binary or memory: http://schemas.datacontract.org/2004/07/Microsoft.Office.Web.Roaming.SoapObjectsItemsSortKeyArrayOfR |
Source: Plat#U0103 revizuit#U0103_shrunk.exe, 00000000.00000002.2202989415.0000000002CA7000.00000004.00000800.00020000.00000000.sdmp, iKHPXKiqI.exe, 0000000B.00000002.2322866054.0000000003127000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name |
Source: Aut2exe.exe.10.dr, AutoIt3_x64.exe.10.dr | String found in binary or memory: http://secure.globalsign.com/cacert/gscodesignsha2g3ocsp.crt08 |
Source: Aut2exe.exe.10.dr, AutoIt3_x64.exe.10.dr | String found in binary or memory: http://secure.globalsign.com/cacert/gstsacasha384g4.crt0 |
Source: officeappguardwin32.exe.10.dr | String found in binary or memory: http://tempuri.org/ |
Source: SPREADSHEETCOMPARE.EXE.10.dr | String found in binary or memory: http://tempuri.org/DataSet1.xsd |
Source: officeappguardwin32.exe.10.dr | String found in binary or memory: http://tempuri.org/IRoamingSettingsService/DisableUser |
Source: officeappguardwin32.exe.10.dr | String found in binary or memory: http://tempuri.org/IRoamingSettingsService/DisableUserResponse |
Source: officeappguardwin32.exe.10.dr | String found in binary or memory: http://tempuri.org/IRoamingSettingsService/EnableUser |
Source: officeappguardwin32.exe.10.dr | String found in binary or memory: http://tempuri.org/IRoamingSettingsService/EnableUserResponse |
Source: officeappguardwin32.exe.10.dr | String found in binary or memory: http://tempuri.org/IRoamingSettingsService/GetConfig |
Source: officeappguardwin32.exe.10.dr | String found in binary or memory: http://tempuri.org/IRoamingSettingsService/GetConfigResponse |
Source: officeappguardwin32.exe.10.dr | String found in binary or memory: http://tempuri.org/IRoamingSettingsService/ReadSettings |
Source: officeappguardwin32.exe.10.dr | String found in binary or memory: http://tempuri.org/IRoamingSettingsService/ReadSettingsResponse |
Source: officeappguardwin32.exe.10.dr | String found in binary or memory: http://tempuri.org/IRoamingSettingsService/WriteSettings |
Source: officeappguardwin32.exe.10.dr | String found in binary or memory: http://tempuri.org/IRoamingSettingsService/WriteSettingsResponse |
Source: officeappguardwin32.exe.10.dr | String found in binary or memory: http://tempuri.org/IRoamingSettingsService/WriteSettingshttp://tempuri.org/IRoamingSettingsService/R |
Source: Aut2exe.exe.10.dr | String found in binary or memory: http://www.autoitscript.com/autoit3/ |
Source: Aut2exe.exe.10.dr | String found in binary or memory: http://www.autoitscript.com/autoit3/8 |
Source: AutoIt3_x64.exe.10.dr | String found in binary or memory: http://www.autoitscript.com/autoit3/J |
Source: jp2launcher.exe.10.dr | String found in binary or memory: http://www.digicert.com/CPS0 |
Source: OcPubMgr.exe.10.dr | String found in binary or memory: http://xml.org/sax/properties/lexical-handlerhttp://xml.org/sax/features/namespace-prefixeshttp://xm |
Source: Plat#U0103 revizuit#U0103_shrunk.exe, 00000000.00000002.2205988648.0000000003C49000.00000004.00000800.00020000.00000000.sdmp, Plat#U0103 revizuit#U0103_shrunk.exe, 00000000.00000002.2205988648.0000000003DDA000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://account.dyn.com/ |
Source: Plat#U0103 revizuit#U0103_shrunk.exe, 00000000.00000002.2205988648.0000000003C49000.00000004.00000800.00020000.00000000.sdmp, Plat#U0103 revizuit#U0103_shrunk.exe, 00000000.00000002.2205988648.0000000003DDA000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://api.telegram.org/bot7000875199:AAGcJDBHFcfVUBvhBO4xZLw34OXk1NWXSe0/ |
Source: pwahelper.exe1.10.dr, setup.exe.10.dr, pwahelper.exe0.10.dr, pwahelper.exe.10.dr | String found in binary or memory: https://github.com/pq-crystals/kyber/commit/28413dfbf523fdde181246451c2bd77199c0f7ff |
Source: pwahelper.exe1.10.dr, setup.exe.10.dr, pwahelper.exe0.10.dr, pwahelper.exe.10.dr | String found in binary or memory: https://github.com/pq-crystals/kyber/commit/28413dfbf523fdde181246451c2bd77199c0f7ffDilithium2Dilith |
Source: NisSrv.exe0.10.dr | String found in binary or memory: https://unitedstates1.ss.wd.microsoft.us/ |
Source: NisSrv.exe0.10.dr | String found in binary or memory: https://unitedstates2.ss.wd.microsoft.us/ |
Source: NisSrv.exe0.10.dr | String found in binary or memory: https://unitedstates4.ss.wd.microsoft.us/ |
Source: Aut2exe.exe.10.dr, AutoIt3_x64.exe.10.dr | String found in binary or memory: https://www.autoitscript.com/autoit3/ |
Source: Aut2exe.exe.10.dr, AutoIt3_x64.exe.10.dr | String found in binary or memory: https://www.globalsign.com/repository/0 |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Section loaded: dwrite.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Section loaded: windowscodecs.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Section loaded: edputil.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Section loaded: windows.staterepositoryps.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Section loaded: appresolver.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Section loaded: bcp47langs.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Section loaded: slc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Section loaded: sppc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Section loaded: onecorecommonproxystub.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Section loaded: onecoreuapcommonproxystub.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: atl.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: msisip.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wshext.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: appxsip.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: opcservices.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: secur32.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: atl.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: msisip.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wshext.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: appxsip.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: opcservices.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: secur32.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: microsoft.management.infrastructure.native.unmanaged.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: mi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: miutils.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wmidcom.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: dpapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wbemcomn.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\schtasks.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\schtasks.exe | Section loaded: taskschd.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\schtasks.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Section loaded: edputil.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Section loaded: windows.staterepositoryps.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Section loaded: appresolver.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Section loaded: bcp47langs.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Section loaded: slc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Section loaded: sppc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Section loaded: onecorecommonproxystub.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Section loaded: onecoreuapcommonproxystub.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Section loaded: ntvdm64.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Section loaded: textshaping.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Section loaded: textinputframework.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Section loaded: coreuicomponents.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\iKHPXKiqI.exe | Section loaded: mscoree.dll | |
Source: C:\Users\user\AppData\Roaming\iKHPXKiqI.exe | Section loaded: apphelp.dll | |
Source: C:\Users\user\AppData\Roaming\iKHPXKiqI.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Users\user\AppData\Roaming\iKHPXKiqI.exe | Section loaded: version.dll | |
Source: C:\Users\user\AppData\Roaming\iKHPXKiqI.exe | Section loaded: vcruntime140_clr0400.dll | |
Source: C:\Users\user\AppData\Roaming\iKHPXKiqI.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Users\user\AppData\Roaming\iKHPXKiqI.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Users\user\AppData\Roaming\iKHPXKiqI.exe | Section loaded: uxtheme.dll | |
Source: C:\Users\user\AppData\Roaming\iKHPXKiqI.exe | Section loaded: windows.storage.dll | |
Source: C:\Users\user\AppData\Roaming\iKHPXKiqI.exe | Section loaded: wldp.dll | |
Source: C:\Users\user\AppData\Roaming\iKHPXKiqI.exe | Section loaded: profapi.dll | |
Source: C:\Users\user\AppData\Roaming\iKHPXKiqI.exe | Section loaded: cryptsp.dll | |
Source: C:\Users\user\AppData\Roaming\iKHPXKiqI.exe | Section loaded: rsaenh.dll | |
Source: C:\Users\user\AppData\Roaming\iKHPXKiqI.exe | Section loaded: cryptbase.dll | |
Source: C:\Users\user\AppData\Roaming\iKHPXKiqI.exe | Section loaded: dwrite.dll | |
Source: C:\Users\user\AppData\Roaming\iKHPXKiqI.exe | Section loaded: windowscodecs.dll | |
Source: C:\Users\user\AppData\Roaming\iKHPXKiqI.exe | Section loaded: amsi.dll | |
Source: C:\Users\user\AppData\Roaming\iKHPXKiqI.exe | Section loaded: userenv.dll | |
Source: C:\Users\user\AppData\Roaming\iKHPXKiqI.exe | Section loaded: msasn1.dll | |
Source: C:\Users\user\AppData\Roaming\iKHPXKiqI.exe | Section loaded: gpapi.dll | |
Source: C:\Users\user\AppData\Roaming\iKHPXKiqI.exe | Section loaded: propsys.dll | |
Source: C:\Users\user\AppData\Roaming\iKHPXKiqI.exe | Section loaded: edputil.dll | |
Source: C:\Users\user\AppData\Roaming\iKHPXKiqI.exe | Section loaded: urlmon.dll | |
Source: C:\Users\user\AppData\Roaming\iKHPXKiqI.exe | Section loaded: iertutil.dll | |
Source: C:\Users\user\AppData\Roaming\iKHPXKiqI.exe | Section loaded: srvcli.dll | |
Source: C:\Users\user\AppData\Roaming\iKHPXKiqI.exe | Section loaded: netutils.dll | |
Source: C:\Users\user\AppData\Roaming\iKHPXKiqI.exe | Section loaded: windows.staterepositoryps.dll | |
Source: C:\Users\user\AppData\Roaming\iKHPXKiqI.exe | Section loaded: sspicli.dll | |
Source: C:\Users\user\AppData\Roaming\iKHPXKiqI.exe | Section loaded: wintypes.dll | |
Source: C:\Users\user\AppData\Roaming\iKHPXKiqI.exe | Section loaded: appresolver.dll | |
Source: C:\Users\user\AppData\Roaming\iKHPXKiqI.exe | Section loaded: bcp47langs.dll | |
Source: C:\Users\user\AppData\Roaming\iKHPXKiqI.exe | Section loaded: slc.dll | |
Source: C:\Users\user\AppData\Roaming\iKHPXKiqI.exe | Section loaded: sppc.dll | |
Source: C:\Users\user\AppData\Roaming\iKHPXKiqI.exe | Section loaded: onecorecommonproxystub.dll | |
Source: C:\Users\user\AppData\Roaming\iKHPXKiqI.exe | Section loaded: onecoreuapcommonproxystub.dll | |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: fastprox.dll | |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: ncobjapi.dll | |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: wbemcomn.dll | |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: wbemcomn.dll | |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: mpclient.dll | |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: userenv.dll | |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: version.dll | |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: msasn1.dll | |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: wmitomi.dll | |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: mi.dll | |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: miutils.dll | |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: miutils.dll | |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: gpapi.dll | |
Source: | Binary string: D:\a\_work\e\src\out\Release_x64\pwahelper.exe.pdb source: pwahelper.exe1.10.dr, pwahelper.exe0.10.dr, pwahelper.exe.10.dr |
Source: | Binary string: c:\jenkins\workspace\8-2-build-windows-i586-cygwin-sans-NAS\jdk8u381\237\build\windows-i586\deploy\tmp\jp2launcher\obj\jp2launcher.pdb@@4 source: jp2launcher.exe.10.dr |
Source: | Binary string: NisSrv.pdb source: NisSrv.exe0.10.dr |
Source: | Binary string: D:\dbs\el\omr\Target\x86\ship\postc2rcross\x-none\appsharinghookcontroller.pdb source: AppSharingHookController.exe.10.dr |
Source: | Binary string: D:\dbs\el\omr\Target\x86\ship\postc2r\x-none\selfcert.pdb source: SELFCERT.EXE.10.dr |
Source: | Binary string: \??\C:\Windows\dll\mscorlib.pdb source: iKHPXKiqI.exe, 0000000B.00000002.2334957405.0000000007B0E000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: WmQc.pdbs\WmQc.pdbpdbmQc.pdbg\WmQc.pdb source: iKHPXKiqI.exe, 0000000B.00000002.2317304776.0000000000DD7000.00000004.00000010.00020000.00000000.sdmp |
Source: | Binary string: HP^o(C:\Windows\WmQc.pdb source: iKHPXKiqI.exe, 0000000B.00000002.2317304776.0000000000DD7000.00000004.00000010.00020000.00000000.sdmp |
Source: | Binary string: D:\dbs\el\ja2\Target\x86\ship\dcf\x-none\SpreadsheetCompare.pdb source: SPREADSHEETCOMPARE.EXE.10.dr |
Source: | Binary string: d:\dbs\el\ja2\target\x86\ship\delivery\x-none\ose.pdb000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000S source: OSE.EXE.10.dr |
Source: | Binary string: D:\dbs\el\omr\Target\x86\ship\postc2r\x-none\officeappguardwin32.pdb source: officeappguardwin32.exe.10.dr |
Source: | Binary string: \??\C:\Windows\exe\WmQc.pdb source: iKHPXKiqI.exe, 0000000B.00000002.2334957405.0000000007AF5000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: D:\a\_work\e\src\out\Release_x64\setup.exe.pdbOGP source: setup.exe.10.dr |
Source: | Binary string: C:\Windows\WmQc.pdbpdbmQc.pdb source: iKHPXKiqI.exe, 0000000B.00000002.2334957405.0000000007B0E000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: !!.pdb source: iKHPXKiqI.exe, 0000000B.00000002.2317304776.0000000000DD7000.00000004.00000010.00020000.00000000.sdmp |
Source: | Binary string: WmQc.pdb^1w^ source: iKHPXKiqI.exe, 0000000B.00000002.2317304776.0000000000DD7000.00000004.00000010.00020000.00000000.sdmp |
Source: | Binary string: d:\dbs\el\omr\target\x86\ship\graphics_filterloader\x-none\FLTLDR.pdb source: FLTLDR.EXE.10.dr |
Source: | Binary string: D:\dbs\el\omr\Target\x86\ship\postc2r\x-none\namecontrolserver.pdb source: NAMECONTROLSERVER.EXE.10.dr |
Source: | Binary string: D:\dbs\el\omr\Target\x86\ship\postc2r\x-none\cnfnot32.pdb00000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000S source: CNFNOT32.EXE.10.dr |
Source: | Binary string: WmQc.pdb21-2246122658-3693405117-2476756634-1003_Classes\WOW6432Node\CLSID\{0A29FF9E-7F9C-4437-8B11-F424491E3931}\InprocServer32EW source: iKHPXKiqI.exe, 0000000B.00000002.2334957405.0000000007B0E000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Windows\System.pdbE source: iKHPXKiqI.exe, 0000000B.00000002.2334957405.0000000007AF5000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: @jo.pdb source: iKHPXKiqI.exe, 0000000B.00000002.2317304776.0000000000DD7000.00000004.00000010.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System\v4.0_4.0.0.0__b77a5c561934e089\System.pdb} source: iKHPXKiqI.exe, 0000000B.00000002.2318435074.0000000001373000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: ker.pdb source: OfficeScrBroker.exe.10.dr |
Source: | Binary string: C:\Data\svn\autoit\branch_3.3.16\bin\Aut2Exe\Aut2Exe.pdb source: Aut2exe.exe.10.dr |
Source: | Binary string: C:\Windows\mscorlib.pdbpdblib.pdbZ source: iKHPXKiqI.exe, 0000000B.00000002.2334957405.0000000007B0E000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: R:\JoeSecurity\trunk\src\windows\usermode\tools\FakeChrome\Release\Chrome.pdb source: chrome.exe.10.dr |
Source: | Binary string: WmQc.pdbSHA256 source: iKHPXKiqI.exe, 0000000B.00000002.2318435074.0000000001405000.00000004.00000020.00020000.00000000.sdmp, Plat#U0103 revizuit#U0103_shrunk.exe |
Source: | Binary string: symbols\exe\WmQc.pdbjo source: iKHPXKiqI.exe, 0000000B.00000002.2317304776.0000000000DD7000.00000004.00000010.00020000.00000000.sdmp |
Source: | Binary string: C:\Users\user\AppData\Roaming\iKHPXKiqI.PDB source: iKHPXKiqI.exe, 0000000B.00000002.2317304776.0000000000DD7000.00000004.00000010.00020000.00000000.sdmp |
Source: | Binary string: r.pdb source: AppSharingHookController.exe.10.dr |
Source: | Binary string: D:\dbs\el\omr\Target\x86\ship\postc2r\x-none\ocpubmgr.pdb source: OcPubMgr.exe.10.dr |
Source: | Binary string: d:\dbs\el\ja2\target\x86\ship\dcf\x-none\FileCompare.pdb000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000S source: filecompare.exe.10.dr |
Source: | Binary string: \??\C:\Windows\mscorlib.pdb source: iKHPXKiqI.exe, 0000000B.00000002.2334957405.0000000007AF5000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: MsMpEng.pdbGCTL source: MsMpEng.exe0.10.dr, MsMpEng.exe.10.dr |
Source: | Binary string: c:\jenkins\workspace\8-2-build-windows-i586-cygwin-sans-NAS\jdk8u381\237\build\windows-i586\deploy\tmp\jp2launcher\obj\jp2launcher.pdb source: jp2launcher.exe.10.dr |
Source: | Binary string: ?joC:\Users\user\AppData\Roaming\WmQc.pdb source: iKHPXKiqI.exe, 0000000B.00000002.2317304776.0000000000DD7000.00000004.00000010.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Windows\exe\WmQc.pdbe source: iKHPXKiqI.exe, 0000000B.00000002.2334957405.0000000007AF5000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: D:\dbs\el\omr\Target\x86\ship\postc2r\x-none\officescrbroker.pdbker.pdb00000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000S source: OfficeScrBroker.exe.10.dr |
Source: | Binary string: D:\dbs\el\omr\Target\x86\ship\postc2r\x-none\orgchart.pdb source: ORGCHART.EXE.10.dr |
Source: | Binary string: D:\a\_work\e\src\out\Release_x64\setup.exe.pdb source: setup.exe.10.dr |
Source: | Binary string: D:\dbs\el\omr\Target\x86\ship\postc2r\x-none\orgchart.pdb0000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000S source: ORGCHART.EXE.10.dr |
Source: | Binary string: \??\C:\Windows\symbols\dll\System.pdb source: iKHPXKiqI.exe, 0000000B.00000002.2334957405.0000000007B0E000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Windows\dll\mscorlib.pdbP source: iKHPXKiqI.exe, 0000000B.00000002.2334957405.0000000007B0E000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: d:\dbs\el\ja2\target\x86\ship\delivery\x-none\ose.pdb source: OSE.EXE.10.dr |
Source: | Binary string: D:\dbs\el\omr\Target\x86\ship\postc2r\x-none\selfcert.pdbT.pdb00000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000S source: SELFCERT.EXE.10.dr |
Source: | Binary string: MpCmdRun.pdbGCTL source: MpCmdRun.exe1.10.dr, MpCmdRun.exe0.10.dr, MpCmdRun.exe2.10.dr |
Source: | Binary string: \??\C:\Windows\WmQc.pdb source: iKHPXKiqI.exe, 0000000B.00000002.2334957405.0000000007B0E000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: D:\dbs\el\omr\Target\x86\ship\postc2r\x-none\cnfnot32.pdb source: CNFNOT32.EXE.10.dr |
Source: | Binary string: MpCmdRun.pdb source: MpCmdRun.exe1.10.dr, MpCmdRun.exe0.10.dr, MpCmdRun.exe2.10.dr |
Source: | Binary string: C:\Windows\System.pdbpdbtem.pdb.1D source: iKHPXKiqI.exe, 0000000B.00000002.2334957405.0000000007B0E000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Windows\Microsoft.Net\assembly\GAC_32\mscorlib\v4.0_4.0.0.0__b77a5c561934e089\mscorlib.pdb source: iKHPXKiqI.exe, 0000000B.00000002.2334957405.0000000007AD0000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: D:\dbs\el\omr\Target\x86\ship\postc2r\x-none\perfboost.pdb source: PerfBoost.exe.10.dr |
Source: | Binary string: MicrosoftEdgeUpdateCore_unsigned.pdbd source: MicrosoftEdgeUpdateCore.exe.10.dr |
Source: | Binary string: D:\dbs\el\omr\Target\x86\ship\postc2r\x-none\ocpubmgr.pdb00000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000S source: OcPubMgr.exe.10.dr |
Source: | Binary string: \??\C:\Users\user\AppData\Roaming\iKHPXKiqI.PDB source: iKHPXKiqI.exe, 0000000B.00000002.2334957405.0000000007AD0000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: D:\a\_work\1\s\src\ai\windows\dll\Win32\Release\ai.exe.pdb source: ai.exe0.10.dr |
Source: | Binary string: D:\dbs\el\omr\Target\x86\ship\postc2r\x-none\scanpst.pdb000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000S source: SCANPST.EXE.10.dr |
Source: | Binary string: d:\dbs\el\omr\target\x86\ship\graphics_filterloader\x-none\FLTLDR.pdb00000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000S source: FLTLDR.EXE.10.dr |
Source: | Binary string: D:\dbs\el\omr\Target\x86\ship\postc2rcross\x-none\appsharinghookcontroller.pdbr.pdb00000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000S source: AppSharingHookController.exe.10.dr |
Source: | Binary string: T.pdb source: SELFCERT.EXE.10.dr |
Source: | Binary string: in32.pdb source: officeappguardwin32.exe.10.dr |
Source: | Binary string: D:\a\_work\e\src\out\Release_x64\pwahelper.exe.pdbOGP source: pwahelper.exe1.10.dr, pwahelper.exe0.10.dr, pwahelper.exe.10.dr |
Source: | Binary string: WmQc.pdb source: iKHPXKiqI.exe, 0000000B.00000002.2334957405.0000000007B0E000.00000004.00000020.00020000.00000000.sdmp, iKHPXKiqI.exe, 0000000B.00000002.2318435074.0000000001405000.00000004.00000020.00020000.00000000.sdmp, iKHPXKiqI.exe, 0000000B.00000002.2317304776.0000000000DD7000.00000004.00000010.00020000.00000000.sdmp, Plat#U0103 revizuit#U0103_shrunk.exe |
Source: | Binary string: \??\C:\Windows\dll\System.pdb source: iKHPXKiqI.exe, 0000000B.00000002.2334957405.0000000007B0E000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Windows\symbols\exe\WmQc.pdbj source: iKHPXKiqI.exe, 0000000B.00000002.2334957405.0000000007B0E000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Windows\symbols\dll\mscorlib.pdb source: iKHPXKiqI.exe, 0000000B.00000002.2334957405.0000000007B0E000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: D:\dbs\el\omr\Target\x86\ship\postc2r\x-none\officescrbroker.pdb source: OfficeScrBroker.exe.10.dr |
Source: | Binary string: D:\dbs\el\omr\Target\x86\ship\postc2r\x-none\officeappguardwin32.pdbin32.pdb000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000S source: officeappguardwin32.exe.10.dr |
Source: | Binary string: MicrosoftEdgeUpdateCore_unsigned.pdb source: MicrosoftEdgeUpdateCore.exe.10.dr |
Source: | Binary string: NisSrv.pdbGCTL source: NisSrv.exe0.10.dr |
Source: | Binary string: \??\C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System\v4.0_4.0.0.0__b77a5c561934e089\System.pdb source: iKHPXKiqI.exe, 0000000B.00000002.2318435074.0000000001373000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: MsMpEng.pdb source: MsMpEng.exe0.10.dr, MsMpEng.exe.10.dr |
Source: | Binary string: D:\a\_work\1\s\src\ai\windows\dll\Win32\Release\ai.exe.pdb/ source: ai.exe0.10.dr |
Source: | Binary string: D:\dbs\el\omr\Target\x86\ship\postc2r\x-none\perfboost.pdbb00000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000S source: PerfBoost.exe.10.dr |
Source: | Binary string: D:\dbs\el\omr\Target\x86\ship\postc2r\x-none\namecontrolserver.pdbb000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000S source: NAMECONTROLSERVER.EXE.10.dr |
Source: | Binary string: \??\C:\Windows\symbols\exe\WmQc.pdb source: iKHPXKiqI.exe, 0000000B.00000002.2334957405.0000000007B0E000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: D:\dbs\el\omr\Target\x86\ship\postc2r\x-none\scanpst.pdb source: SCANPST.EXE.10.dr |
Source: | Binary string: d:\dbs\el\ja2\target\x86\ship\dcf\x-none\FileCompare.pdb source: filecompare.exe.10.dr |
Source: | Binary string: \??\C:\Users\user\AppData\Roaming\WmQc.pdb source: iKHPXKiqI.exe, 0000000B.00000002.2334957405.0000000007AF5000.00000004.00000020.00020000.00000000.sdmp |
Source: 0.2.Plat#U0103 revizuit#U0103_shrunk.exe.2c8a258.0.raw.unpack, kD0JNdgNBriBGn5egS.cs | High entropy of concatenated method names: 'ubU6vJppswKkZ', 'uvAmfDYbimWPg9rmyH6', 'XHYItoYHo1DoUvgeuNZ', 'tYVkNWYXlYIi7gDFfLn', 'TV4H82YzoL7kT86loIA', 'yoiEG7M3KqRFDlQAaqW', 'rU4RpWYS77WPQpUZwKR', 'vGvSIFYGEhSitdykOPg', 'TCSl6vMYjB5c5h75h4u' |
Source: 0.2.Plat#U0103 revizuit#U0103_shrunk.exe.2c8a258.0.raw.unpack, QBy45BY4uMbUQs88Qq.cs | High entropy of concatenated method names: 'QByY45B4u', 'EbUNQs88Q', 'D8PguGCCm', 'gfwtorebq', 'rQ9oD0JNd', 'cBrXiBGn5', 'sgS08fT72', 'lmAQKmrG6', 'qn1mTNvNO', 'K084ZL4CG' |
Source: 0.2.Plat#U0103 revizuit#U0103_shrunk.exe.2c7da30.3.raw.unpack, kD0JNdgNBriBGn5egS.cs | High entropy of concatenated method names: 'ubU6vJppswKkZ', 'uvAmfDYbimWPg9rmyH6', 'XHYItoYHo1DoUvgeuNZ', 'tYVkNWYXlYIi7gDFfLn', 'TV4H82YzoL7kT86loIA', 'yoiEG7M3KqRFDlQAaqW', 'rU4RpWYS77WPQpUZwKR', 'vGvSIFYGEhSitdykOPg', 'TCSl6vMYjB5c5h75h4u' |
Source: 0.2.Plat#U0103 revizuit#U0103_shrunk.exe.2c7da30.3.raw.unpack, QBy45BY4uMbUQs88Qq.cs | High entropy of concatenated method names: 'QByY45B4u', 'EbUNQs88Q', 'D8PguGCCm', 'gfwtorebq', 'rQ9oD0JNd', 'cBrXiBGn5', 'sgS08fT72', 'lmAQKmrG6', 'qn1mTNvNO', 'K084ZL4CG' |
Source: 0.2.Plat#U0103 revizuit#U0103_shrunk.exe.3cef6e8.4.raw.unpack, i3QFsjjoAPkUndGBmc.cs | High entropy of concatenated method names: 'nxBhvINf01', 'JM5hJVYI0G', 'xkyh5PXUgn', 'DFJhC5ZybL', 'RebhsmNwGI', 'iF3hNIpSUS', 'vmkhGGiMUL', 'AWnLaUPho5', 'QsULMQN5ay', 'hhDLjgUMCR' |
Source: 0.2.Plat#U0103 revizuit#U0103_shrunk.exe.3cef6e8.4.raw.unpack, lympCmhAo8DkBB5YJn.cs | High entropy of concatenated method names: 'bCrOkBj3yF', 'lQUO06s2Un', 'RpHOy05m9w', 'JyKOcc9mZl', 'GXXOKH4pcU', 'R6FOeL3XCN', 'qBKOtvRvS6', 'Ge9OH13XRJ', 'CGsOYrVOF5', 'sJxODRq5NA' |
Source: 0.2.Plat#U0103 revizuit#U0103_shrunk.exe.3cef6e8.4.raw.unpack, Ev4NU9fl0WsJ9RcSij.cs | High entropy of concatenated method names: 'TsKEUapl2Y', 'jVwESIyy1n', 'ToString', 'M0MECN8NWQ', 'q1ZEsCsu0i', 'J09E48r9q1', 'WYKENl8E8n', 'paVEGsDPgw', 'gBZEFn2Jgh', 'aMDEVMp6JD' |
Source: 0.2.Plat#U0103 revizuit#U0103_shrunk.exe.3cef6e8.4.raw.unpack, EWBDlTwtvjH60TEEpY.cs | High entropy of concatenated method names: 'V9hs202UtI', 'sIAs6dkNkR', 'lyTs1aJDbd', 'b5IsosevID', 'HYYsdq58oj', 'T1WsT9MWZ3', 'tpUsa0w3Q4', 'YHisMRBWwf', 'gAYsj4tOJP', 't0Rsn7M02o' |
Source: 0.2.Plat#U0103 revizuit#U0103_shrunk.exe.3cef6e8.4.raw.unpack, dHK0JAuufJel4uCYfC.cs | High entropy of concatenated method names: 'leM4PP1phQ', 'AeU49aHpqw', 'DId4kS12me', 'yNb40SQfX7', 'fag48WwoFd', 'qM74pIsRni', 'Hm24E47CPI', 'loJ4Lm9YO0', 'rGL4hSDSqC', 'xeI43pJhBf' |
Source: 0.2.Plat#U0103 revizuit#U0103_shrunk.exe.3cef6e8.4.raw.unpack, lbaPktE2bTWtbRkDt5.cs | High entropy of concatenated method names: 'fO0FCfV5kk', 'n8VF4mcPfI', 'jvJFGMXW5B', 'jUqGnuhGS0', 'sxxGzlKef0', 'NytFuOeJJg', 'l5dFvxweGj', 'fLfFbECSmX', 'wytFJbRSIg', 'FXvF5UFpKL' |
Source: 0.2.Plat#U0103 revizuit#U0103_shrunk.exe.3cef6e8.4.raw.unpack, qodqsKeqLvo5DFFps0.cs | High entropy of concatenated method names: 'R7BNi9Opoc', 'rx8NXlbyXH', 'EOU4Q10dXb', 'Sut4KeJ4DH', 'NVO4etyoNx', 'PA047gnhPe', 'yCA4tPmLFn', 'NVp4HpoKyC', 'Ebw4Z1ebnZ', 'sCs4YrwrqI' |
Source: 0.2.Plat#U0103 revizuit#U0103_shrunk.exe.3cef6e8.4.raw.unpack, nIZjT41dYUX23CleyT.cs | High entropy of concatenated method names: 'SnXFlWS2UG', 'AyaFBAWhW8', 'BypFrojx4u', 'uIHFP6sISb', 'C3bFixMA9I', 'yFNF9E6hFn', 'UFkFXiPDbr', 'eFDFkZU7mU', 'lEZF0KuY5m', 'BUKFqU1nPG' |
Source: 0.2.Plat#U0103 revizuit#U0103_shrunk.exe.3cef6e8.4.raw.unpack, HDAe46A2O6fF0GX7vE.cs | High entropy of concatenated method names: 'CbFLC7kTI7', 'CfPLs2xjxu', 'wIeL4SnWyK', 'e2yLNv8ENY', 'TdMLGGH3iD', 'SG7LFTibTy', 'CybLVcKHjY', 'vxGLm8du6p', 'PuGLUGNTKM', 'aJgLS3G1L9' |
Source: 0.2.Plat#U0103 revizuit#U0103_shrunk.exe.3cef6e8.4.raw.unpack, l33W9b55KZlmGgZZfOs.cs | High entropy of concatenated method names: 'ToString', 'gNp3JLDgqY', 'NBd35L6JMk', 'dKm3R52w7F', 'McF3CCqiHI', 'vuW3s9hcrZ', 'gXt34o9f0C', 'dQx3NfuSva', 'Lat0GLFrDZVByffRPNb', 'VNAPKiFtZypWVKxQwZm' |
Source: 0.2.Plat#U0103 revizuit#U0103_shrunk.exe.3cef6e8.4.raw.unpack, uhS9RZ5ahWF0HqJupPq.cs | High entropy of concatenated method names: 'bT3hllU7bm', 'riFhBPMJj4', 'BWkhrcPq6D', 'gWxhP1CnkK', 'bRNhiDwCFY', 'tCYh9GJi6I', 'pMRhXQs52t', 'wR0hkdx87w', 'uhoh0ElEX5', 'hAahqumiXV' |
Source: 0.2.Plat#U0103 revizuit#U0103_shrunk.exe.3cef6e8.4.raw.unpack, mnZWJCLmR68gF25k1b.cs | High entropy of concatenated method names: 'ektEMLI7i1', 'NPOEnYTQ6u', 'IogLuOZpJG', 'oP6LvwT5cX', 'DItEDmUFmj', 'y4qEgkEiGO', 'PCpExVbt4e', 'O25E2rZJ8U', 'hfpE6frD0Z', 'bNcE19aM3V' |
Source: 0.2.Plat#U0103 revizuit#U0103_shrunk.exe.3cef6e8.4.raw.unpack, nNpPf2bbiU0wr5aAbG.cs | High entropy of concatenated method names: 'tJRGRppK14', 'KQ6Gscq9nC', 'Aw9GNvOMqU', 'tdxGFBqoCC', 'sf2GVJNRk1', 'slfNd9Y4M5', 'BKTNTEIoXV', 'raCNaItRTA', 'qPuNMpb1li', 'uoFNj2jhRw' |
Source: 0.2.Plat#U0103 revizuit#U0103_shrunk.exe.3cef6e8.4.raw.unpack, Q3cYm63WTXjOtmGRQk.cs | High entropy of concatenated method names: 'pZeJRwNh2J', 'BlsJCUKBu2', 'mtDJsoE9gD', 'ybTJ4584LE', 'SUXJNKU7EM', 'vDFJGXmog0', 'ge8JFWUm4L', 'cysJVjHT6L', 'vuKJmO8QX7', 'yxoJU4C5Mf' |
Source: 0.2.Plat#U0103 revizuit#U0103_shrunk.exe.3cef6e8.4.raw.unpack, sMffnmzUkmObinjZBa.cs | High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'DuqhO678ql', 'svQh8yDKvO', 'uiIhph5941', 'urhhEKAGJX', 'FskhLhjcvS', 'vhXhhTkTrL', 'IdDh341Q5i' |
Source: 0.2.Plat#U0103 revizuit#U0103_shrunk.exe.3cef6e8.4.raw.unpack, j1GIrwPHgpSbc4PlfT.cs | High entropy of concatenated method names: 'NXCLy4vJ15', 'DFjLcRAklq', 'JhYLQOFx6s', 'j4pLKWHI7c', 'JP1L29CoYY', 'ivwLe24UBS', 'Next', 'Next', 'Next', 'NextBytes' |
Source: 0.2.Plat#U0103 revizuit#U0103_shrunk.exe.3cef6e8.4.raw.unpack, jwCfPD5VUsRfBbdgXYY.cs | High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'LMU32Gy81E', 'VJy36eEJRV', 'fgM31Pfw61', 'b2Z3ooitw5', 'rdi3dMVCrd', 'DOZ3ToEYNX', 'U1f3ap0T89' |
Source: 0.2.Plat#U0103 revizuit#U0103_shrunk.exe.3cef6e8.4.raw.unpack, dakg5lc8YcgJC3pGDS.cs | High entropy of concatenated method names: 'lePvFRIqSx', 'c9hvV9VkPp', 'iBcvUhBxTs', 'mxCvSbavG5', 'IH3v8OBY0Q', 'KVYvpUnBfd', 'WE6VVmIR9HqicFOc58', 'rOxHNId5OOW8VoUcUp', 'iTovvgOlHw', 'La7vJ753jb' |
Source: 0.2.Plat#U0103 revizuit#U0103_shrunk.exe.3cef6e8.4.raw.unpack, wBrAhgpZKKs8gFMTeX.cs | High entropy of concatenated method names: 'rhurNtPmf', 'Bw0PyZ1Mv', 's6g9tv3f0', 'X5UXnJ8aR', 'vtV0N97Io', 'IUjqK3unb', 'RRP6f4XvZxghQE4Zun', 'zxSjGJqkJljY7ZFRtM', 'Vv9Ly93yF', 'tvl3jahZF' |
Source: 0.2.Plat#U0103 revizuit#U0103_shrunk.exe.3cef6e8.4.raw.unpack, nv7pDIdaGY08lNoLhp.cs | High entropy of concatenated method names: 'Dispose', 'ptOvjw0vRq', 'AjebcTD0Y4', 'fhvIIrHU6h', 'iFQvnM6hpK', 'fkUvzK4eqi', 'ProcessDialogKey', 's9gbucpt7e', 'AShbvSd6kj', 'UOhbb4MUYb' |
Source: 0.2.Plat#U0103 revizuit#U0103_shrunk.exe.5360000.5.raw.unpack, kD0JNdgNBriBGn5egS.cs | High entropy of concatenated method names: 'ubU6vJppswKkZ', 'uvAmfDYbimWPg9rmyH6', 'XHYItoYHo1DoUvgeuNZ', 'tYVkNWYXlYIi7gDFfLn', 'TV4H82YzoL7kT86loIA', 'yoiEG7M3KqRFDlQAaqW', 'rU4RpWYS77WPQpUZwKR', 'vGvSIFYGEhSitdykOPg', 'TCSl6vMYjB5c5h75h4u' |
Source: 0.2.Plat#U0103 revizuit#U0103_shrunk.exe.5360000.5.raw.unpack, QBy45BY4uMbUQs88Qq.cs | High entropy of concatenated method names: 'QByY45B4u', 'EbUNQs88Q', 'D8PguGCCm', 'gfwtorebq', 'rQ9oD0JNd', 'cBrXiBGn5', 'sgS08fT72', 'lmAQKmrG6', 'qn1mTNvNO', 'K084ZL4CG' |
Source: 0.2.Plat#U0103 revizuit#U0103_shrunk.exe.2cd9b3c.1.raw.unpack, kD0JNdgNBriBGn5egS.cs | High entropy of concatenated method names: 'ubU6vJppswKkZ', 'uvAmfDYbimWPg9rmyH6', 'XHYItoYHo1DoUvgeuNZ', 'tYVkNWYXlYIi7gDFfLn', 'TV4H82YzoL7kT86loIA', 'yoiEG7M3KqRFDlQAaqW', 'rU4RpWYS77WPQpUZwKR', 'vGvSIFYGEhSitdykOPg', 'TCSl6vMYjB5c5h75h4u' |
Source: 0.2.Plat#U0103 revizuit#U0103_shrunk.exe.2cd9b3c.1.raw.unpack, QBy45BY4uMbUQs88Qq.cs | High entropy of concatenated method names: 'QByY45B4u', 'EbUNQs88Q', 'D8PguGCCm', 'gfwtorebq', 'rQ9oD0JNd', 'cBrXiBGn5', 'sgS08fT72', 'lmAQKmrG6', 'qn1mTNvNO', 'K084ZL4CG' |
Source: 0.2.Plat#U0103 revizuit#U0103_shrunk.exe.2ccc98c.2.raw.unpack, kD0JNdgNBriBGn5egS.cs | High entropy of concatenated method names: 'ubU6vJppswKkZ', 'uvAmfDYbimWPg9rmyH6', 'XHYItoYHo1DoUvgeuNZ', 'tYVkNWYXlYIi7gDFfLn', 'TV4H82YzoL7kT86loIA', 'yoiEG7M3KqRFDlQAaqW', 'rU4RpWYS77WPQpUZwKR', 'vGvSIFYGEhSitdykOPg', 'TCSl6vMYjB5c5h75h4u' |
Source: 0.2.Plat#U0103 revizuit#U0103_shrunk.exe.2ccc98c.2.raw.unpack, QBy45BY4uMbUQs88Qq.cs | High entropy of concatenated method names: 'QByY45B4u', 'EbUNQs88Q', 'D8PguGCCm', 'gfwtorebq', 'rQ9oD0JNd', 'cBrXiBGn5', 'sgS08fT72', 'lmAQKmrG6', 'qn1mTNvNO', 'K084ZL4CG' |
Source: 0.2.Plat#U0103 revizuit#U0103_shrunk.exe.7e50000.6.raw.unpack, i3QFsjjoAPkUndGBmc.cs | High entropy of concatenated method names: 'nxBhvINf01', 'JM5hJVYI0G', 'xkyh5PXUgn', 'DFJhC5ZybL', 'RebhsmNwGI', 'iF3hNIpSUS', 'vmkhGGiMUL', 'AWnLaUPho5', 'QsULMQN5ay', 'hhDLjgUMCR' |
Source: 0.2.Plat#U0103 revizuit#U0103_shrunk.exe.7e50000.6.raw.unpack, lympCmhAo8DkBB5YJn.cs | High entropy of concatenated method names: 'bCrOkBj3yF', 'lQUO06s2Un', 'RpHOy05m9w', 'JyKOcc9mZl', 'GXXOKH4pcU', 'R6FOeL3XCN', 'qBKOtvRvS6', 'Ge9OH13XRJ', 'CGsOYrVOF5', 'sJxODRq5NA' |
Source: 0.2.Plat#U0103 revizuit#U0103_shrunk.exe.7e50000.6.raw.unpack, Ev4NU9fl0WsJ9RcSij.cs | High entropy of concatenated method names: 'TsKEUapl2Y', 'jVwESIyy1n', 'ToString', 'M0MECN8NWQ', 'q1ZEsCsu0i', 'J09E48r9q1', 'WYKENl8E8n', 'paVEGsDPgw', 'gBZEFn2Jgh', 'aMDEVMp6JD' |
Source: 0.2.Plat#U0103 revizuit#U0103_shrunk.exe.7e50000.6.raw.unpack, EWBDlTwtvjH60TEEpY.cs | High entropy of concatenated method names: 'V9hs202UtI', 'sIAs6dkNkR', 'lyTs1aJDbd', 'b5IsosevID', 'HYYsdq58oj', 'T1WsT9MWZ3', 'tpUsa0w3Q4', 'YHisMRBWwf', 'gAYsj4tOJP', 't0Rsn7M02o' |
Source: 0.2.Plat#U0103 revizuit#U0103_shrunk.exe.7e50000.6.raw.unpack, dHK0JAuufJel4uCYfC.cs | High entropy of concatenated method names: 'leM4PP1phQ', 'AeU49aHpqw', 'DId4kS12me', 'yNb40SQfX7', 'fag48WwoFd', 'qM74pIsRni', 'Hm24E47CPI', 'loJ4Lm9YO0', 'rGL4hSDSqC', 'xeI43pJhBf' |
Source: 0.2.Plat#U0103 revizuit#U0103_shrunk.exe.7e50000.6.raw.unpack, lbaPktE2bTWtbRkDt5.cs | High entropy of concatenated method names: 'fO0FCfV5kk', 'n8VF4mcPfI', 'jvJFGMXW5B', 'jUqGnuhGS0', 'sxxGzlKef0', 'NytFuOeJJg', 'l5dFvxweGj', 'fLfFbECSmX', 'wytFJbRSIg', 'FXvF5UFpKL' |
Source: 0.2.Plat#U0103 revizuit#U0103_shrunk.exe.7e50000.6.raw.unpack, qodqsKeqLvo5DFFps0.cs | High entropy of concatenated method names: 'R7BNi9Opoc', 'rx8NXlbyXH', 'EOU4Q10dXb', 'Sut4KeJ4DH', 'NVO4etyoNx', 'PA047gnhPe', 'yCA4tPmLFn', 'NVp4HpoKyC', 'Ebw4Z1ebnZ', 'sCs4YrwrqI' |
Source: 0.2.Plat#U0103 revizuit#U0103_shrunk.exe.7e50000.6.raw.unpack, nIZjT41dYUX23CleyT.cs | High entropy of concatenated method names: 'SnXFlWS2UG', 'AyaFBAWhW8', 'BypFrojx4u', 'uIHFP6sISb', 'C3bFixMA9I', 'yFNF9E6hFn', 'UFkFXiPDbr', 'eFDFkZU7mU', 'lEZF0KuY5m', 'BUKFqU1nPG' |
Source: 0.2.Plat#U0103 revizuit#U0103_shrunk.exe.7e50000.6.raw.unpack, HDAe46A2O6fF0GX7vE.cs | High entropy of concatenated method names: 'CbFLC7kTI7', 'CfPLs2xjxu', 'wIeL4SnWyK', 'e2yLNv8ENY', 'TdMLGGH3iD', 'SG7LFTibTy', 'CybLVcKHjY', 'vxGLm8du6p', 'PuGLUGNTKM', 'aJgLS3G1L9' |
Source: 0.2.Plat#U0103 revizuit#U0103_shrunk.exe.7e50000.6.raw.unpack, l33W9b55KZlmGgZZfOs.cs | High entropy of concatenated method names: 'ToString', 'gNp3JLDgqY', 'NBd35L6JMk', 'dKm3R52w7F', 'McF3CCqiHI', 'vuW3s9hcrZ', 'gXt34o9f0C', 'dQx3NfuSva', 'Lat0GLFrDZVByffRPNb', 'VNAPKiFtZypWVKxQwZm' |
Source: 0.2.Plat#U0103 revizuit#U0103_shrunk.exe.7e50000.6.raw.unpack, uhS9RZ5ahWF0HqJupPq.cs | High entropy of concatenated method names: 'bT3hllU7bm', 'riFhBPMJj4', 'BWkhrcPq6D', 'gWxhP1CnkK', 'bRNhiDwCFY', 'tCYh9GJi6I', 'pMRhXQs52t', 'wR0hkdx87w', 'uhoh0ElEX5', 'hAahqumiXV' |
Source: 0.2.Plat#U0103 revizuit#U0103_shrunk.exe.7e50000.6.raw.unpack, mnZWJCLmR68gF25k1b.cs | High entropy of concatenated method names: 'ektEMLI7i1', 'NPOEnYTQ6u', 'IogLuOZpJG', 'oP6LvwT5cX', 'DItEDmUFmj', 'y4qEgkEiGO', 'PCpExVbt4e', 'O25E2rZJ8U', 'hfpE6frD0Z', 'bNcE19aM3V' |
Source: 0.2.Plat#U0103 revizuit#U0103_shrunk.exe.7e50000.6.raw.unpack, nNpPf2bbiU0wr5aAbG.cs | High entropy of concatenated method names: 'tJRGRppK14', 'KQ6Gscq9nC', 'Aw9GNvOMqU', 'tdxGFBqoCC', 'sf2GVJNRk1', 'slfNd9Y4M5', 'BKTNTEIoXV', 'raCNaItRTA', 'qPuNMpb1li', 'uoFNj2jhRw' |
Source: 0.2.Plat#U0103 revizuit#U0103_shrunk.exe.7e50000.6.raw.unpack, Q3cYm63WTXjOtmGRQk.cs | High entropy of concatenated method names: 'pZeJRwNh2J', 'BlsJCUKBu2', 'mtDJsoE9gD', 'ybTJ4584LE', 'SUXJNKU7EM', 'vDFJGXmog0', 'ge8JFWUm4L', 'cysJVjHT6L', 'vuKJmO8QX7', 'yxoJU4C5Mf' |
Source: 0.2.Plat#U0103 revizuit#U0103_shrunk.exe.7e50000.6.raw.unpack, sMffnmzUkmObinjZBa.cs | High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'DuqhO678ql', 'svQh8yDKvO', 'uiIhph5941', 'urhhEKAGJX', 'FskhLhjcvS', 'vhXhhTkTrL', 'IdDh341Q5i' |
Source: 0.2.Plat#U0103 revizuit#U0103_shrunk.exe.7e50000.6.raw.unpack, j1GIrwPHgpSbc4PlfT.cs | High entropy of concatenated method names: 'NXCLy4vJ15', 'DFjLcRAklq', 'JhYLQOFx6s', 'j4pLKWHI7c', 'JP1L29CoYY', 'ivwLe24UBS', 'Next', 'Next', 'Next', 'NextBytes' |
Source: 0.2.Plat#U0103 revizuit#U0103_shrunk.exe.7e50000.6.raw.unpack, jwCfPD5VUsRfBbdgXYY.cs | High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'LMU32Gy81E', 'VJy36eEJRV', 'fgM31Pfw61', 'b2Z3ooitw5', 'rdi3dMVCrd', 'DOZ3ToEYNX', 'U1f3ap0T89' |
Source: 0.2.Plat#U0103 revizuit#U0103_shrunk.exe.7e50000.6.raw.unpack, dakg5lc8YcgJC3pGDS.cs | High entropy of concatenated method names: 'lePvFRIqSx', 'c9hvV9VkPp', 'iBcvUhBxTs', 'mxCvSbavG5', 'IH3v8OBY0Q', 'KVYvpUnBfd', 'WE6VVmIR9HqicFOc58', 'rOxHNId5OOW8VoUcUp', 'iTovvgOlHw', 'La7vJ753jb' |
Source: 0.2.Plat#U0103 revizuit#U0103_shrunk.exe.7e50000.6.raw.unpack, wBrAhgpZKKs8gFMTeX.cs | High entropy of concatenated method names: 'rhurNtPmf', 'Bw0PyZ1Mv', 's6g9tv3f0', 'X5UXnJ8aR', 'vtV0N97Io', 'IUjqK3unb', 'RRP6f4XvZxghQE4Zun', 'zxSjGJqkJljY7ZFRtM', 'Vv9Ly93yF', 'tvl3jahZF' |
Source: 0.2.Plat#U0103 revizuit#U0103_shrunk.exe.7e50000.6.raw.unpack, nv7pDIdaGY08lNoLhp.cs | High entropy of concatenated method names: 'Dispose', 'ptOvjw0vRq', 'AjebcTD0Y4', 'fhvIIrHU6h', 'iFQvnM6hpK', 'fkUvzK4eqi', 'ProcessDialogKey', 's9gbucpt7e', 'AShbvSd6kj', 'UOhbb4MUYb' |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\javaws.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\DCF\DATABASECOMPARE.EXE | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\BHO\ie_to_edge_stub.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\PerfBoost.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MsMpEng.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\X86\MpCmdRun.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesX64\Microsoft Office\Office16\MSOHTMED.EXE | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX86\Microsoft Shared\Office16\MSOXMLED.EXE | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft Office\Office16\OSPPREARM.EXE | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpCopyAccelerator.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Common Files\Java\Java Update\jaureg.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\msedgewebview2.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\SETLANG.EXE | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_749031\javaw.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\msedge_pwa_launcher.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\lync99.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\ssvagent.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\DCF\filecompare.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\SELFCERT.EXE | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\SCANPST.EXE | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\xlicons.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MpCopyAccelerator.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\ConfigSecurityPolicy.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\msedge_proxy.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Common Files\Microsoft Shared\VSTO\10.0\VSTOInstaller.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\AutoIt3\AutoIt3Help.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.55\identity_helper.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Client\AppVDllSurrogate64.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\msoev.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\accicons.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\AutoIt3\Aut2Exe\Aut2exe.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\lyncicon.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Users\user\AppData\Local\Temp\chrome.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\IEContentService.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesX86\Microsoft Analysis Services\AS OLEDB\140\SQLDumper.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Client\AppVLP.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleUpdate.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleUpdateOnDemand.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\wordicon.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\DCF\SPREADSHEETCOMPARE.EXE | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\misc.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\javacpl.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\pwahelper.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleCrashHandler64.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MsMpEng.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\java.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\ConfigSecurityPolicy.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\AutoIt3\Au3Check.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\NisSrv.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleUpdateBroker.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\pj11icon.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\ACCICONS.EXE | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MpDefenderCoreService.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX86\Microsoft Shared\Office16\MSOICONS.EXE | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\misc.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesX64\Microsoft Office\Office16\AppSharingHookController64.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_749031\java.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\visicon.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeComRegisterShellARM64.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\msedge.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.55\elevation_service.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\joticon.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\CLVIEW.EXE | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\SkypeSrv\SKYPESERVER.EXE | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_749031\javaws.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Google\Update\Install\{EB80938B-EC00-4683-A2CC-456206E3A4E1}\117.0.5938.134_117.0.5938.132_chrome_updater.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\mpextms.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\NisSrv.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\XLICONS.EXE | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\AutoIt3\AutoIt3_x64.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Mozilla Maintenance Service\Uninstall.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\Installer\setup.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.55\msedge.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.55\cookie_exporter.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-001F-0409-0000-0000000FF1CE}\misc.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpDlpCmd.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\javaw.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleUpdateComRegisterShell64.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\DCF\Common.DBConnection64.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.55\Installer\setup.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\AutoIt3\Au3Info_x64.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleCrashHandler.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.55\BHO\ie_to_edge_stub.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\pptico.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\outicon.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\jp2launcher.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\dbcicons.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleUpdateCore.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE16\LICLUA.EXE | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\ORGCHART.EXE | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\SDXHelper.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\PPTICO.EXE | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\osmclienticon.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpCmdRun.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\WORDICON.EXE | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\AutoIt3\Aut2Exe\upx.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MpCmdRun.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARMHelper.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Java\jre-1.8\bin\unpack200.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\GRAPH.EXE | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\AutoIt3\Uninstall.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Google\Update\Download\{8A69D345-D564-463C-AFF1-A69D9E530F96}\117.0.5938.134\117.0.5938.134_117.0.5938.132_chrome_updater.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\sscicons.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\X86\MpCmdRun.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\DCF\Common.DBConnection.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\CNFNOT32.EXE | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\msoadfsb.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\pwahelper.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\AutoIt3\Au3Info.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\elevation_service.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\notification_helper.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\cookie_exporter.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\AutoIt3\Aut2Exe\Aut2exe_x64.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\mpextms.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\AppSharingHookController.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\Wordconv.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\ProgramData\Package Cache\{8bdfe669-9705-4184-9368-db9ce581e0e7}\VC_redist.x64.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MpDlpCmd.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\AutoIt3\SciTE\SciTE.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\ADDINS\Microsoft Power Query for Excel Integrated\bin\Microsoft.Mashup.Container.Loader.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\VPREVIEW.EXE | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX86\Microsoft Shared\Office16\OLicenseHeartbeat.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\integrator.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\Office16\OLCFG.EXE | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\grv_icons.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft\Edge\Application\msedge_proxy.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\identity_helper.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | System file written: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\pubs.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Office16\DCF\DATABASECOMPARE.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Java\jre-1.8\bin\javaws.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.55\msedgewebview2.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\BHO\ie_to_edge_stub.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeUpdateComRegisterShell64.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Office16\PerfBoost.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MsMpEng.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\X86\MpCmdRun.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesX64\Microsoft Office\Office16\MSOHTMED.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX86\Microsoft Shared\Office16\MSOXMLED.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Microsoft Office\Office16\OSPPREARM.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpCopyAccelerator.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Common Files\Java\Java Update\jaureg.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-006E-0409-0000-0000000FF1CE}\misc.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\msedgewebview2.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Office16\SETLANG.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX86\Microsoft Shared\DW\DW20.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Windows\svchost.com | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-001F-0C0A-0000-0000000FF1CE}\misc.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_749031\javaw.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\msedge_pwa_launcher.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Office16\lync99.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX86\Microsoft Shared\Office16\FLTLDR.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\aimgr.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Java\jre-1.8\bin\ssvagent.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Office16\DCF\filecompare.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Office16\SELFCERT.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Office16\SCANPST.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Client\AppVDllSurrogate.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\xlicons.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MpCopyAccelerator.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\ConfigSecurityPolicy.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSREC.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\msedge_proxy.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Common Files\Microsoft Shared\VSTO\10.0\VSTOInstaller.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeUpdateBroker.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\AutoIt3\AutoIt3Help.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.55\identity_helper.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Client\AppVDllSurrogate64.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Office16\msoev.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\accicons.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\AutoIt3\Aut2Exe\Aut2exe.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\lyncicon.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.55\msedge_proxy.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeUpdateSetup.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Office16\IEContentService.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Users\user\AppData\Local\Temp\chrome.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesX86\Microsoft Analysis Services\AS OLEDB\140\SQLDumper.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.55\notification_click_helper.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Client\AppVLP.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleUpdate.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Office16\officeappguardwin32.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleUpdateOnDemand.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\wordicon.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Office16\DCF\SPREADSHEETCOMPARE.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Office16\misc.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Java\jre-1.8\bin\javacpl.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleCrashHandler64.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Microsoft\Edge\Application\pwahelper.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MsMpEng.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Java\jre-1.8\bin\java.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\ConfigSecurityPolicy.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\AutoIt3\Au3Check.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\NisSrv.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleUpdateBroker.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\pj11icon.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Office16\ACCICONS.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MpDefenderCoreService.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX86\Microsoft Shared\Office16\MSOICONS.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\misc.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesX64\Microsoft Office\Office16\AppSharingHookController64.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_749031\java.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\visicon.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeComRegisterShellARM64.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\msedge.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.55\elevation_service.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\joticon.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Office16\CLVIEW.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Office16\MSOHTMED.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Office16\SkypeSrv\SKYPESERVER.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_749031\javaws.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Google\Update\Install\{EB80938B-EC00-4683-A2CC-456206E3A4E1}\117.0.5938.134_117.0.5938.132_chrome_updater.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\mpextms.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.55\msedge_pwa_launcher.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\NisSrv.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Office16\XLICONS.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\AutoIt3\AutoIt3_x64.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Mozilla Maintenance Service\Uninstall.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\Installer\setup.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.55\msedge.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX86\Microsoft Shared\Office16\ai.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeUpdateOnDemand.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.55\cookie_exporter.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-001F-0409-0000-0000000FF1CE}\misc.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpDlpCmd.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Java\jre-1.8\bin\javaw.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleUpdateComRegisterShell64.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Office16\DCF\Common.DBConnection64.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.55\Installer\setup.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\AutoIt3\Au3Info_x64.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleCrashHandler.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Office16\NAMECONTROLSERVER.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.55\BHO\ie_to_edge_stub.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\pptico.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Client\AppVDllSurrogate32.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\outicon.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Java\jre-1.8\bin\jp2launcher.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\dbcicons.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Office16\MSQRY32.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleUpdateCore.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-001F-040C-0000-0000000FF1CE}\misc.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE16\LICLUA.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Office16\ORGCHART.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Office16\SDXHelper.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Office16\PPTICO.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\osmclienticon.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Integration\Integrator.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpCmdRun.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Office16\WORDICON.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Office16\OfficeScrSanBroker.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\AutoIt3\Aut2Exe\upx.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MpCmdRun.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARMHelper.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Office16\GRAPH.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Java\jre-1.8\bin\unpack200.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\AutoIt3\Uninstall.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Google\Update\Download\{8A69D345-D564-463C-AFF1-A69D9E530F96}\117.0.5938.134\117.0.5938.134_117.0.5938.132_chrome_updater.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\sscicons.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\X86\MpCmdRun.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Office16\DCF\Common.DBConnection.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Office16\CNFNOT32.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Office16\msoadfsb.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\pwahelper.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Users\user\AppData\Roaming\iKHPXKiqI.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\AutoIt3\Au3Info.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\elevation_service.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\notification_helper.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\MSOXMLED.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\cookie_exporter.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\AutoIt3\Aut2Exe\Aut2exe_x64.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\mpextms.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Office16\AppSharingHookController.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Office16\OfficeScrBroker.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Office16\Wordconv.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\ProgramData\Package Cache\{8bdfe669-9705-4184-9368-db9ce581e0e7}\VC_redist.x64.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MpDlpCmd.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.55\pwahelper.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Office16\OcPubMgr.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\AutoIt3\SciTE\SciTE.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX86\Microsoft Shared\Office16\aimgr.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeUpdateCore.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeUpdate.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Office16\ADDINS\Microsoft Power Query for Excel Integrated\bin\Microsoft.Mashup.Container.Loader.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Office16\VPREVIEW.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX86\Microsoft Shared\Office16\OLicenseHeartbeat.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\integrator.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Office16\OLCFG.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\grv_icons.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX86\Microsoft Shared\Source user\OSE.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Microsoft Office\root\Office16\msoasb.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\pubs.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge_proxy.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | File created: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\identity_helper.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\iKHPXKiqI.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\iKHPXKiqI.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\iKHPXKiqI.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\iKHPXKiqI.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\iKHPXKiqI.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\iKHPXKiqI.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\iKHPXKiqI.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\iKHPXKiqI.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\iKHPXKiqI.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\iKHPXKiqI.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\iKHPXKiqI.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\iKHPXKiqI.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\iKHPXKiqI.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\iKHPXKiqI.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\iKHPXKiqI.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\iKHPXKiqI.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\iKHPXKiqI.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\iKHPXKiqI.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\iKHPXKiqI.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\iKHPXKiqI.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\iKHPXKiqI.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\iKHPXKiqI.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\iKHPXKiqI.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\iKHPXKiqI.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\iKHPXKiqI.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\iKHPXKiqI.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\iKHPXKiqI.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\iKHPXKiqI.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\iKHPXKiqI.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\iKHPXKiqI.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\iKHPXKiqI.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\iKHPXKiqI.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\iKHPXKiqI.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\iKHPXKiqI.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\iKHPXKiqI.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\iKHPXKiqI.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\iKHPXKiqI.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\iKHPXKiqI.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\iKHPXKiqI.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\iKHPXKiqI.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\iKHPXKiqI.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\iKHPXKiqI.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\iKHPXKiqI.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\iKHPXKiqI.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\iKHPXKiqI.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\iKHPXKiqI.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\iKHPXKiqI.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\iKHPXKiqI.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\iKHPXKiqI.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\iKHPXKiqI.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\iKHPXKiqI.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\iKHPXKiqI.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\iKHPXKiqI.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\iKHPXKiqI.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\iKHPXKiqI.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\iKHPXKiqI.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\iKHPXKiqI.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\iKHPXKiqI.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\iKHPXKiqI.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\iKHPXKiqI.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\iKHPXKiqI.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\iKHPXKiqI.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\iKHPXKiqI.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\iKHPXKiqI.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\iKHPXKiqI.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\iKHPXKiqI.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\iKHPXKiqI.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\iKHPXKiqI.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\iKHPXKiqI.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\iKHPXKiqI.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\iKHPXKiqI.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\iKHPXKiqI.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\iKHPXKiqI.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\iKHPXKiqI.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\iKHPXKiqI.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\iKHPXKiqI.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\iKHPXKiqI.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\iKHPXKiqI.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\iKHPXKiqI.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\iKHPXKiqI.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\iKHPXKiqI.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\iKHPXKiqI.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\iKHPXKiqI.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\iKHPXKiqI.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX | |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX | |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX | |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Java\jre-1.8\bin\javaws.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Office16\DCF\DATABASECOMPARE.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.55\msedgewebview2.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\BHO\ie_to_edge_stub.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeUpdateComRegisterShell64.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Office16\PerfBoost.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MsMpEng.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\X86\MpCmdRun.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesX64\Microsoft Office\Office16\MSOHTMED.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX86\Microsoft Shared\Office16\MSOXMLED.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\Office16\OSPPREARM.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Common Files\Java\Java Update\jaureg.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-006E-0409-0000-0000000FF1CE}\misc.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpCopyAccelerator.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Office16\SETLANG.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\msedgewebview2.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX86\Microsoft Shared\DW\DW20.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-001F-0C0A-0000-0000000FF1CE}\misc.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Windows\svchost.com | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_749031\javaw.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\msedge_pwa_launcher.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Office16\lync99.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX86\Microsoft Shared\Office16\FLTLDR.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\aimgr.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Java\jre-1.8\bin\ssvagent.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Office16\SELFCERT.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Office16\DCF\filecompare.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Office16\SCANPST.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Client\AppVDllSurrogate.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\xlicons.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MpCopyAccelerator.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\ConfigSecurityPolicy.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSREC.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\msedge_proxy.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Common Files\Microsoft Shared\VSTO\10.0\VSTOInstaller.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeUpdateBroker.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\AutoIt3\AutoIt3Help.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.55\identity_helper.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\accicons.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Client\AppVDllSurrogate64.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Office16\msoev.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\AutoIt3\Aut2Exe\Aut2exe.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\lyncicon.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.55\msedge_proxy.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\chrome.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Office16\IEContentService.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeUpdateSetup.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesX86\Microsoft Analysis Services\AS OLEDB\140\SQLDumper.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.55\notification_click_helper.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleUpdate.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Client\AppVLP.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Office16\officeappguardwin32.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleUpdateOnDemand.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\wordicon.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Office16\DCF\SPREADSHEETCOMPARE.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Office16\misc.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Java\jre-1.8\bin\javacpl.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleCrashHandler64.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Edge\Application\pwahelper.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MsMpEng.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Java\jre-1.8\bin\java.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\ConfigSecurityPolicy.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\AutoIt3\Au3Check.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleUpdateBroker.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\pj11icon.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\NisSrv.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Office16\ACCICONS.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX86\Microsoft Shared\Office16\MSOICONS.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MpDefenderCoreService.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\misc.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesX64\Microsoft Office\Office16\AppSharingHookController64.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_749031\java.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\visicon.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeComRegisterShellARM64.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\msedge.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.55\elevation_service.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\joticon.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Office16\CLVIEW.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Office16\MSOHTMED.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Office16\SkypeSrv\SKYPESERVER.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Google\Update\Install\{EB80938B-EC00-4683-A2CC-456206E3A4E1}\117.0.5938.134_117.0.5938.132_chrome_updater.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Common Files\Oracle\Java\javapath_target_749031\javaws.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\mpextms.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.55\msedge_pwa_launcher.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Office16\XLICONS.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\NisSrv.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Mozilla Maintenance Service\Uninstall.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\AutoIt3\AutoIt3_x64.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\Installer\setup.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.55\msedge.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX86\Microsoft Shared\Office16\ai.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeUpdateOnDemand.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.55\cookie_exporter.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-001F-0409-0000-0000000FF1CE}\misc.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpDlpCmd.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Java\jre-1.8\bin\javaw.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleUpdateComRegisterShell64.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Office16\DCF\Common.DBConnection64.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.55\Installer\setup.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleCrashHandler.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\AutoIt3\Au3Info_x64.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Office16\NAMECONTROLSERVER.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.55\BHO\ie_to_edge_stub.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\pptico.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Client\AppVDllSurrogate32.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\outicon.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Java\jre-1.8\bin\jp2launcher.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\dbcicons.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Office16\MSQRY32.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Google\Update\1.3.36.312\GoogleUpdateCore.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-001F-040C-0000-0000000FF1CE}\misc.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE16\LICLUA.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Office16\SDXHelper.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Office16\ORGCHART.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\osmclienticon.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Office16\PPTICO.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Integration\Integrator.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpCmdRun.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Office16\WORDICON.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Office16\OfficeScrSanBroker.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\AutoIt3\Aut2Exe\upx.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MpCmdRun.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARMHelper.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\ai.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Java\jre-1.8\bin\unpack200.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Office16\GRAPH.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Google\Update\Download\{8A69D345-D564-463C-AFF1-A69D9E530F96}\117.0.5938.134\117.0.5938.134_117.0.5938.132_chrome_updater.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\AutoIt3\Uninstall.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\sscicons.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\X86\MpCmdRun.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Office16\DCF\Common.DBConnection.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Office16\CNFNOT32.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Office16\msoadfsb.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\pwahelper.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\AutoIt3\Au3Info.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\elevation_service.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX64\Microsoft Shared\Office16\MSOXMLED.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\notification_helper.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\cookie_exporter.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\AutoIt3\Aut2Exe\Aut2exe_x64.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\mpextms.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Office16\AppSharingHookController.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Office16\OfficeScrBroker.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Office16\Wordconv.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\ProgramData\Package Cache\{8bdfe669-9705-4184-9368-db9ce581e0e7}\VC_redist.x64.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23090.2008-0\MpDlpCmd.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Edge\Application\117.0.2045.55\pwahelper.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Office16\OcPubMgr.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\AutoIt3\SciTE\SciTE.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX86\Microsoft Shared\Office16\aimgr.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeUpdateCore.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Office16\ADDINS\Microsoft Power Query for Excel Integrated\bin\Microsoft.Mashup.Container.Loader.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Temp\EUC7A5.tmp\MicrosoftEdgeUpdate.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX86\Microsoft Shared\Office16\OLicenseHeartbeat.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Office16\VPREVIEW.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\integrator.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Office16\OLCFG.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\grv_icons.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX86\Microsoft Shared\Source user\OSE.EXE | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\Office16\msoasb.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft Office\root\vfs\Windows\Installer\{90160000-000F-0000-0000-0000000FF1CE}\pubs.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft\EdgeCore\117.0.2045.47\identity_helper.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Dropped PE file which has not been started: C:\Program Files (x86)\Microsoft\Edge\Application\msedge_proxy.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Queries volume information: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Queries volume information: C:\Windows\Fonts\micross.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\Plat#U0103 revizuit#U0103_shrunk.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\ VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-GroupPolicy-ClientTools-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\Microsoft.Management.Infrastructure.Native\v4.0_1.0.0.0__31bf3856ad364e35\Microsoft.Management.Infrastructure.Native.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\AppvClient\Microsoft.AppV.AppVClientPowerShell.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1865.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-WOW64-Package~31bf3856ad364e35~amd64~en-GB~10.0.19041.1.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\BitLocker\Microsoft.BitLocker.Structures.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management\v4.0_3.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Management.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\ VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-AppManagement-AppV-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\Microsoft.Management.Infrastructure.Native\v4.0_1.0.0.0__31bf3856ad364e35\Microsoft.Management.Infrastructure.Native.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\AppvClient\Microsoft.AppV.AppVClientPowerShell.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1865.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-WOW64-Package~31bf3856ad364e35~amd64~en-GB~10.0.19041.1.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\BitLocker\Microsoft.BitLocker.Structures.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management\v4.0_3.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Management.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\iKHPXKiqI.exe | Queries volume information: C:\Users\user\AppData\Roaming\iKHPXKiqI.exe VolumeInformation | |
Source: C:\Users\user\AppData\Roaming\iKHPXKiqI.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation | |
Source: C:\Users\user\AppData\Roaming\iKHPXKiqI.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation | |
Source: C:\Users\user\AppData\Roaming\iKHPXKiqI.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation | |
Source: C:\Users\user\AppData\Roaming\iKHPXKiqI.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation | |