Source: dxdiag.exe, 00000084.00000003.36259067577.00000000061E2000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://OCSP.intel.com/0 |
Source: z1Quotation.scr.exe, 00000082.00000003.35958881929.0000000007431000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.35991087390.0000000007431000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.35968576941.0000000007431000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.35961051808.0000000007431000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.35121830730.000000000742E000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.34025085580.000000000742C000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.35978843989.0000000007431000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.35970951043.0000000007431000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.33996272367.0000000007435000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.33995869114.0000000007435000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.35981100178.0000000007431000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.35988865373.0000000007431000.00000004.00000020.00020000.00000000.sdmp, dxdiag.exe, 00000084.00000003.36286467585.0000000002ACD000.00000004.00000020.00020000.00000000.sdmp, dxdiag.exe, 00000084.00000002.36290061377.0000000002ACD000.00000004.00000020.00020000.00000000.sdmp, dxdiag.exe, 00000084.00000003.36215218240.0000000002ACD000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://crl.comodoca.com/AAACertificateServices.crl06 |
Source: dxdiag.exe, 00000084.00000003.36259067577.00000000061E2000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://crl.comodoca.com/COMODORSACertificationAuthority.crl0q |
Source: z1Quotation.scr.exe, 00000082.00000003.35958881929.0000000007431000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.35991087390.0000000007431000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.35968576941.0000000007431000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.35961051808.0000000007431000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.35121830730.000000000742E000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.34025085580.000000000742C000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.35978843989.0000000007431000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.35970951043.0000000007431000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.33996272367.0000000007435000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.33995869114.0000000007435000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.35981100178.0000000007431000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.35988865373.0000000007431000.00000004.00000020.00020000.00000000.sdmp, dxdiag.exe, 00000084.00000003.36286467585.0000000002ACD000.00000004.00000020.00020000.00000000.sdmp, dxdiag.exe, 00000084.00000002.36290061377.0000000002ACD000.00000004.00000020.00020000.00000000.sdmp, dxdiag.exe, 00000084.00000003.36215218240.0000000002ACD000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://crl.globalsign.net/root-r2.crl0 |
Source: dxdiag.exe, 00000084.00000003.36259067577.00000000061E2000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://crl.quovadisglobal.com/qvicag4.crl0 |
Source: dxdiag.exe, 00000084.00000003.36259067577.00000000061E2000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://crl.quovadisglobal.com/qvrca.crl0 |
Source: z1Quotation.scr.exe, 00000082.00000003.34024760811.0000000007483000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://geoplugin.net/ |
Source: z1Quotation.scr.exe, 00000082.00000003.35958881929.0000000007431000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.35122151040.0000000007489000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.35991087390.0000000007431000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.35968576941.0000000007431000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.35961051808.0000000007431000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.35121830730.000000000742E000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.34024760811.0000000007483000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.34025085580.000000000742C000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.35978843989.0000000007431000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.35970951043.0000000007431000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.35959037232.00000000073DF000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.34024760811.0000000007487000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.35121905251.0000000007487000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.35121957679.00000000073E0000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.35981100178.0000000007431000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.35988865373.0000000007431000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://geoplugin.net/json.gp |
Source: z1Quotation.scr.exe, 00000082.00000003.35958881929.0000000007431000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.35991087390.0000000007431000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.35968576941.0000000007431000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.35961051808.0000000007431000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.35121830730.000000000742E000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.34025085580.000000000742C000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.35978843989.0000000007431000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.35970951043.0000000007431000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.35981100178.0000000007431000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.35988865373.0000000007431000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://geoplugin.net/json.gpB_ |
Source: z1Quotation.scr.exe, 00000082.00000003.35958881929.0000000007431000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.35991087390.0000000007431000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.35968576941.0000000007431000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.35961051808.0000000007431000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.35121830730.000000000742E000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.34025085580.000000000742C000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.35978843989.0000000007431000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.35970951043.0000000007431000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.35981100178.0000000007431000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.35988865373.0000000007431000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://geoplugin.net/json.gpH_ |
Source: z1Quotation.scr.exe, 00000082.00000003.35121830730.000000000742E000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.34025085580.000000000742C000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://geoplugin.net/json.gpM |
Source: z1Quotation.scr.exe, 00000082.00000003.35958881929.0000000007431000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.35991087390.0000000007431000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.35968576941.0000000007431000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.35961051808.0000000007431000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.35121830730.000000000742E000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.34025085580.000000000742C000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.35978843989.0000000007431000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.35970951043.0000000007431000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.35981100178.0000000007431000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.35988865373.0000000007431000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://geoplugin.net/json.gpV_0 |
Source: z1Quotation.scr.exe, 00000082.00000003.35121830730.000000000742E000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.34025085580.000000000742C000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://geoplugin.net/json.gpn.net/json.gp |
Source: z1Quotation.scr.exe, 00000082.00000003.35958881929.0000000007431000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.35991087390.0000000007431000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.35968576941.0000000007431000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.35961051808.0000000007431000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.35121830730.000000000742E000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.34025085580.000000000742C000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.35978843989.0000000007431000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.35970951043.0000000007431000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.35981100178.0000000007431000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.35988865373.0000000007431000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://geoplugin.net/json.gpo_ |
Source: z1Quotation.scr.exe, 00000082.00000003.35958881929.0000000007431000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.35991087390.0000000007431000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.35968576941.0000000007431000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.35961051808.0000000007431000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.35121830730.000000000742E000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.34025085580.000000000742C000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.35978843989.0000000007431000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.35970951043.0000000007431000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.35981100178.0000000007431000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.35988865373.0000000007431000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://geoplugin.net/json.gpsg |
Source: z1Quotation.scr.exe, z1Quotation.scr.exe, 00000000.00000000.32405926725.000000000040A000.00000008.00000001.01000000.00000003.sdmp, z1Quotation.scr.exe, 00000000.00000002.33493288992.000000000040A000.00000004.00000001.01000000.00000003.sdmp, z1Quotation.scr.exe, 00000082.00000000.32835780083.000000000040A000.00000008.00000001.01000000.00000003.sdmp |
String found in binary or memory: http://nsis.sf.net/NSIS_Error |
Source: z1Quotation.scr.exe, 00000000.00000000.32405926725.000000000040A000.00000008.00000001.01000000.00000003.sdmp, z1Quotation.scr.exe, 00000000.00000002.33493288992.000000000040A000.00000004.00000001.01000000.00000003.sdmp, z1Quotation.scr.exe, 00000082.00000000.32835780083.000000000040A000.00000008.00000001.01000000.00000003.sdmp |
String found in binary or memory: http://nsis.sf.net/NSIS_ErrorError |
Source: dxdiag.exe, 00000084.00000003.36259067577.00000000061E2000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://ocsp.comodoca.com05 |
Source: dxdiag.exe, 00000084.00000003.36259067577.00000000061E2000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://ocsp.quovadisglobal.com05 |
Source: dxdiag.exe, 00000084.00000003.36259067577.00000000061E2000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://ocsp.quovadisglobal.com0O |
Source: dxdiag.exe, 00000084.00000003.36259067577.00000000061E2000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://pki.intel.com/crl/IntelCA7B.crl0f |
Source: dxdiag.exe, 00000084.00000003.36259067577.00000000061E2000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://pki.intel.com/crt/IntelCA7B.crt0 |
Source: dxdiag.exe, 00000084.00000003.36259067577.00000000061E2000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://trust.quovadisglobal.com/qvicag4.crt0 |
Source: dxdiag.exe, 00000084.00000003.36259067577.00000000061E2000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://trust.quovadisglobal.com/qvrca.crt0 |
Source: z1Quotation.scr.exe |
String found in binary or memory: http://www.ebuddy.com |
Source: z1Quotation.scr.exe |
String found in binary or memory: http://www.imvu.com |
Source: z1Quotation.scr.exe |
String found in binary or memory: http://www.nirsoft.net/ |
Source: z1Quotation.scr.exe, 00000082.00000003.35958881929.0000000007431000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.35991087390.0000000007431000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.35968576941.0000000007431000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.35961051808.0000000007431000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.35121830730.000000000742E000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.34025085580.000000000742C000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.35978843989.0000000007431000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.35970951043.0000000007431000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.33996272367.0000000007435000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.33995869114.0000000007435000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.35981100178.0000000007431000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.35988865373.0000000007431000.00000004.00000020.00020000.00000000.sdmp, dxdiag.exe, 00000084.00000003.36286467585.0000000002ACD000.00000004.00000020.00020000.00000000.sdmp, dxdiag.exe, 00000084.00000002.36290061377.0000000002ACD000.00000004.00000020.00020000.00000000.sdmp, dxdiag.exe, 00000084.00000003.36215218240.0000000002ACD000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://www.quovadis.bm0 |
Source: dxdiag.exe, 00000084.00000003.36259067577.00000000061E2000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://www.quovadisglobal.com/repository0 |
Source: z1Quotation.scr.exe |
String found in binary or memory: https://login.yahoo.com/config/login |
Source: z1Quotation.scr.exe, 00000082.00000003.35958881929.0000000007431000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.35991087390.0000000007431000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.35968576941.0000000007431000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.35961051808.0000000007431000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.35121830730.000000000742E000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.34025085580.000000000742C000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.35978843989.0000000007431000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.35970951043.0000000007431000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.33996272367.0000000007435000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.33995869114.0000000007435000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.35981100178.0000000007431000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.35988865373.0000000007431000.00000004.00000020.00020000.00000000.sdmp, dxdiag.exe, 00000084.00000003.36286467585.0000000002ACD000.00000004.00000020.00020000.00000000.sdmp, dxdiag.exe, 00000084.00000002.36290061377.0000000002ACD000.00000004.00000020.00020000.00000000.sdmp, dxdiag.exe, 00000084.00000003.36215218240.0000000002ACD000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://ocsp.quovadisoffshore.com0 |
Source: z1Quotation.scr.exe, 00000082.00000003.33541985946.00000000073DF000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.35968794940.00000000073DF000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.35959037232.00000000073DF000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.35979025881.00000000073DF000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.33236979197.00000000073FC000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.33542108978.00000000073FF000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.35989039555.00000000073DF000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.35121957679.00000000073E0000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://telesavers.co.za/ |
Source: z1Quotation.scr.exe, 00000082.00000003.33541985946.00000000073F7000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.33236979197.00000000073FC000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.33542108978.00000000073FF000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://telesavers.co.za/( |
Source: z1Quotation.scr.exe, 00000082.00000003.33236979197.00000000073FC000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://telesavers.co.za/) |
Source: z1Quotation.scr.exe, 00000082.00000003.33237027260.00000000073DF000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.33541985946.00000000073DF000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://telesavers.co.za/-4062-986e-6b0fce555694 |
Source: z1Quotation.scr.exe, 00000082.00000003.33541985946.00000000073DF000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://telesavers.co.za/-4062-986e-6b0fce555694s |
Source: z1Quotation.scr.exe, 00000082.00000003.33541985946.00000000073DF000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://telesavers.co.za/-4062-986e-6b0fce555694sDN |
Source: z1Quotation.scr.exe, 00000082.00000003.33237027260.00000000073DF000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.33541985946.00000000073DF000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://telesavers.co.za/Bo |
Source: z1Quotation.scr.exe, 00000082.00000003.33541893342.0000000007415000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.33542108978.00000000073FF000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.35968794940.0000000007415000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://telesavers.co.za/FrKSUMZ203.bin |
Source: z1Quotation.scr.exe, 00000082.00000003.33541985946.00000000073F7000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.33542108978.00000000073FF000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://telesavers.co.za/FrKSUMZ203.binAppData |
Source: z1Quotation.scr.exe, 00000082.00000003.33541985946.00000000073F7000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.33236810978.0000000007415000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.33236979197.00000000073FC000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.33541893342.0000000007415000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.33542108978.00000000073FF000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://telesavers.co.za/FrKSUMZ203.binI |
Source: z1Quotation.scr.exe, 00000082.00000003.33236810978.0000000007415000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.33541893342.0000000007415000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://telesavers.co.za/FrKSUMZ203.binc |
Source: z1Quotation.scr.exe, 00000082.00000003.33541985946.00000000073F7000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.33236979197.00000000073FC000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.33542108978.00000000073FF000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://telesavers.co.za/FrKSUMZ203.binrasadhlp.dll |
Source: z1Quotation.scr.exe, 00000082.00000003.33237027260.00000000073DF000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.33541985946.00000000073DF000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://telesavers.co.za/Jo |
Source: z1Quotation.scr.exe, 00000082.00000003.33541985946.00000000073F7000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.33236979197.00000000073FC000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.33542108978.00000000073FF000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://telesavers.co.za/Tt |
Source: z1Quotation.scr.exe, 00000082.00000003.33541985946.00000000073DF000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://telesavers.co.za/bo |
Source: z1Quotation.scr.exe, 00000082.00000003.33541985946.00000000073F7000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.33542108978.00000000073FF000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://telesavers.co.za/telesavers.co.za |
Source: z1Quotation.scr.exe, 00000082.00000003.33541985946.00000000073F7000.00000004.00000020.00020000.00000000.sdmp, z1Quotation.scr.exe, 00000082.00000003.33542108978.00000000073FF000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://telesavers.co.za/telesavers.co.za5 |
Source: z1Quotation.scr.exe |
String found in binary or memory: https://www.google.com |
Source: z1Quotation.scr.exe |
String found in binary or memory: https://www.google.com/accounts/servicelogin |
Source: unknown |
Process created: C:\Users\user\Desktop\z1Quotation.scr.exe "C:\Users\user\Desktop\z1Quotation.scr.exe" |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "250^177" |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "244^177" |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "227^177" |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "255^177" |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "244^177" |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "253^177" |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "130^177" |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "131^177" |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "139^177" |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "139^177" |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "242^177" |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "208^177" |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "197^177" |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "216^177" |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "221^177" |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "212^177" |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "240^177" |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "153^177" |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "220^177" |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "145^177" |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "195^177" |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "133^177" |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "145^177" |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "157^177" |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "145^177" |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "216^177" |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "201^177" |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "137^177" |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "129^177" |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "129^177" |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "129^177" |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "129^177" |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "129^177" |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "129^177" |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "129^177" |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "157^177" |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "145^177" |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "216^177" |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "145^177" |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "145^177" |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "129^177" |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "145^177" |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "216^177" |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "145^177" |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "157^177" |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "145^177" |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "216^177" |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "145^177" |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "129^177" |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "201^177" |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "129^177" |
|
Source: C:\Windows\SysWOW64\cmd.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Users\user\Desktop\z1Quotation.scr.exe "C:\Users\user\Desktop\z1Quotation.scr.exe" |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\dxdiag.exe "C:\Windows\System32\dxdiag.exe" /t C:\Users\user\AppData\Local\Temp\sysinfo.txt |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Users\user\Desktop\z1Quotation.scr.exe C:\Users\user\Desktop\z1Quotation.scr.exe /stext "C:\Users\user\AppData\Local\Temp\jcokhfyxinncnfcgtxknzv" |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Users\user\Desktop\z1Quotation.scr.exe C:\Users\user\Desktop\z1Quotation.scr.exe /stext "C:\Users\user\AppData\Local\Temp\hhsvynxt" |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Users\user\Desktop\z1Quotation.scr.exe C:\Users\user\Desktop\z1Quotation.scr.exe /stext "C:\Users\user\AppData\Local\Temp\pqvxpoqshoxjfvzq" |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Users\user\Desktop\z1Quotation.scr.exe C:\Users\user\Desktop\z1Quotation.scr.exe /sort "Visit Time" /stext "C:\Users\user\AppData\Local\Temp\azdzamjeqinayzgxunqjk" |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\WerFault.exe C:\Windows\SysWOW64\WerFault.exe -u -p 1412 -s 2348 |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Users\user\Desktop\z1Quotation.scr.exe C:\Users\user\Desktop\z1Quotation.scr.exe /stext "C:\Users\user\AppData\Local\Temp\xadmhfv" |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Users\user\Desktop\z1Quotation.scr.exe C:\Users\user\Desktop\z1Quotation.scr.exe /stext "C:\Users\user\AppData\Local\Temp\xpsjxjoeplzrro" |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Users\user\Desktop\z1Quotation.scr.exe C:\Users\user\Desktop\z1Quotation.scr.exe /stext "C:\Users\user\AppData\Local\Temp\gymlnlyltcmojzwgtmnvsm" |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "250^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "244^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "227^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "255^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "244^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "253^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "130^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "131^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "139^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "139^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "242^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "255^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "244^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "208^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "197^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "131^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "139^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "216^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "221^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "212^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "240^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "153^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "220^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "145^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "195^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "133^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "145^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "157^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "145^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "139^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "195^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "137^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "129^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "129^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "129^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "129^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "195^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "137^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "129^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "129^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "133^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "145^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "145^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "157^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "145^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "145^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "201^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "145^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "157^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "137^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "129^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "157^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "255^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "244^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "145^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "145^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "129^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "137^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "220^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "145^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "255^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "244^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Users\user\Desktop\z1Quotation.scr.exe C:\Users\user\Desktop\z1Quotation.scr.exe /sort "Visit Time" /stext "C:\Users\user\AppData\Local\Temp\azdzamjeqinayzgxunqjk" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "145^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "129^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "133^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "221^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "157^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Users\user\Desktop\z1Quotation.scr.exe C:\Users\user\Desktop\z1Quotation.scr.exe /stext "C:\Users\user\AppData\Local\Temp\xpsjxjoeplzrro" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "145^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "137^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "129^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "157^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "130^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "145^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "145^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "129^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "129^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "131^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "201^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "221^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "129^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Users\user\Desktop\z1Quotation.scr.exe "C:\Users\user\Desktop\z1Quotation.scr.exe" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\dxdiag.exe "C:\Windows\System32\dxdiag.exe" /t C:\Users\user\AppData\Local\Temp\sysinfo.txt |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Users\user\Desktop\z1Quotation.scr.exe C:\Users\user\Desktop\z1Quotation.scr.exe /stext "C:\Users\user\AppData\Local\Temp\jcokhfyxinncnfcgtxknzv" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Users\user\Desktop\z1Quotation.scr.exe C:\Users\user\Desktop\z1Quotation.scr.exe /stext "C:\Users\user\AppData\Local\Temp\hhsvynxt" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Users\user\Desktop\z1Quotation.scr.exe C:\Users\user\Desktop\z1Quotation.scr.exe /stext "C:\Users\user\AppData\Local\Temp\pqvxpoqshoxjfvzq" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Users\user\Desktop\z1Quotation.scr.exe C:\Users\user\Desktop\z1Quotation.scr.exe /sort "Visit Time" /stext "C:\Users\user\AppData\Local\Temp\azdzamjeqinayzgxunqjk" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Users\user\Desktop\z1Quotation.scr.exe C:\Users\user\Desktop\z1Quotation.scr.exe /stext "C:\Users\user\AppData\Local\Temp\xadmhfv" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Users\user\Desktop\z1Quotation.scr.exe C:\Users\user\Desktop\z1Quotation.scr.exe /stext "C:\Users\user\AppData\Local\Temp\xpsjxjoeplzrro" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Users\user\Desktop\z1Quotation.scr.exe C:\Users\user\Desktop\z1Quotation.scr.exe /stext "C:\Users\user\AppData\Local\Temp\gymlnlyltcmojzwgtmnvsm" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: edgegdi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: propsys.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: dwmapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: cryptbase.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: oleacc.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: ntmarta.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: shfolder.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: riched20.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: usp10.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: msls31.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: textinputframework.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: coreuicomponents.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: coremessaging.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: coremessaging.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: textshaping.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: edgegdi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: wininet.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: iertutil.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: ondemandconnroutehelper.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: winhttp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: mswsock.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: iphlpapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: winnsi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: urlmon.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: srvcli.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: netutils.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: dnsapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: rasadhlp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: fwpuclnt.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: schannel.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: mskeyprotect.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: ntasn1.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: msasn1.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: dpapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: cryptsp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: rsaenh.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: cryptbase.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: gpapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: ncrypt.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: ncryptsslp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: winmm.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: rstrtmgr.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: windowscodecs.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: propsys.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: edputil.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: windows.staterepositoryps.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: appresolver.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: bcp47langs.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: slc.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: sppc.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: onecorecommonproxystub.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: onecoreuapcommonproxystub.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\dxdiag.exe |
Section loaded: edgegdi.dll |
|
Source: C:\Windows\SysWOW64\dxdiag.exe |
Section loaded: kernel.appcore.dll |
|
Source: C:\Windows\SysWOW64\dxdiag.exe |
Section loaded: uxtheme.dll |
|
Source: C:\Windows\SysWOW64\dxdiag.exe |
Section loaded: dxdiagn.dll |
|
Source: C:\Windows\SysWOW64\dxdiag.exe |
Section loaded: d3d11.dll |
|
Source: C:\Windows\SysWOW64\dxdiag.exe |
Section loaded: d3d12.dll |
|
Source: C:\Windows\SysWOW64\dxdiag.exe |
Section loaded: cryptsp.dll |
|
Source: C:\Windows\SysWOW64\dxdiag.exe |
Section loaded: powrprof.dll |
|
Source: C:\Windows\SysWOW64\dxdiag.exe |
Section loaded: devobj.dll |
|
Source: C:\Windows\SysWOW64\dxdiag.exe |
Section loaded: winmmbase.dll |
|
Source: C:\Windows\SysWOW64\dxdiag.exe |
Section loaded: dxgi.dll |
|
Source: C:\Windows\SysWOW64\dxdiag.exe |
Section loaded: wmiclnt.dll |
|
Source: C:\Windows\SysWOW64\dxdiag.exe |
Section loaded: umpdc.dll |
|
Source: C:\Windows\SysWOW64\dxdiag.exe |
Section loaded: msasn1.dll |
|
Source: C:\Windows\SysWOW64\dxdiag.exe |
Section loaded: wbemcomn.dll |
|
Source: C:\Windows\SysWOW64\dxdiag.exe |
Section loaded: amsi.dll |
|
Source: C:\Windows\SysWOW64\dxdiag.exe |
Section loaded: userenv.dll |
|
Source: C:\Windows\SysWOW64\dxdiag.exe |
Section loaded: profapi.dll |
|
Source: C:\Windows\SysWOW64\dxdiag.exe |
Section loaded: version.dll |
|
Source: C:\Windows\SysWOW64\dxdiag.exe |
Section loaded: winbrand.dll |
|
Source: C:\Windows\SysWOW64\dxdiag.exe |
Section loaded: wldp.dll |
|
Source: C:\Windows\SysWOW64\dxdiag.exe |
Section loaded: windows.storage.dll |
|
Source: C:\Windows\SysWOW64\dxdiag.exe |
Section loaded: wldp.dll |
|
Source: C:\Windows\SysWOW64\dxdiag.exe |
Section loaded: dsound.dll |
|
Source: C:\Windows\SysWOW64\dxdiag.exe |
Section loaded: resourcepolicyclient.dll |
|
Source: C:\Windows\SysWOW64\dxdiag.exe |
Section loaded: devrtl.dll |
|
Source: C:\Windows\SysWOW64\dxdiag.exe |
Section loaded: spinf.dll |
|
Source: C:\Windows\SysWOW64\dxdiag.exe |
Section loaded: drvstore.dll |
|
Source: C:\Windows\SysWOW64\dxdiag.exe |
Section loaded: rsaenh.dll |
|
Source: C:\Windows\SysWOW64\dxdiag.exe |
Section loaded: cryptbase.dll |
|
Source: C:\Windows\SysWOW64\dxdiag.exe |
Section loaded: gpapi.dll |
|
Source: C:\Windows\SysWOW64\dxdiag.exe |
Section loaded: wifidisplay.dll |
|
Source: C:\Windows\SysWOW64\dxdiag.exe |
Section loaded: sspicli.dll |
|
Source: C:\Windows\SysWOW64\dxdiag.exe |
Section loaded: dnsapi.dll |
|
Source: C:\Windows\SysWOW64\dxdiag.exe |
Section loaded: iphlpapi.dll |
|
Source: C:\Windows\SysWOW64\dxdiag.exe |
Section loaded: mswsock.dll |
|
Source: C:\Windows\SysWOW64\dxdiag.exe |
Section loaded: wlanapi.dll |
|
Source: C:\Windows\SysWOW64\dxdiag.exe |
Section loaded: mmdevapi.dll |
|
Source: C:\Windows\SysWOW64\dxdiag.exe |
Section loaded: mfplat.dll |
|
Source: C:\Windows\SysWOW64\dxdiag.exe |
Section loaded: rtworkq.dll |
|
Source: C:\Windows\SysWOW64\dxdiag.exe |
Section loaded: mf.dll |
|
Source: C:\Windows\SysWOW64\dxdiag.exe |
Section loaded: mfcore.dll |
|
Source: C:\Windows\SysWOW64\dxdiag.exe |
Section loaded: ksuser.dll |
|
Source: C:\Windows\SysWOW64\dxdiag.exe |
Section loaded: mfperfhelper.dll |
|
Source: C:\Windows\SysWOW64\dxdiag.exe |
Section loaded: mfsensorgroup.dll |
|
Source: C:\Windows\SysWOW64\dxdiag.exe |
Section loaded: comppkgsup.dll |
|
Source: C:\Windows\SysWOW64\dxdiag.exe |
Section loaded: windows.media.dll |
|
Source: C:\Windows\SysWOW64\dxdiag.exe |
Section loaded: windows.applicationmodel.dll |
|
Source: C:\Windows\SysWOW64\dxdiag.exe |
Section loaded: twinapi.appcore.dll |
|
Source: C:\Windows\SysWOW64\dxdiag.exe |
Section loaded: appxdeploymentclient.dll |
|
Source: C:\Windows\SysWOW64\dxdiag.exe |
Section loaded: windows.staterepositoryps.dll |
|
Source: C:\Windows\SysWOW64\dxdiag.exe |
Section loaded: wintypes.dll |
|
Source: C:\Windows\SysWOW64\dxdiag.exe |
Section loaded: dispbroker.dll |
|
Source: C:\Windows\SysWOW64\dxdiag.exe |
Section loaded: d3d12core.dll |
|
Source: C:\Windows\SysWOW64\dxdiag.exe |
Section loaded: dxcore.dll |
|
Source: C:\Windows\SysWOW64\dxdiag.exe |
Section loaded: d3dscache.dll |
|
Source: C:\Windows\SysWOW64\dxdiag.exe |
Section loaded: dxilconv.dll |
|
Source: C:\Windows\SysWOW64\dxdiag.exe |
Section loaded: ncrypt.dll |
|
Source: C:\Windows\SysWOW64\dxdiag.exe |
Section loaded: ntasn1.dll |
|
Source: C:\Windows\SysWOW64\dxdiag.exe |
Section loaded: ncrypt.dll |
|
Source: C:\Windows\SysWOW64\dxdiag.exe |
Section loaded: ntasn1.dll |
|
Source: C:\Windows\SysWOW64\dxdiag.exe |
Section loaded: ncrypt.dll |
|
Source: C:\Windows\SysWOW64\dxdiag.exe |
Section loaded: ntasn1.dll |
|
Source: C:\Windows\SysWOW64\dxdiag.exe |
Section loaded: ncrypt.dll |
|
Source: C:\Windows\SysWOW64\dxdiag.exe |
Section loaded: ntasn1.dll |
|
Source: C:\Windows\SysWOW64\dxdiag.exe |
Section loaded: ncrypt.dll |
|
Source: C:\Windows\SysWOW64\dxdiag.exe |
Section loaded: ntasn1.dll |
|
Source: C:\Windows\SysWOW64\dxdiag.exe |
Section loaded: ncrypt.dll |
|
Source: C:\Windows\SysWOW64\dxdiag.exe |
Section loaded: ntasn1.dll |
|
Source: C:\Windows\SysWOW64\dxdiag.exe |
Section loaded: ncrypt.dll |
|
Source: C:\Windows\SysWOW64\dxdiag.exe |
Section loaded: ntasn1.dll |
|
Source: C:\Windows\SysWOW64\dxdiag.exe |
Section loaded: ncrypt.dll |
|
Source: C:\Windows\SysWOW64\dxdiag.exe |
Section loaded: ntasn1.dll |
|
Source: C:\Windows\SysWOW64\dxdiag.exe |
Section loaded: ncrypt.dll |
|
Source: C:\Windows\SysWOW64\dxdiag.exe |
Section loaded: ntasn1.dll |
|
Source: C:\Windows\SysWOW64\dxdiag.exe |
Section loaded: d3d9.dll |
|
Source: C:\Windows\SysWOW64\dxdiag.exe |
Section loaded: dwmapi.dll |
|
Source: C:\Windows\SysWOW64\dxdiag.exe |
Section loaded: mscat32.dll |
|
Source: C:\Windows\SysWOW64\dxdiag.exe |
Section loaded: d3d9.dll |
|
Source: C:\Windows\SysWOW64\dxdiag.exe |
Section loaded: dwmapi.dll |
|
Source: C:\Windows\SysWOW64\dxdiag.exe |
Section loaded: ddraw.dll |
|
Source: C:\Windows\SysWOW64\dxdiag.exe |
Section loaded: dciman32.dll |
|
Source: C:\Windows\SysWOW64\dxdiag.exe |
Section loaded: audioses.dll |
|
Source: C:\Windows\SysWOW64\dxdiag.exe |
Section loaded: resourcepolicyclient.dll |
|
Source: C:\Windows\SysWOW64\dxdiag.exe |
Section loaded: dinput8.dll |
|
Source: C:\Windows\SysWOW64\dxdiag.exe |
Section loaded: inputhost.dll |
|
Source: C:\Windows\SysWOW64\dxdiag.exe |
Section loaded: coremessaging.dll |
|
Source: C:\Windows\SysWOW64\dxdiag.exe |
Section loaded: propsys.dll |
|
Source: C:\Windows\SysWOW64\dxdiag.exe |
Section loaded: coreuicomponents.dll |
|
Source: C:\Windows\SysWOW64\dxdiag.exe |
Section loaded: ntmarta.dll |
|
Source: C:\Windows\SysWOW64\dxdiag.exe |
Section loaded: hid.dll |
|
Source: C:\Windows\SysWOW64\dxdiag.exe |
Section loaded: winmm.dll |
|
Source: C:\Windows\SysWOW64\dxdiag.exe |
Section loaded: devenum.dll |
|
Source: C:\Windows\SysWOW64\dxdiag.exe |
Section loaded: msdmo.dll |
|
Source: C:\Windows\SysWOW64\dxdiag.exe |
Section loaded: quartz.dll |
|
Source: C:\Windows\SysWOW64\dxdiag.exe |
Section loaded: d3d9.dll |
|
Source: C:\Windows\SysWOW64\dxdiag.exe |
Section loaded: dwmapi.dll |
|
Source: C:\Windows\SysWOW64\dxdiag.exe |
Section loaded: msvfw32.dll |
|
Source: C:\Windows\SysWOW64\dxdiag.exe |
Section loaded: iccvid.dll |
|
Source: C:\Windows\SysWOW64\dxdiag.exe |
Section loaded: iyuv_32.dll |
|
Source: C:\Windows\SysWOW64\dxdiag.exe |
Section loaded: iyuv_32.dll |
|
Source: C:\Windows\SysWOW64\dxdiag.exe |
Section loaded: msrle32.dll |
|
Source: C:\Windows\SysWOW64\dxdiag.exe |
Section loaded: msvidc32.dll |
|
Source: C:\Windows\SysWOW64\dxdiag.exe |
Section loaded: msyuv.dll |
|
Source: C:\Windows\SysWOW64\dxdiag.exe |
Section loaded: msyuv.dll |
|
Source: C:\Windows\SysWOW64\dxdiag.exe |
Section loaded: tsbyuv.dll |
|
Source: C:\Windows\SysWOW64\dxdiag.exe |
Section loaded: msyuv.dll |
|
Source: C:\Windows\SysWOW64\dxdiag.exe |
Section loaded: msacm32.dll |
|
Source: C:\Windows\SysWOW64\dxdiag.exe |
Section loaded: avrt.dll |
|
Source: C:\Windows\SysWOW64\dxdiag.exe |
Section loaded: msacm32.dll |
|
Source: C:\Windows\SysWOW64\dxdiag.exe |
Section loaded: midimap.dll |
|
Source: C:\Windows\SysWOW64\dxdiag.exe |
Section loaded: avicap32.dll |
|
Source: C:\Windows\SysWOW64\dxdiag.exe |
Section loaded: msvfw32.dll |
|
Source: C:\Windows\SysWOW64\dxdiag.exe |
Section loaded: spfileq.dll |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: version.dll |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: wininet.dll |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: edgegdi.dll |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: windows.storage.dll |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: wldp.dll |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: cryptsp.dll |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: rsaenh.dll |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: cryptbase.dll |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: pstorec.dll |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: vaultcli.dll |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: wintypes.dll |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: dpapi.dll |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: msasn1.dll |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: edgegdi.dll |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: windows.storage.dll |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: wldp.dll |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: pstorec.dll |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: sspicli.dll |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: msasn1.dll |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: msasn1.dll |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: edgegdi.dll |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: windows.storage.dll |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: wldp.dll |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: msasn1.dll |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: sspicli.dll |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: cryptsp.dll |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: rsaenh.dll |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: cryptbase.dll |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: version.dll |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: wininet.dll |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: edgegdi.dll |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: kernel.appcore.dll |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: uxtheme.dll |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: userenv.dll |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: profapi.dll |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: windows.storage.dll |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: wldp.dll |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: version.dll |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: wininet.dll |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: edgegdi.dll |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: windows.storage.dll |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: wldp.dll |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: cryptsp.dll |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: rsaenh.dll |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: cryptbase.dll |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: pstorec.dll |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: vaultcli.dll |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: wintypes.dll |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: dpapi.dll |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: msasn1.dll |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: edgegdi.dll |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: windows.storage.dll |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: wldp.dll |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: pstorec.dll |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: sspicli.dll |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: msasn1.dll |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: msasn1.dll |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: edgegdi.dll |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: windows.storage.dll |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: wldp.dll |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: msasn1.dll |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: sspicli.dll |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: cryptsp.dll |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: rsaenh.dll |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Section loaded: cryptbase.dll |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "250^177" |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "244^177" |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "227^177" |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "255^177" |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "244^177" |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "253^177" |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "130^177" |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "131^177" |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "139^177" |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "139^177" |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "242^177" |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "208^177" |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "197^177" |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "216^177" |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "221^177" |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "212^177" |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "240^177" |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "153^177" |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "220^177" |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "145^177" |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "195^177" |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "133^177" |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "145^177" |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "157^177" |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "145^177" |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "216^177" |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "201^177" |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "137^177" |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "129^177" |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "129^177" |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "129^177" |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "129^177" |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "129^177" |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "129^177" |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "129^177" |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "157^177" |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "145^177" |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "216^177" |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "145^177" |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "145^177" |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "129^177" |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "145^177" |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "216^177" |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "145^177" |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "157^177" |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "145^177" |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "216^177" |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "145^177" |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "129^177" |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "201^177" |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "129^177" |
|
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "250^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "244^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "227^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "255^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "244^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "253^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "130^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "131^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "139^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "139^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "242^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "255^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "244^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "208^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "197^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "131^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "139^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "216^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "221^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "212^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "240^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "153^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "220^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "145^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "195^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "133^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "145^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "157^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "145^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "139^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "195^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "137^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "129^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "129^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "129^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "129^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "195^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "137^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "129^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "129^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "133^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "145^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "145^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "157^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "145^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "145^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "201^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "145^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "157^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "137^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "129^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "157^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "255^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "244^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "145^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "145^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "129^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "137^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "220^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "145^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "255^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "244^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "145^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "129^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "133^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "221^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "157^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "145^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "137^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "129^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "157^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "130^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "145^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "145^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "129^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "129^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "131^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "201^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "221^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "129^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "250^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "244^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "227^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "255^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "244^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "253^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "130^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "131^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "139^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "139^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "242^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "255^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "244^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "208^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "197^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "131^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "139^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "216^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "221^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "212^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "240^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "153^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "220^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "145^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "195^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "133^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "145^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "157^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "145^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "139^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "195^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "137^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "129^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "129^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "129^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "129^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "195^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "137^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "129^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "129^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "133^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "145^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "145^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "157^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "145^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "145^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "201^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "145^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "157^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "137^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "129^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "157^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "255^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "244^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "145^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "145^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "129^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "137^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "220^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "145^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "255^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "244^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Users\user\Desktop\z1Quotation.scr.exe C:\Users\user\Desktop\z1Quotation.scr.exe /sort "Visit Time" /stext "C:\Users\user\AppData\Local\Temp\azdzamjeqinayzgxunqjk" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "145^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "129^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "133^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "221^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "157^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Users\user\Desktop\z1Quotation.scr.exe C:\Users\user\Desktop\z1Quotation.scr.exe /stext "C:\Users\user\AppData\Local\Temp\xpsjxjoeplzrro" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "145^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "137^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "129^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "157^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "130^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "145^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "145^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "129^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "129^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "131^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "201^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "221^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\System32\Conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c set /a "129^177" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Users\user\Desktop\z1Quotation.scr.exe "C:\Users\user\Desktop\z1Quotation.scr.exe" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Windows\SysWOW64\dxdiag.exe "C:\Windows\System32\dxdiag.exe" /t C:\Users\user\AppData\Local\Temp\sysinfo.txt |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Users\user\Desktop\z1Quotation.scr.exe C:\Users\user\Desktop\z1Quotation.scr.exe /stext "C:\Users\user\AppData\Local\Temp\jcokhfyxinncnfcgtxknzv" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Users\user\Desktop\z1Quotation.scr.exe C:\Users\user\Desktop\z1Quotation.scr.exe /stext "C:\Users\user\AppData\Local\Temp\hhsvynxt" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Users\user\Desktop\z1Quotation.scr.exe C:\Users\user\Desktop\z1Quotation.scr.exe /stext "C:\Users\user\AppData\Local\Temp\pqvxpoqshoxjfvzq" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Users\user\Desktop\z1Quotation.scr.exe C:\Users\user\Desktop\z1Quotation.scr.exe /sort "Visit Time" /stext "C:\Users\user\AppData\Local\Temp\azdzamjeqinayzgxunqjk" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Users\user\Desktop\z1Quotation.scr.exe C:\Users\user\Desktop\z1Quotation.scr.exe /stext "C:\Users\user\AppData\Local\Temp\xadmhfv" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Users\user\Desktop\z1Quotation.scr.exe C:\Users\user\Desktop\z1Quotation.scr.exe /stext "C:\Users\user\AppData\Local\Temp\xpsjxjoeplzrro" |
Jump to behavior |
Source: C:\Users\user\Desktop\z1Quotation.scr.exe |
Process created: C:\Users\user\Desktop\z1Quotation.scr.exe C:\Users\user\Desktop\z1Quotation.scr.exe /stext "C:\Users\user\AppData\Local\Temp\gymlnlyltcmojzwgtmnvsm" |
Jump to behavior |