Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00BB8880 CryptAcquireContextW,VirtualAlloc,GetModuleHandleA,LoadLibraryA,GetProcAddress,CryptReleaseContext,VirtualFree,CryptReleaseContext,VirtualFree, |
0_2_00BB8880 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00BB64F0 CryptAcquireContextW,GetLastError,CryptAcquireContextW,CryptGenKey,CryptExportKey,CryptExportKey,CryptDestroyKey,CryptReleaseContext,CryptAcquireContextW, |
0_2_00BB64F0 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00BB58D0 VirtualAlloc,VirtualFree,CryptBinaryToStringA,CryptBinaryToStringA,CryptBinaryToStringA,lstrlenA,lstrlenA,lstrlenA,VirtualAlloc,lstrlenA,lstrlenA,lstrlenA,lstrlenA,lstrlenA,lstrlenA,lstrcatW,lstrlenW,lstrlenW,lstrlenW,lstrcatW,lstrlenW,lstrcatW,lstrlenW,lstrcatW,lstrlenW,lstrcatW,lstrlenW,lstrcatW,VirtualFree,VirtualFree,VirtualFree,lstrlenW,lstrcatW,lstrlenW,lstrlenW,lstrlenW,lstrlenA,lstrlenW,MultiByteToWideChar,lstrcatW,lstrlenW,lstrlenA,MultiByteToWideChar,lstrcatW,lstrlenW,VirtualAlloc,lstrlenW,lstrlenW,lstrlenW,VirtualFree,lstrlenW,VirtualAlloc,wsprintfA,lstrlenW,CryptBinaryToStringA,GetLastError,lstrlenA,VirtualAlloc,lstrlenA,lstrlenA,lstrlenA,lstrlenA,MultiByteToWideChar,VirtualFree,VirtualFree,VirtualFree,VirtualFree,VirtualFree,VirtualFree,VirtualFree,VirtualFree,VirtualFree,VirtualFree, |
0_2_00BB58D0 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00BB4B30 Sleep,ExitProcess,CreateThread,WaitForSingleObject,TerminateThread,CloseHandle,VirtualAlloc,GetModuleFileNameW,VirtualFree,ExitProcess,Sleep,lstrlenA,VirtualAlloc,CryptStringToBinaryA,ExitProcess,InitializeCriticalSection,DeleteCriticalSection,VirtualAlloc,GetModuleFileNameW,VirtualFree,ShellExecuteW,ExitThread, |
0_2_00BB4B30 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00BB8730 CryptAcquireContextW,VirtualAlloc,GetModuleHandleA,LoadLibraryA,GetProcAddress,CryptReleaseContext,VirtualFree,CryptReleaseContext,VirtualFree, |
0_2_00BB8730 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00BB56A0 VirtualAlloc,wsprintfW,lstrlenW,lstrlenW,lstrlenW,VirtualFree,lstrlenW,VirtualAlloc,wsprintfA,lstrlenW,CryptBinaryToStringA,GetLastError,lstrlenA,lstrlenA,VirtualAlloc,lstrlenA,lstrlenA,lstrlenA,VirtualFree,VirtualFree,VirtualFree,VirtualFree, |
0_2_00BB56A0 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00BB34F0 lstrlenA,VirtualAlloc,VirtualAlloc,CryptStringToBinaryA,VirtualAlloc,VirtualAlloc,wsprintfW,wsprintfW,wsprintfW,VirtualFree, |
0_2_00BB34F0 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00BB5400 lstrlenA,VirtualAlloc,CryptStringToBinaryA,lstrlenA,VirtualAlloc,lstrcpyA,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,VirtualFree,GetLastError,lstrlenA,VirtualAlloc,VirtualAlloc,VirtualAlloc,lstrcatA,lstrlenA,lstrlenW,lstrlenA,VirtualFree,VirtualFree,VirtualFree,VirtualFree,InternetCloseHandle, |
0_2_00BB5400 |
Source: C:\Users\user\Desktop\file.exe |
Code function: 0_2_00BB6770 EnterCriticalSection,CryptAcquireContextW,GetLastError,CryptAcquireContextW,LeaveCriticalSection,LeaveCriticalSection,CryptImportKey,CryptGetKeyParam,CryptEncrypt,GetLastError,CryptReleaseContext,LeaveCriticalSection, |
0_2_00BB6770 |
Source: C:\Users\user\AppData\Roaming\Microsoft\dwqocx.exe |
Code function: 15_2_00F94B30 Sleep,ExitProcess,CreateThread,WaitForSingleObject,TerminateThread,CloseHandle,VirtualAlloc,GetModuleFileNameW,VirtualFree,ExitProcess,Sleep,lstrlenA,VirtualAlloc,CryptStringToBinaryA,ExitProcess,InitializeCriticalSection,DeleteCriticalSection,VirtualAlloc,GetModuleFileNameW,VirtualFree,ShellExecuteW,ExitThread, |
15_2_00F94B30 |
Source: C:\Users\user\AppData\Roaming\Microsoft\dwqocx.exe |
Code function: 15_2_00F964F0 CryptAcquireContextW,GetLastError,CryptAcquireContextW,CryptGenKey,CryptExportKey,CryptExportKey,CryptDestroyKey,CryptReleaseContext,CryptAcquireContextW, |
15_2_00F964F0 |
Source: C:\Users\user\AppData\Roaming\Microsoft\dwqocx.exe |
Code function: 15_2_00F934F0 lstrlenA,VirtualAlloc,VirtualAlloc,CryptStringToBinaryA,VirtualAlloc,VirtualAlloc,wsprintfW,wsprintfW,wsprintfW,VirtualFree, |
15_2_00F934F0 |
Source: C:\Users\user\AppData\Roaming\Microsoft\dwqocx.exe |
Code function: 15_2_00F958D0 VirtualAlloc,VirtualFree,CryptBinaryToStringA,CryptBinaryToStringA,CryptBinaryToStringA,lstrlenA,lstrlenA,lstrlenA,VirtualAlloc,lstrlenA,lstrlenA,lstrlenA,lstrlenA,lstrlenA,lstrlenA,lstrcatW,lstrlenW,lstrlenW,lstrlenW,lstrcatW,lstrlenW,lstrcatW,lstrlenW,lstrcatW,lstrlenW,lstrcatW,lstrlenW,lstrcatW,VirtualFree,VirtualFree,VirtualFree,lstrlenW,lstrcatW,lstrlenW,lstrlenW,lstrlenW,lstrlenA,lstrlenW,MultiByteToWideChar,lstrcatW,lstrlenW,lstrlenA,MultiByteToWideChar,lstrcatW,lstrlenW,VirtualAlloc,lstrlenW,lstrlenW,lstrlenW,VirtualFree,lstrlenW,VirtualAlloc,wsprintfA,lstrlenW,CryptBinaryToStringA,GetLastError,lstrlenA,VirtualAlloc,lstrlenA,lstrlenA,lstrlenA,lstrlenA,MultiByteToWideChar,VirtualFree,VirtualFree,VirtualFree,VirtualFree,VirtualFree,VirtualFree,VirtualFree,VirtualFree,VirtualFree,VirtualFree, |
15_2_00F958D0 |
Source: C:\Users\user\AppData\Roaming\Microsoft\dwqocx.exe |
Code function: 15_2_00F956A0 VirtualAlloc,wsprintfW,lstrlenW,lstrlenW,lstrlenW,VirtualFree,lstrlenW,VirtualAlloc,wsprintfA,lstrlenW,CryptBinaryToStringA,GetLastError,lstrlenA,lstrlenA,VirtualAlloc,lstrlenA,lstrlenA,lstrlenA,VirtualFree,VirtualFree,VirtualFree,VirtualFree, |
15_2_00F956A0 |
Source: C:\Users\user\AppData\Roaming\Microsoft\dwqocx.exe |
Code function: 15_2_00F98880 CryptAcquireContextW,VirtualAlloc,GetModuleHandleA,LoadLibraryA,GetProcAddress,CryptReleaseContext,VirtualFree,CryptReleaseContext,VirtualFree, |
15_2_00F98880 |
Source: C:\Users\user\AppData\Roaming\Microsoft\dwqocx.exe |
Code function: 15_2_00F96770 EnterCriticalSection,CryptAcquireContextW,GetLastError,CryptAcquireContextW,LeaveCriticalSection,LeaveCriticalSection,CryptImportKey,CryptGetKeyParam,CryptEncrypt,GetLastError,CryptReleaseContext,LeaveCriticalSection, |
15_2_00F96770 |
Source: C:\Users\user\AppData\Roaming\Microsoft\dwqocx.exe |
Code function: 15_2_00F98730 CryptAcquireContextW,VirtualAlloc,GetModuleHandleA,LoadLibraryA,GetProcAddress,CryptReleaseContext,VirtualFree,CryptReleaseContext,VirtualFree, |
15_2_00F98730 |
Source: C:\Users\user\AppData\Roaming\Microsoft\dwqocx.exe |
Code function: 15_2_00F95400 lstrlenA,VirtualAlloc,CryptStringToBinaryA,lstrlenA,VirtualAlloc,lstrcpyA,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,VirtualFree,GetLastError,lstrlenA,VirtualAlloc,VirtualAlloc,VirtualAlloc,lstrcatA,lstrlenA,lstrlenW,lstrlenA,VirtualFree,VirtualFree,VirtualFree,VirtualFree,InternetCloseHandle, |
15_2_00F95400 |
Source: C:\Users\user\AppData\Roaming\Microsoft\dwqocx.exe |
Code function: 29_2_00434B30 Sleep,ExitProcess,CreateThread,WaitForSingleObject,TerminateThread,CloseHandle,VirtualAlloc,GetModuleFileNameW,VirtualFree,ExitProcess,Sleep,lstrlenA,VirtualAlloc,CryptStringToBinaryA,ExitProcess,InitializeCriticalSection,DeleteCriticalSection,VirtualAlloc,GetModuleFileNameW,VirtualFree,ShellExecuteW,ExitThread, |
29_2_00434B30 |
Source: C:\Users\user\AppData\Roaming\Microsoft\dwqocx.exe |
Code function: 29_2_00436770 EnterCriticalSection,CryptAcquireContextW,GetLastError,CryptAcquireContextW,LeaveCriticalSection,LeaveCriticalSection,CryptImportKey,CryptGetKeyParam,CryptEncrypt,GetLastError,CryptReleaseContext,LeaveCriticalSection, |
29_2_00436770 |
Source: C:\Users\user\AppData\Roaming\Microsoft\dwqocx.exe |
Code function: 29_2_00435400 lstrlenA,VirtualAlloc,CryptStringToBinaryA,lstrlenA,VirtualAlloc,lstrcpyA,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,VirtualFree,GetLastError,lstrlenA,VirtualAlloc,VirtualAlloc,VirtualAlloc,lstrcatA,lstrlenA,lstrlenW,lstrlenA,VirtualFree,VirtualFree,VirtualFree,VirtualFree,InternetCloseHandle, |
29_2_00435400 |
Source: C:\Users\user\AppData\Roaming\Microsoft\dwqocx.exe |
Code function: 29_2_00438730 CryptAcquireContextW,VirtualAlloc,GetModuleHandleA,LoadLibraryA,GetProcAddress,CryptReleaseContext,VirtualFree,CryptReleaseContext,VirtualFree, |
29_2_00438730 |
Source: C:\Users\user\AppData\Roaming\Microsoft\dwqocx.exe |
Code function: 29_2_004358D0 VirtualAlloc,VirtualFree,CryptBinaryToStringA,CryptBinaryToStringA,CryptBinaryToStringA,lstrlenA,lstrlenA,lstrlenA,VirtualAlloc,lstrlenA,lstrlenA,lstrlenA,lstrlenA,lstrlenA,lstrlenA,lstrcatW,lstrlenW,lstrlenW,lstrlenW,lstrcatW,lstrlenW,lstrcatW,lstrlenW,lstrcatW,lstrlenW,lstrcatW,lstrlenW,lstrcatW,VirtualFree,VirtualFree,VirtualFree,lstrlenW,lstrcatW,lstrlenW,lstrlenW,lstrlenW,lstrlenA,lstrlenW,MultiByteToWideChar,lstrcatW,lstrlenW,lstrlenA,MultiByteToWideChar,lstrcatW,lstrlenW,VirtualAlloc,lstrlenW,lstrlenW,lstrlenW,VirtualFree,lstrlenW,VirtualAlloc,wsprintfA,lstrlenW,CryptBinaryToStringA,GetLastError,lstrlenA,VirtualAlloc,lstrlenA,lstrlenA,lstrlenA,lstrlenA,MultiByteToWideChar,VirtualFree,VirtualFree,VirtualFree,VirtualFree,VirtualFree,VirtualFree,VirtualFree,VirtualFree,VirtualFree,VirtualFree, |
29_2_004358D0 |
Source: C:\Users\user\AppData\Roaming\Microsoft\dwqocx.exe |
Code function: 29_2_004364F0 CryptAcquireContextW,GetLastError,CryptAcquireContextW,CryptGenKey,CryptExportKey,CryptExportKey,CryptDestroyKey,CryptReleaseContext,CryptAcquireContextW, |
29_2_004364F0 |
Source: C:\Users\user\AppData\Roaming\Microsoft\dwqocx.exe |
Code function: 29_2_004334F0 lstrlenA,VirtualAlloc,VirtualAlloc,CryptStringToBinaryA,VirtualAlloc,VirtualAlloc,wsprintfW,wsprintfW,wsprintfW,VirtualFree, |
29_2_004334F0 |
Source: C:\Users\user\AppData\Roaming\Microsoft\dwqocx.exe |
Code function: 29_2_00438880 CryptAcquireContextW,VirtualAlloc,GetModuleHandleA,LoadLibraryA,GetProcAddress,CryptReleaseContext,VirtualFree,CryptReleaseContext,VirtualFree, |
29_2_00438880 |
Source: C:\Users\user\AppData\Roaming\Microsoft\dwqocx.exe |
Code function: 29_2_004356A0 VirtualAlloc,wsprintfW,lstrlenW,lstrlenW,lstrlenW,VirtualFree,lstrlenW,VirtualAlloc,wsprintfA,lstrlenW,CryptBinaryToStringA,GetLastError,lstrlenA,lstrlenA,VirtualAlloc,lstrlenA,lstrlenA,lstrlenA,VirtualFree,VirtualFree,VirtualFree,VirtualFree, |
29_2_004356A0 |
Source: unknown |
Process created: C:\Users\user\Desktop\file.exe "C:\Users\user\Desktop\file.exe" |
|
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Windows\System32\dllhost.exe C:\Windows\system32\DllHost.exe /Processid:{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} |
|
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Windows\SysWOW64\nslookup.exe nslookup zonealarm.bit ns1.cloud-name.ru |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Windows\SysWOW64\nslookup.exe nslookup ransomware.bit ns2.cloud-name.ru |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Windows\SysWOW64\nslookup.exe nslookup zonealarm.bit ns2.cloud-name.ru |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Windows\SysWOW64\nslookup.exe nslookup ransomware.bit ns1.cloud-name.ru |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Windows\SysWOW64\nslookup.exe nslookup zonealarm.bit ns1.cloud-name.ru |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Windows\SysWOW64\nslookup.exe nslookup ransomware.bit ns2.cloud-name.ru |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Users\user\AppData\Roaming\Microsoft\dwqocx.exe "C:\Users\user\AppData\Roaming\Microsoft\dwqocx.exe" |
|
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Windows\SysWOW64\nslookup.exe nslookup zonealarm.bit ns2.cloud-name.ru |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Windows\SysWOW64\nslookup.exe nslookup ransomware.bit ns1.cloud-name.ru |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Windows\SysWOW64\nslookup.exe nslookup zonealarm.bit ns1.cloud-name.ru |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Windows\SysWOW64\nslookup.exe nslookup ransomware.bit ns2.cloud-name.ru |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Windows\SysWOW64\nslookup.exe nslookup zonealarm.bit ns2.cloud-name.ru |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Windows\SysWOW64\nslookup.exe nslookup ransomware.bit ns1.cloud-name.ru |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: unknown |
Process created: C:\Users\user\AppData\Roaming\Microsoft\dwqocx.exe "C:\Users\user\AppData\Roaming\Microsoft\dwqocx.exe" |
|
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Windows\SysWOW64\nslookup.exe nslookup zonealarm.bit ns1.cloud-name.ru |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Windows\SysWOW64\nslookup.exe nslookup ransomware.bit ns2.cloud-name.ru |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Windows\SysWOW64\nslookup.exe nslookup zonealarm.bit ns2.cloud-name.ru |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Windows\SysWOW64\nslookup.exe nslookup ransomware.bit ns1.cloud-name.ru |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Windows\SysWOW64\nslookup.exe nslookup zonealarm.bit ns1.cloud-name.ru |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Windows\SysWOW64\nslookup.exe nslookup ransomware.bit ns2.cloud-name.ru |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Windows\SysWOW64\nslookup.exe nslookup zonealarm.bit ns2.cloud-name.ru |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Windows\SysWOW64\nslookup.exe nslookup ransomware.bit ns1.cloud-name.ru |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Windows\SysWOW64\nslookup.exe nslookup zonealarm.bit ns1.cloud-name.ru |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Windows\SysWOW64\nslookup.exe nslookup ransomware.bit ns2.cloud-name.ru |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Windows\SysWOW64\nslookup.exe nslookup zonealarm.bit ns2.cloud-name.ru |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Windows\SysWOW64\nslookup.exe nslookup ransomware.bit ns1.cloud-name.ru |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Windows\SysWOW64\nslookup.exe nslookup zonealarm.bit ns1.cloud-name.ru |
|
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Program Files\Windows Defender\MpCmdRun.exe "C:\Program Files\Windows Defender\mpcmdrun.exe" -wdenable |
|
Source: C:\Program Files\Windows Defender\MpCmdRun.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Windows\SysWOW64\nslookup.exe nslookup ransomware.bit ns2.cloud-name.ru |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Windows\SysWOW64\nslookup.exe nslookup zonealarm.bit ns2.cloud-name.ru |
|
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Windows\SysWOW64\nslookup.exe nslookup ransomware.bit ns1.cloud-name.ru |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Windows\SysWOW64\nslookup.exe nslookup zonealarm.bit ns1.cloud-name.ru |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Windows\SysWOW64\nslookup.exe nslookup ransomware.bit ns2.cloud-name.ru |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Windows\SysWOW64\nslookup.exe nslookup zonealarm.bit ns2.cloud-name.ru |
|
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Windows\SysWOW64\nslookup.exe nslookup ransomware.bit ns1.cloud-name.ru |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
|
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Windows\SysWOW64\nslookup.exe nslookup zonealarm.bit ns1.cloud-name.ru |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Windows\SysWOW64\nslookup.exe nslookup ransomware.bit ns2.cloud-name.ru |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Windows\SysWOW64\nslookup.exe nslookup zonealarm.bit ns2.cloud-name.ru |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Windows\SysWOW64\nslookup.exe nslookup ransomware.bit ns1.cloud-name.ru |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Windows\SysWOW64\nslookup.exe nslookup zonealarm.bit ns1.cloud-name.ru |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Windows\SysWOW64\nslookup.exe nslookup ransomware.bit ns2.cloud-name.ru |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Windows\SysWOW64\nslookup.exe nslookup zonealarm.bit ns2.cloud-name.ru |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Windows\SysWOW64\nslookup.exe nslookup ransomware.bit ns1.cloud-name.ru |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Windows\SysWOW64\nslookup.exe nslookup zonealarm.bit ns1.cloud-name.ru |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Windows\SysWOW64\nslookup.exe nslookup ransomware.bit ns2.cloud-name.ru |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Windows\SysWOW64\nslookup.exe nslookup zonealarm.bit ns2.cloud-name.ru |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Windows\SysWOW64\nslookup.exe nslookup ransomware.bit ns1.cloud-name.ru |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Windows\SysWOW64\nslookup.exe nslookup zonealarm.bit ns1.cloud-name.ru |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Windows\SysWOW64\nslookup.exe nslookup ransomware.bit ns2.cloud-name.ru |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Windows\SysWOW64\nslookup.exe nslookup zonealarm.bit ns2.cloud-name.ru |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Windows\SysWOW64\nslookup.exe nslookup ransomware.bit ns1.cloud-name.ru |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Users\user\AppData\Roaming\Microsoft\dwqocx.exe "C:\Users\user\AppData\Roaming\Microsoft\dwqocx.exe" |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Windows\SysWOW64\nslookup.exe nslookup ransomware.bit ns2.cloud-name.ru |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Windows\SysWOW64\nslookup.exe nslookup zonealarm.bit ns2.cloud-name.ru |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Windows\SysWOW64\nslookup.exe nslookup ransomware.bit ns1.cloud-name.ru |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Windows\SysWOW64\nslookup.exe nslookup zonealarm.bit ns1.cloud-name.ru |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Windows\SysWOW64\nslookup.exe nslookup ransomware.bit ns2.cloud-name.ru |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Windows\SysWOW64\nslookup.exe nslookup zonealarm.bit ns2.cloud-name.ru |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Windows\SysWOW64\nslookup.exe nslookup ransomware.bit ns1.cloud-name.ru |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Windows\SysWOW64\nslookup.exe nslookup zonealarm.bit ns1.cloud-name.ru |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Windows\SysWOW64\nslookup.exe nslookup zonealarm.bit ns2.cloud-name.ru |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Windows\SysWOW64\nslookup.exe nslookup ransomware.bit ns1.cloud-name.ru |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Windows\SysWOW64\nslookup.exe nslookup zonealarm.bit ns1.cloud-name.ru |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Windows\SysWOW64\nslookup.exe nslookup ransomware.bit ns2.cloud-name.ru |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Windows\System32\dllhost.exe C:\Windows\system32\DllHost.exe /Processid:{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Program Files\Windows Defender\MpCmdRun.exe "C:\Program Files\Windows Defender\mpcmdrun.exe" -wdenable |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Section loaded: wininet.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Section loaded: cryptsp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Section loaded: rsaenh.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Section loaded: cryptbase.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Section loaded: iertutil.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Section loaded: ondemandconnroutehelper.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Section loaded: winhttp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Section loaded: mswsock.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Section loaded: iphlpapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Section loaded: winnsi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Section loaded: urlmon.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Section loaded: srvcli.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Section loaded: netutils.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Section loaded: dnsapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Section loaded: rasadhlp.dll |
Jump to behavior |
Source: C:\Windows\System32\dllhost.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Windows\System32\dllhost.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Windows\System32\dllhost.exe |
Section loaded: thumbcache.dll |
Jump to behavior |
Source: C:\Windows\System32\dllhost.exe |
Section loaded: propsys.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: dnsapi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: mswsock.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: iphlpapi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: napinsp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: pnrpnsp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: wshbth.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: nlaapi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: winrnr.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: rasadhlp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: dhcpcsvc6.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: dhcpcsvc.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: winnsi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: dnsapi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: mswsock.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: iphlpapi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: napinsp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: pnrpnsp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: wshbth.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: nlaapi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: winrnr.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: rasadhlp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: dhcpcsvc6.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: dhcpcsvc.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: winnsi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: dnsapi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: mswsock.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: iphlpapi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: napinsp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: pnrpnsp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: wshbth.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: nlaapi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: winrnr.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: rasadhlp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: dhcpcsvc6.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: dhcpcsvc.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: winnsi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: dnsapi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: mswsock.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: iphlpapi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: napinsp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: pnrpnsp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: wshbth.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: nlaapi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: winrnr.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: rasadhlp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: dhcpcsvc6.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: dhcpcsvc.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: winnsi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: dnsapi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: mswsock.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: iphlpapi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: napinsp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: pnrpnsp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: wshbth.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: nlaapi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: winrnr.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: rasadhlp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: dhcpcsvc6.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: dhcpcsvc.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: winnsi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: dnsapi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: mswsock.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: iphlpapi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: napinsp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: pnrpnsp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: wshbth.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: nlaapi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: winrnr.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: rasadhlp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: dhcpcsvc6.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: dhcpcsvc.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: winnsi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\dwqocx.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\dwqocx.exe |
Section loaded: wininet.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: dnsapi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: mswsock.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: iphlpapi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: napinsp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: pnrpnsp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: wshbth.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: nlaapi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: winrnr.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: rasadhlp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: dhcpcsvc6.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: dhcpcsvc.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: winnsi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: dnsapi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: mswsock.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: iphlpapi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: napinsp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: pnrpnsp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: wshbth.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: nlaapi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: winrnr.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: rasadhlp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: dhcpcsvc6.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: dhcpcsvc.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: winnsi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: dnsapi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: mswsock.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: iphlpapi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: napinsp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: pnrpnsp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: wshbth.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: nlaapi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: winrnr.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: rasadhlp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: dhcpcsvc6.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: dhcpcsvc.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: winnsi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: dnsapi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: mswsock.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: iphlpapi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: napinsp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: pnrpnsp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: wshbth.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: nlaapi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: winrnr.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: rasadhlp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: dhcpcsvc6.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: dhcpcsvc.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: winnsi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: dnsapi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: mswsock.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: iphlpapi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: napinsp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: pnrpnsp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: wshbth.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: nlaapi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: winrnr.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: rasadhlp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: dhcpcsvc6.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: dhcpcsvc.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: winnsi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: dnsapi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: mswsock.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: iphlpapi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: napinsp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: pnrpnsp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: wshbth.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: nlaapi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: winrnr.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: rasadhlp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: dhcpcsvc6.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: dhcpcsvc.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: winnsi.dll |
Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\dwqocx.exe |
Section loaded: wininet.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: dnsapi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: mswsock.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: iphlpapi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: napinsp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: pnrpnsp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: wshbth.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: nlaapi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: winrnr.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: rasadhlp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: dhcpcsvc6.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: dhcpcsvc.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: winnsi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: dnsapi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: mswsock.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: iphlpapi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: napinsp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: pnrpnsp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: wshbth.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: nlaapi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: winrnr.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: rasadhlp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: dhcpcsvc6.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: dhcpcsvc.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: winnsi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: dnsapi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: mswsock.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: iphlpapi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: napinsp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: pnrpnsp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: wshbth.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: nlaapi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: winrnr.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: rasadhlp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: dhcpcsvc6.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: dhcpcsvc.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: winnsi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: dnsapi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: mswsock.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: iphlpapi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: napinsp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: pnrpnsp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: wshbth.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: nlaapi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: winrnr.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: rasadhlp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: dhcpcsvc6.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: dhcpcsvc.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: winnsi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: dnsapi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: mswsock.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: iphlpapi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: napinsp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: pnrpnsp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: wshbth.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: nlaapi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: winrnr.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: rasadhlp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: dhcpcsvc6.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: dhcpcsvc.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: winnsi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: dnsapi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: mswsock.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: iphlpapi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: napinsp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: pnrpnsp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: wshbth.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: nlaapi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: winrnr.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: rasadhlp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: dhcpcsvc6.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: dhcpcsvc.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: winnsi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: dnsapi.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: mswsock.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: iphlpapi.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: napinsp.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: pnrpnsp.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: wshbth.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: nlaapi.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: winrnr.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: rasadhlp.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: dhcpcsvc6.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: dhcpcsvc.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: winnsi.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: dnsapi.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: mswsock.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: iphlpapi.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: napinsp.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: pnrpnsp.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: wshbth.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: nlaapi.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: winrnr.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: rasadhlp.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: dhcpcsvc6.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: dhcpcsvc.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: winnsi.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: dnsapi.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: mswsock.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: iphlpapi.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: napinsp.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: pnrpnsp.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: wshbth.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: nlaapi.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: winrnr.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: rasadhlp.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: dhcpcsvc6.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: dhcpcsvc.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: winnsi.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: dnsapi.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: mswsock.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: iphlpapi.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: napinsp.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: pnrpnsp.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: wshbth.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: nlaapi.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: winrnr.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: rasadhlp.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: dhcpcsvc6.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: dhcpcsvc.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: winnsi.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: dnsapi.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: mswsock.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: iphlpapi.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: napinsp.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: pnrpnsp.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: wshbth.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: nlaapi.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: winrnr.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: rasadhlp.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: dhcpcsvc6.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: dhcpcsvc.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: winnsi.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: dnsapi.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: mswsock.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: iphlpapi.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: napinsp.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: pnrpnsp.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: wshbth.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: nlaapi.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: winrnr.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: rasadhlp.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: dhcpcsvc6.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: dhcpcsvc.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: winnsi.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: dnsapi.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: mswsock.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: iphlpapi.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: napinsp.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: pnrpnsp.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: wshbth.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: nlaapi.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: winrnr.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: rasadhlp.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: dhcpcsvc6.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: dhcpcsvc.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: winnsi.dll |
|
Source: C:\Program Files\Windows Defender\MpCmdRun.exe |
Section loaded: mpclient.dll |
|
Source: C:\Program Files\Windows Defender\MpCmdRun.exe |
Section loaded: secur32.dll |
|
Source: C:\Program Files\Windows Defender\MpCmdRun.exe |
Section loaded: sspicli.dll |
|
Source: C:\Program Files\Windows Defender\MpCmdRun.exe |
Section loaded: version.dll |
|
Source: C:\Program Files\Windows Defender\MpCmdRun.exe |
Section loaded: msasn1.dll |
|
Source: C:\Program Files\Windows Defender\MpCmdRun.exe |
Section loaded: kernel.appcore.dll |
|
Source: C:\Program Files\Windows Defender\MpCmdRun.exe |
Section loaded: userenv.dll |
|
Source: C:\Program Files\Windows Defender\MpCmdRun.exe |
Section loaded: gpapi.dll |
|
Source: C:\Program Files\Windows Defender\MpCmdRun.exe |
Section loaded: wbemcomn.dll |
|
Source: C:\Program Files\Windows Defender\MpCmdRun.exe |
Section loaded: amsi.dll |
|
Source: C:\Program Files\Windows Defender\MpCmdRun.exe |
Section loaded: profapi.dll |
|
Source: C:\Program Files\Windows Defender\MpCmdRun.exe |
Section loaded: wscapi.dll |
|
Source: C:\Program Files\Windows Defender\MpCmdRun.exe |
Section loaded: urlmon.dll |
|
Source: C:\Program Files\Windows Defender\MpCmdRun.exe |
Section loaded: iertutil.dll |
|
Source: C:\Program Files\Windows Defender\MpCmdRun.exe |
Section loaded: srvcli.dll |
|
Source: C:\Program Files\Windows Defender\MpCmdRun.exe |
Section loaded: netutils.dll |
|
Source: C:\Program Files\Windows Defender\MpCmdRun.exe |
Section loaded: slc.dll |
|
Source: C:\Program Files\Windows Defender\MpCmdRun.exe |
Section loaded: sppc.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: dnsapi.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: mswsock.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: iphlpapi.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: napinsp.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: pnrpnsp.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: wshbth.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: nlaapi.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: winrnr.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: rasadhlp.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: dhcpcsvc6.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: dhcpcsvc.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: winnsi.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: dnsapi.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: mswsock.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: iphlpapi.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: napinsp.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: pnrpnsp.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: wshbth.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: nlaapi.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: winrnr.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: rasadhlp.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: dhcpcsvc6.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: dhcpcsvc.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: winnsi.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: dnsapi.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: mswsock.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: iphlpapi.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: napinsp.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: pnrpnsp.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: wshbth.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: nlaapi.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: winrnr.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: rasadhlp.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: dhcpcsvc6.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: dhcpcsvc.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: winnsi.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: dnsapi.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: mswsock.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: iphlpapi.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: napinsp.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: pnrpnsp.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: wshbth.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: nlaapi.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: winrnr.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: rasadhlp.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: dhcpcsvc6.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: dhcpcsvc.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: winnsi.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: dnsapi.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: mswsock.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: iphlpapi.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: napinsp.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: pnrpnsp.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: wshbth.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: nlaapi.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: winrnr.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: rasadhlp.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: dhcpcsvc6.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: dhcpcsvc.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: winnsi.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: dnsapi.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: mswsock.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: iphlpapi.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: napinsp.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: pnrpnsp.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: wshbth.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: nlaapi.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: winrnr.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: rasadhlp.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: dhcpcsvc6.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: dhcpcsvc.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: winnsi.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: dnsapi.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: mswsock.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: iphlpapi.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: napinsp.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: pnrpnsp.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: wshbth.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: nlaapi.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: winrnr.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: rasadhlp.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: dhcpcsvc6.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: dhcpcsvc.dll |
|
Source: C:\Windows\SysWOW64\nslookup.exe |
Section loaded: winnsi.dll |
|
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Windows\SysWOW64\nslookup.exe nslookup zonealarm.bit ns1.cloud-name.ru |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Windows\SysWOW64\nslookup.exe nslookup ransomware.bit ns2.cloud-name.ru |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Windows\SysWOW64\nslookup.exe nslookup zonealarm.bit ns2.cloud-name.ru |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Windows\SysWOW64\nslookup.exe nslookup ransomware.bit ns1.cloud-name.ru |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Windows\SysWOW64\nslookup.exe nslookup zonealarm.bit ns1.cloud-name.ru |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Windows\SysWOW64\nslookup.exe nslookup ransomware.bit ns2.cloud-name.ru |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Windows\SysWOW64\nslookup.exe nslookup zonealarm.bit ns2.cloud-name.ru |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Windows\SysWOW64\nslookup.exe nslookup ransomware.bit ns1.cloud-name.ru |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Windows\SysWOW64\nslookup.exe nslookup zonealarm.bit ns1.cloud-name.ru |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Windows\SysWOW64\nslookup.exe nslookup ransomware.bit ns2.cloud-name.ru |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Windows\SysWOW64\nslookup.exe nslookup zonealarm.bit ns2.cloud-name.ru |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Windows\SysWOW64\nslookup.exe nslookup ransomware.bit ns1.cloud-name.ru |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Windows\SysWOW64\nslookup.exe nslookup zonealarm.bit ns1.cloud-name.ru |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Windows\SysWOW64\nslookup.exe nslookup ransomware.bit ns2.cloud-name.ru |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Windows\SysWOW64\nslookup.exe nslookup zonealarm.bit ns2.cloud-name.ru |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Windows\SysWOW64\nslookup.exe nslookup ransomware.bit ns1.cloud-name.ru |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Users\user\AppData\Roaming\Microsoft\dwqocx.exe "C:\Users\user\AppData\Roaming\Microsoft\dwqocx.exe" |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Windows\SysWOW64\nslookup.exe nslookup ransomware.bit ns2.cloud-name.ru |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Windows\SysWOW64\nslookup.exe nslookup zonealarm.bit ns2.cloud-name.ru |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Windows\SysWOW64\nslookup.exe nslookup ransomware.bit ns1.cloud-name.ru |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Windows\SysWOW64\nslookup.exe nslookup zonealarm.bit ns1.cloud-name.ru |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Windows\SysWOW64\nslookup.exe nslookup ransomware.bit ns2.cloud-name.ru |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Windows\SysWOW64\nslookup.exe nslookup zonealarm.bit ns2.cloud-name.ru |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Windows\SysWOW64\nslookup.exe nslookup ransomware.bit ns1.cloud-name.ru |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Windows\SysWOW64\nslookup.exe nslookup zonealarm.bit ns1.cloud-name.ru |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Windows\SysWOW64\nslookup.exe nslookup zonealarm.bit ns2.cloud-name.ru |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Windows\SysWOW64\nslookup.exe nslookup ransomware.bit ns1.cloud-name.ru |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Windows\SysWOW64\nslookup.exe nslookup zonealarm.bit ns1.cloud-name.ru |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Windows\SysWOW64\nslookup.exe nslookup ransomware.bit ns2.cloud-name.ru |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Windows\System32\dllhost.exe C:\Windows\system32\DllHost.exe /Processid:{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Program Files\Windows Defender\MpCmdRun.exe "C:\Program Files\Windows Defender\mpcmdrun.exe" -wdenable |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |
Source: C:\Users\user\Desktop\file.exe |
Process created: unknown unknown |
Jump to behavior |