Source: TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe, 00000000.00000002.1379490138.0000000004349000.00000004.00000800.00020000.00000000.sdmp, YzkHZRBcm.exe, 0000000E.00000002.3796978484.0000000000432000.00000040.00000400.00020000.00000000.sdmp | String found in binary or memory: http://51.38.247.67:8081/_send_.php?LCapplication/x-www-form-urlencoded |
Source: TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe, 00000000.00000002.1379490138.0000000004349000.00000004.00000800.00020000.00000000.sdmp, TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe, 00000009.00000002.3803235047.0000000002EE1000.00000004.00000800.00020000.00000000.sdmp, YzkHZRBcm.exe, 0000000E.00000002.3796978484.0000000000432000.00000040.00000400.00020000.00000000.sdmp, YzkHZRBcm.exe, 0000000E.00000002.3802870010.0000000003001000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://aborters.duckdns.org:8081 |
Source: TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe, 00000000.00000002.1379490138.0000000004349000.00000004.00000800.00020000.00000000.sdmp, TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe, 00000009.00000002.3803235047.0000000002EE1000.00000004.00000800.00020000.00000000.sdmp, YzkHZRBcm.exe, 0000000E.00000002.3796978484.0000000000432000.00000040.00000400.00020000.00000000.sdmp, YzkHZRBcm.exe, 0000000E.00000002.3802870010.0000000003001000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://anotherarmy.dns.army:8081 |
Source: TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe, 00000009.00000002.3803235047.0000000002EE1000.00000004.00000800.00020000.00000000.sdmp, YzkHZRBcm.exe, 0000000E.00000002.3802870010.0000000003001000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://checkip.dyndns.org |
Source: TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe, 00000009.00000002.3803235047.0000000002EE1000.00000004.00000800.00020000.00000000.sdmp, YzkHZRBcm.exe, 0000000E.00000002.3802870010.0000000003001000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://checkip.dyndns.org/ |
Source: TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe, 00000000.00000002.1379490138.0000000004349000.00000004.00000800.00020000.00000000.sdmp, YzkHZRBcm.exe, 0000000E.00000002.3796978484.0000000000432000.00000040.00000400.00020000.00000000.sdmp | String found in binary or memory: http://checkip.dyndns.org/q |
Source: TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe, 00000000.00000002.1377186980.0000000003341000.00000004.00000800.00020000.00000000.sdmp, TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe, 00000009.00000002.3803235047.0000000002EE1000.00000004.00000800.00020000.00000000.sdmp, YzkHZRBcm.exe, 0000000A.00000002.1419410557.0000000002B61000.00000004.00000800.00020000.00000000.sdmp, YzkHZRBcm.exe, 0000000E.00000002.3802870010.0000000003001000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name |
Source: TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe, 00000000.00000002.1379490138.0000000004349000.00000004.00000800.00020000.00000000.sdmp, TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe, 00000009.00000002.3803235047.0000000002EE1000.00000004.00000800.00020000.00000000.sdmp, YzkHZRBcm.exe, 0000000E.00000002.3796978484.0000000000432000.00000040.00000400.00020000.00000000.sdmp, YzkHZRBcm.exe, 0000000E.00000002.3802870010.0000000003001000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://varders.kozow.com:8081 |
Source: TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe, 00000009.00000002.3808408989.00000000041F4000.00000004.00000800.00020000.00000000.sdmp, TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe, 00000009.00000002.3808408989.0000000003F02000.00000004.00000800.00020000.00000000.sdmp, YzkHZRBcm.exe, 0000000E.00000002.3808451526.0000000004311000.00000004.00000800.00020000.00000000.sdmp, YzkHZRBcm.exe, 0000000E.00000002.3808451526.0000000004023000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ac.ecosia.org/autocomplete?q= |
Source: TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe, 00000009.00000002.3803235047.0000000002FC9000.00000004.00000800.00020000.00000000.sdmp, YzkHZRBcm.exe, 0000000E.00000002.3802870010.00000000030E7000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://api.telegram.org |
Source: TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe, 00000000.00000002.1379490138.0000000004349000.00000004.00000800.00020000.00000000.sdmp, TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe, 00000009.00000002.3803235047.0000000002FC9000.00000004.00000800.00020000.00000000.sdmp, YzkHZRBcm.exe, 0000000E.00000002.3796978484.0000000000432000.00000040.00000400.00020000.00000000.sdmp, YzkHZRBcm.exe, 0000000E.00000002.3802870010.00000000030E7000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://api.telegram.org/bot |
Source: TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe, 00000009.00000002.3803235047.0000000002FC9000.00000004.00000800.00020000.00000000.sdmp, YzkHZRBcm.exe, 0000000E.00000002.3802870010.00000000030E7000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://api.telegram.org/bot/sendMessage?chat_id=&text= |
Source: TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe, 00000009.00000002.3803235047.0000000002FC9000.00000004.00000800.00020000.00000000.sdmp, YzkHZRBcm.exe, 0000000E.00000002.3802870010.00000000030E7000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://api.telegram.org/bot/sendMessage?chat_id=&text=%20%0D%0A%0D%0APC%20Name:124406%0D%0ADate%20a |
Source: TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe, 00000009.00000002.3808408989.00000000041F4000.00000004.00000800.00020000.00000000.sdmp, TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe, 00000009.00000002.3808408989.0000000003F02000.00000004.00000800.00020000.00000000.sdmp, YzkHZRBcm.exe, 0000000E.00000002.3808451526.0000000004311000.00000004.00000800.00020000.00000000.sdmp, YzkHZRBcm.exe, 0000000E.00000002.3808451526.0000000004023000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://cdn.ecosia.org/assets/images/ico/favicon.icohttps://www.ecosia.org/search?q= |
Source: TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe, 00000009.00000002.3808408989.00000000041F4000.00000004.00000800.00020000.00000000.sdmp, TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe, 00000009.00000002.3808408989.0000000003F02000.00000004.00000800.00020000.00000000.sdmp, YzkHZRBcm.exe, 0000000E.00000002.3808451526.0000000004311000.00000004.00000800.00020000.00000000.sdmp, YzkHZRBcm.exe, 0000000E.00000002.3808451526.0000000004023000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ch.search.yahoo.com/favicon.icohttps://ch.search.yahoo.com/search |
Source: TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe, 00000009.00000002.3808408989.00000000041F4000.00000004.00000800.00020000.00000000.sdmp, TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe, 00000009.00000002.3808408989.0000000003F02000.00000004.00000800.00020000.00000000.sdmp, YzkHZRBcm.exe, 0000000E.00000002.3808451526.0000000004311000.00000004.00000800.00020000.00000000.sdmp, YzkHZRBcm.exe, 0000000E.00000002.3808451526.0000000004023000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ch.search.yahoo.com/sugg/chrome?output=fxjson&appid=crmas&command= |
Source: YzkHZRBcm.exe, 0000000E.00000002.3802870010.0000000003198000.00000004.00000800.00020000.00000000.sdmp, YzkHZRBcm.exe, 0000000E.00000002.3802870010.0000000003189000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://chrome.google.com/webstore?hl=en |
Source: TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe, 00000009.00000002.3803235047.0000000003073000.00000004.00000800.00020000.00000000.sdmp, YzkHZRBcm.exe, 0000000E.00000002.3802870010.0000000003193000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://chrome.google.com/webstore?hl=enlB |
Source: TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe, 00000009.00000002.3808408989.00000000041F4000.00000004.00000800.00020000.00000000.sdmp, TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe, 00000009.00000002.3808408989.0000000003F02000.00000004.00000800.00020000.00000000.sdmp, YzkHZRBcm.exe, 0000000E.00000002.3808451526.0000000004311000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://duckduckgo.com/ac/?q= |
Source: TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe, 00000009.00000002.3808408989.00000000041F4000.00000004.00000800.00020000.00000000.sdmp, TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe, 00000009.00000002.3808408989.0000000003F02000.00000004.00000800.00020000.00000000.sdmp, YzkHZRBcm.exe, 0000000E.00000002.3808451526.0000000004311000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://duckduckgo.com/chrome_newtab |
Source: TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe, 00000009.00000002.3808408989.00000000041F4000.00000004.00000800.00020000.00000000.sdmp, TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe, 00000009.00000002.3808408989.0000000003F02000.00000004.00000800.00020000.00000000.sdmp, YzkHZRBcm.exe, 0000000E.00000002.3808451526.0000000004311000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://duckduckgo.com/favicon.icohttps://duckduckgo.com/?q= |
Source: TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe, 00000009.00000002.3803235047.0000000002F32000.00000004.00000800.00020000.00000000.sdmp, TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe, 00000009.00000002.3803235047.0000000002FA2000.00000004.00000800.00020000.00000000.sdmp, TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe, 00000009.00000002.3803235047.0000000002FC9000.00000004.00000800.00020000.00000000.sdmp, YzkHZRBcm.exe, 0000000E.00000002.3802870010.0000000003051000.00000004.00000800.00020000.00000000.sdmp, YzkHZRBcm.exe, 0000000E.00000002.3802870010.00000000030C1000.00000004.00000800.00020000.00000000.sdmp, YzkHZRBcm.exe, 0000000E.00000002.3802870010.00000000030E7000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://reallyfreegeoip.org |
Source: TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe, 00000000.00000002.1379490138.0000000004349000.00000004.00000800.00020000.00000000.sdmp, TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe, 00000009.00000002.3803235047.0000000002F32000.00000004.00000800.00020000.00000000.sdmp, YzkHZRBcm.exe, 0000000E.00000002.3802870010.0000000003051000.00000004.00000800.00020000.00000000.sdmp, YzkHZRBcm.exe, 0000000E.00000002.3796978484.0000000000432000.00000040.00000400.00020000.00000000.sdmp | String found in binary or memory: https://reallyfreegeoip.org/xml/ |
Source: YzkHZRBcm.exe, 0000000E.00000002.3802870010.000000000307B000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://reallyfreegeoip.org/xml/8.46.123.33 |
Source: TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe, 00000009.00000002.3803235047.0000000002FA2000.00000004.00000800.00020000.00000000.sdmp, TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe, 00000009.00000002.3803235047.0000000002FC9000.00000004.00000800.00020000.00000000.sdmp, TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe, 00000009.00000002.3803235047.0000000002F5D000.00000004.00000800.00020000.00000000.sdmp, YzkHZRBcm.exe, 0000000E.00000002.3802870010.00000000030C1000.00000004.00000800.00020000.00000000.sdmp, YzkHZRBcm.exe, 0000000E.00000002.3802870010.00000000030E7000.00000004.00000800.00020000.00000000.sdmp, YzkHZRBcm.exe, 0000000E.00000002.3802870010.000000000307B000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://reallyfreegeoip.org/xml/8.46.123.33$ |
Source: TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe, 00000009.00000002.3808408989.00000000041F4000.00000004.00000800.00020000.00000000.sdmp, TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe, 00000009.00000002.3808408989.0000000003F02000.00000004.00000800.00020000.00000000.sdmp, YzkHZRBcm.exe, 0000000E.00000002.3808451526.0000000004311000.00000004.00000800.00020000.00000000.sdmp, YzkHZRBcm.exe, 0000000E.00000002.3808451526.0000000004023000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://www.ecosia.org/newtab/ |
Source: TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe, 00000009.00000002.3808408989.00000000041F4000.00000004.00000800.00020000.00000000.sdmp, TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe, 00000009.00000002.3808408989.0000000003F02000.00000004.00000800.00020000.00000000.sdmp, YzkHZRBcm.exe, 0000000E.00000002.3808451526.0000000004311000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://www.google.com/images/branding/product/ico/googleg_lodp.ico |
Source: YzkHZRBcm.exe, 0000000E.00000002.3802870010.00000000031C9000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://www.office.com/ |
Source: TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe, 00000009.00000002.3803235047.00000000030A5000.00000004.00000800.00020000.00000000.sdmp, YzkHZRBcm.exe, 0000000E.00000002.3802870010.00000000031C4000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://www.office.com/lB |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Code function: 0_2_031DD55C | 0_2_031DD55C |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Code function: 0_2_07DCA490 | 0_2_07DCA490 |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Code function: 0_2_07DC0040 | 0_2_07DC0040 |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Code function: 0_2_07DC8ED0 | 0_2_07DC8ED0 |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Code function: 0_2_07DC6980 | 0_2_07DC6980 |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Code function: 0_2_07DC54B0 | 0_2_07DC54B0 |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Code function: 0_2_07DC3458 | 0_2_07DC3458 |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Code function: 0_2_07DC3448 | 0_2_07DC3448 |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Code function: 0_2_07DC0007 | 0_2_07DC0007 |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Code function: 0_2_07DC3020 | 0_2_07DC3020 |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Code function: 0_2_07DC2BE8 | 0_2_07DC2BE8 |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Code function: 0_2_07DC4B00 | 0_2_07DC4B00 |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Code function: 9_2_0133C146 | 9_2_0133C146 |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Code function: 9_2_0133D283 | 9_2_0133D283 |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Code function: 9_2_0133C473 | 9_2_0133C473 |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Code function: 9_2_0133C738 | 9_2_0133C738 |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Code function: 9_2_013369AB | 9_2_013369AB |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Code function: 9_2_0133E988 | 9_2_0133E988 |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Code function: 9_2_0133CA13 | 9_2_0133CA13 |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Code function: 9_2_01333AA1 | 9_2_01333AA1 |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Code function: 9_2_0133CCDF | 9_2_0133CCDF |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Code function: 9_2_0133CFA9 | 9_2_0133CFA9 |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Code function: 9_2_01336FC8 | 9_2_01336FC8 |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Code function: 9_2_01333E09 | 9_2_01333E09 |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Code function: 9_2_01335377 | 9_2_01335377 |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Code function: 9_2_0133F631 | 9_2_0133F631 |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Code function: 9_2_0133E97B | 9_2_0133E97B |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Code function: 9_2_013339EE | 9_2_013339EE |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Code function: 9_2_013329EC | 9_2_013329EC |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Code function: 9_2_0133FA88 | 9_2_0133FA88 |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 10_2_0102D55C | 10_2_0102D55C |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 10_2_051E6A48 | 10_2_051E6A48 |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 10_2_051E0006 | 10_2_051E0006 |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 10_2_051E0040 | 10_2_051E0040 |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 10_2_051E6A38 | 10_2_051E6A38 |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 10_2_071B9718 | 10_2_071B9718 |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 10_2_071B8148 | 10_2_071B8148 |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 10_2_071B6800 | 10_2_071B6800 |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 10_2_071B0040 | 10_2_071B0040 |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 10_2_071B3458 | 10_2_071B3458 |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 10_2_071B3448 | 10_2_071B3448 |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 10_2_071B54B0 | 10_2_071B54B0 |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 10_2_071B4B00 | 10_2_071B4B00 |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 10_2_071B2BE8 | 10_2_071B2BE8 |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 10_2_071B8138 | 10_2_071B8138 |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 10_2_071B0006 | 10_2_071B0006 |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 10_2_071B3020 | 10_2_071B3020 |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 14_2_012BC146 | 14_2_012BC146 |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 14_2_012BA088 | 14_2_012BA088 |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 14_2_012B5362 | 14_2_012B5362 |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 14_2_012BD278 | 14_2_012BD278 |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 14_2_012BC468 | 14_2_012BC468 |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 14_2_012BC738 | 14_2_012BC738 |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 14_2_012B69A0 | 14_2_012B69A0 |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 14_2_012BE988 | 14_2_012BE988 |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 14_2_012BCA08 | 14_2_012BCA08 |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 14_2_012B3AA1 | 14_2_012B3AA1 |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 14_2_012BCCD8 | 14_2_012BCCD8 |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 14_2_012BCFA9 | 14_2_012BCFA9 |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 14_2_012B6FC8 | 14_2_012B6FC8 |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 14_2_012BF631 | 14_2_012BF631 |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 14_2_012BE97B | 14_2_012BE97B |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 14_2_012B39EE | 14_2_012B39EE |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 14_2_012B29EC | 14_2_012B29EC |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 14_2_012BFA88 | 14_2_012BFA88 |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 14_2_012B3E09 | 14_2_012B3E09 |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 14_2_059261E8 | 14_2_059261E8 |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 14_2_05922D9A | 14_2_05922D9A |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 14_2_05924D98 | 14_2_05924D98 |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 14_2_05924D89 | 14_2_05924D89 |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 14_2_05922DA8 | 14_2_05922DA8 |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 14_2_05920DF0 | 14_2_05920DF0 |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 14_2_05920DE0 | 14_2_05920DE0 |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 14_2_05927508 | 14_2_05927508 |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 14_2_0592EC90 | 14_2_0592EC90 |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 14_2_0592D497 | 14_2_0592D497 |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 14_2_0592EC81 | 14_2_0592EC81 |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 14_2_05922488 | 14_2_05922488 |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 14_2_0592BCB2 | 14_2_0592BCB2 |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 14_2_0592D4A8 | 14_2_0592D4A8 |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 14_2_059204D0 | 14_2_059204D0 |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 14_2_0592A4D8 | 14_2_0592A4D8 |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 14_2_0592BCC0 | 14_2_0592BCC0 |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 14_2_059204C0 | 14_2_059204C0 |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 14_2_0592A4C8 | 14_2_0592A4C8 |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 14_2_05928CF0 | 14_2_05928CF0 |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 14_2_059274F8 | 14_2_059274F8 |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 14_2_05928CE1 | 14_2_05928CE1 |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 14_2_05922477 | 14_2_05922477 |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 14_2_05924478 | 14_2_05924478 |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 14_2_05924467 | 14_2_05924467 |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 14_2_0592E7BA | 14_2_0592E7BA |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 14_2_0592CFD0 | 14_2_0592CFD0 |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 14_2_05923FD8 | 14_2_05923FD8 |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 14_2_0592E7C8 | 14_2_0592E7C8 |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 14_2_05921FF8 | 14_2_05921FF8 |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 14_2_0592B7F8 | 14_2_0592B7F8 |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 14_2_05929FFF | 14_2_05929FFF |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 14_2_0592CFE0 | 14_2_0592CFE0 |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 14_2_05923FE8 | 14_2_05923FE8 |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 14_2_05921FE8 | 14_2_05921FE8 |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 14_2_0592B7E8 | 14_2_0592B7E8 |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 14_2_05921710 | 14_2_05921710 |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 14_2_05921701 | 14_2_05921701 |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 14_2_05927E98 | 14_2_05927E98 |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 14_2_05929680 | 14_2_05929680 |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 14_2_05927E88 | 14_2_05927E88 |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 14_2_059266B0 | 14_2_059266B0 |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 14_2_059256B8 | 14_2_059256B8 |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 14_2_059236B9 | 14_2_059236B9 |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 14_2_059266A0 | 14_2_059266A0 |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 14_2_059256A9 | 14_2_059256A9 |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 14_2_059236C8 | 14_2_059236C8 |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 14_2_0592F610 | 14_2_0592F610 |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 14_2_0592DE38 | 14_2_0592DE38 |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 14_2_0592F620 | 14_2_0592F620 |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 14_2_0592DE28 | 14_2_0592DE28 |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 14_2_0592C650 | 14_2_0592C650 |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 14_2_0592AE58 | 14_2_0592AE58 |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 14_2_0592C641 | 14_2_0592C641 |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 14_2_0592AE68 | 14_2_0592AE68 |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 14_2_0592966F | 14_2_0592966F |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 14_2_0592C188 | 14_2_0592C188 |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 14_2_0592A98F | 14_2_0592A98F |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 14_2_059291B8 | 14_2_059291B8 |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 14_2_0592A9A0 | 14_2_0592A9A0 |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 14_2_059291A7 | 14_2_059291A7 |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 14_2_059279D0 | 14_2_059279D0 |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 14_2_059261D9 | 14_2_059261D9 |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 14_2_059279C0 | 14_2_059279C0 |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 14_2_05922918 | 14_2_05922918 |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 14_2_0592290A | 14_2_0592290A |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 14_2_05924908 | 14_2_05924908 |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 14_2_05920950 | 14_2_05920950 |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 14_2_0592F158 | 14_2_0592F158 |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 14_2_0592F147 | 14_2_0592F147 |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 14_2_0592D970 | 14_2_0592D970 |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 14_2_0592C178 | 14_2_0592C178 |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 14_2_05920960 | 14_2_05920960 |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 14_2_0592D960 | 14_2_0592D960 |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 14_2_059248F9 | 14_2_059248F9 |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 14_2_0592A010 | 14_2_0592A010 |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 14_2_05928819 | 14_2_05928819 |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 14_2_05920006 | 14_2_05920006 |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 14_2_05928828 | 14_2_05928828 |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 14_2_0592702F | 14_2_0592702F |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 14_2_05920040 | 14_2_05920040 |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 14_2_05927040 | 14_2_05927040 |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 14_2_0592CB16 | 14_2_0592CB16 |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 14_2_0592CB18 | 14_2_0592CB18 |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 14_2_0592B31F | 14_2_0592B31F |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 14_2_0592E300 | 14_2_0592E300 |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 14_2_0592B330 | 14_2_0592B330 |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 14_2_05925B37 | 14_2_05925B37 |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 14_2_05929B38 | 14_2_05929B38 |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 14_2_05928350 | 14_2_05928350 |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 14_2_05923B58 | 14_2_05923B58 |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 14_2_05921B58 | 14_2_05921B58 |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 14_2_05925B48 | 14_2_05925B48 |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 14_2_05929B48 | 14_2_05929B48 |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 14_2_05923B48 | 14_2_05923B48 |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 14_2_05926B78 | 14_2_05926B78 |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 14_2_05928360 | 14_2_05928360 |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 14_2_05926B6A | 14_2_05926B6A |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 14_2_05921B68 | 14_2_05921B68 |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 14_2_05921280 | 14_2_05921280 |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 14_2_0592FAD7 | 14_2_0592FAD7 |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 14_2_0592FAE8 | 14_2_0592FAE8 |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 14_2_0592E2EF | 14_2_0592E2EF |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 14_2_05925218 | 14_2_05925218 |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 14_2_05923238 | 14_2_05923238 |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 14_2_05923227 | 14_2_05923227 |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 14_2_05925228 | 14_2_05925228 |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Code function: 14_2_0592126F | 14_2_0592126F |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Section loaded: dwrite.dll | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Section loaded: windowscodecs.dll | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Section loaded: edputil.dll | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Section loaded: windows.staterepositoryps.dll | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Section loaded: appresolver.dll | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Section loaded: bcp47langs.dll | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Section loaded: slc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Section loaded: sppc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Section loaded: onecorecommonproxystub.dll | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Section loaded: onecoreuapcommonproxystub.dll | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: atl.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: msisip.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wshext.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: appxsip.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: opcservices.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: secur32.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: atl.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: msisip.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wshext.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: appxsip.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: opcservices.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: secur32.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: microsoft.management.infrastructure.native.unmanaged.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: mi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: miutils.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wmidcom.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: dpapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wbemcomn.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\schtasks.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\schtasks.exe | Section loaded: taskschd.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\schtasks.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Section loaded: rasapi32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Section loaded: rasman.dll | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Section loaded: rtutils.dll | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Section loaded: dhcpcsvc6.dll | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Section loaded: dhcpcsvc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Section loaded: dnsapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Section loaded: winnsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Section loaded: rasadhlp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Section loaded: fwpuclnt.dll | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Section loaded: secur32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Section loaded: schannel.dll | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Section loaded: mskeyprotect.dll | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Section loaded: ntasn1.dll | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Section loaded: ncrypt.dll | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Section loaded: ncryptsslp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Section loaded: dpapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Section loaded: dwrite.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Section loaded: windowscodecs.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Section loaded: edputil.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Section loaded: windows.staterepositoryps.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Section loaded: appresolver.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Section loaded: bcp47langs.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Section loaded: slc.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Section loaded: sppc.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Section loaded: onecorecommonproxystub.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Section loaded: onecoreuapcommonproxystub.dll | Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: fastprox.dll | |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: ncobjapi.dll | |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: wbemcomn.dll | |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: wbemcomn.dll | |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: mpclient.dll | |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: userenv.dll | |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: version.dll | |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: msasn1.dll | |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: wmitomi.dll | |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: mi.dll | |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: miutils.dll | |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: miutils.dll | |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: gpapi.dll | |
Source: C:\Windows\SysWOW64\schtasks.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\SysWOW64\schtasks.exe | Section loaded: taskschd.dll | |
Source: C:\Windows\SysWOW64\schtasks.exe | Section loaded: sspicli.dll | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Section loaded: mscoree.dll | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Section loaded: version.dll | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Section loaded: vcruntime140_clr0400.dll | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Section loaded: uxtheme.dll | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Section loaded: windows.storage.dll | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Section loaded: wldp.dll | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Section loaded: profapi.dll | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Section loaded: cryptsp.dll | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Section loaded: rsaenh.dll | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Section loaded: cryptbase.dll | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Section loaded: rasapi32.dll | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Section loaded: rasman.dll | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Section loaded: rtutils.dll | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Section loaded: mswsock.dll | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Section loaded: winhttp.dll | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Section loaded: ondemandconnroutehelper.dll | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Section loaded: iphlpapi.dll | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Section loaded: dhcpcsvc6.dll | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Section loaded: dhcpcsvc.dll | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Section loaded: dnsapi.dll | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Section loaded: winnsi.dll | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Section loaded: rasadhlp.dll | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Section loaded: fwpuclnt.dll | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Section loaded: secur32.dll | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Section loaded: sspicli.dll | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Section loaded: schannel.dll | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Section loaded: mskeyprotect.dll | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Section loaded: ntasn1.dll | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Section loaded: ncrypt.dll | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Section loaded: ncryptsslp.dll | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Section loaded: msasn1.dll | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Section loaded: gpapi.dll | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Section loaded: dpapi.dll | |
Source: 0.2.TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe.45fd470.1.raw.unpack, fb6yvpsy14g5qhnfk0.cs | High entropy of concatenated method names: 'p4hGfKv758', 'CSCG6OxAhe', 'ToString', 'NiEGd2m8Vr', 'ydAG2e4I7P', 'VQbGPg5Jcw', 'O74GTnf35m', 'iw1GhaxxaK', 'l7bG7BXmHP', 'LYPGRrujTx' |
Source: 0.2.TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe.45fd470.1.raw.unpack, rtPNF2YwxlfdEVDxrl.cs | High entropy of concatenated method names: 'GAN7dExPKi', 'b307PMPUe1', 'k637hhNEMx', 'RwwhBW4Syn', 'KtmhzQSyVO', 'OBH74sqFhx', 'etn7XDI063', 'PgB7LGlfE1', 'TqX7jA5oby', 'TUQ7I4CfOi' |
Source: 0.2.TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe.45fd470.1.raw.unpack, W5VmDo6HmpAgbNZEiu.cs | High entropy of concatenated method names: 'SUUPeJkw3p', 'CKHPvmlX49', 'riCPgHNqd6', 'PpKP9pyFXx', 'CxkPpyhMR7', 'sBKPlFMr86', 'TUtPGycVFG', 'nv6PtOU4vp', 'YLUP5E0whf', 'yXEPZfDNTF' |
Source: 0.2.TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe.45fd470.1.raw.unpack, QgUVtmLMw8PpFR9upN.cs | High entropy of concatenated method names: 'JuyjqubICF', 'adGjdiT4VG', 'G1Lj2rg7J9', 'lFdjPqgoqu', 'APKjT2sUI9', 'a8AjhjZblb', 'gfIj73SfM2', 'VJMjRZG6is', 'DI3jwg3pOC', 'eqcjfcB2V2' |
Source: 0.2.TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe.45fd470.1.raw.unpack, mJTKhIVc7qJwtjTabI.cs | High entropy of concatenated method names: 'cTZ7J7cYNC', 'aDc7bubEX6', 'Gch7rof9kI', 'lXE7eJhLQ3', 'ImL7nb3ykE', 'r227vpCqua', 'X157D4IK4V', 'MCF7gwnQHe', 'XI679DETYL', 'fKZ7cqDSWp' |
Source: 0.2.TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe.45fd470.1.raw.unpack, FcY9ehqsfh4aVO4DAb.cs | High entropy of concatenated method names: 'D2q28UTrCE', 'Y2B2O1qNAl', 'UsS2aZpC1K', 'vLW2mjcXTs', 'CcM2QesN39', 'Hyi21AZKxl', 'CYk2Erijq4', 'vHf2SZEyva', 'q7F20ALLfy', 'uiZ2BWXMey' |
Source: 0.2.TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe.45fd470.1.raw.unpack, NfalMhJ8uA3kaHXvgn.cs | High entropy of concatenated method names: 'ToString', 'tdglMUaySS', 'BMclAsdFte', 'hYZlsxPYEP', 'MK1lkJ0diI', 'dCElo5YxH6', 'JQvl3uxecR', 'PrjlK7yYaC', 'k5TliNlb7R', 'QNRlyNnBHo' |
Source: 0.2.TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe.45fd470.1.raw.unpack, IjoMYfSa29sGRgq0j8.cs | High entropy of concatenated method names: 'vQWr8baQZ', 'Ccae7WApT', 'aVDv3Qkmf', 'aKGDdS7qC', 'Gbm9dAnY8', 'UHGciHeww', 'rtrMBYy51Dp9VwCUMs', 'Cv2kP3WWM0GKyRy3ht', 'z1Lt2Rrlf', 'NgAZ1LGLD' |
Source: 0.2.TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe.45fd470.1.raw.unpack, x64ZxoKhudRg3sF6Kl.cs | High entropy of concatenated method names: 'EditValue', 'GetEditStyle', 'wOtL0N3Xg9', 'hH5LBRHur0', 'rd1LzlS6QM', 'iobj4TwJRY', 'DrrjXiHUKv', 'bHmjLl2JHQ', 'yMEjjykn2a', 'wQ5Z4AFKj0x1Du6XXWu' |
Source: 0.2.TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe.45fd470.1.raw.unpack, lq3FlorROTtpd8nMyY.cs | High entropy of concatenated method names: 'q9ZGSivXxZ', 'CK3GBVQrlu', 'mM5t4fJl6W', 'SsatXaa4E4', 'RLOGMNoVjD', 'NmyGUDJQmN', 'wppGYupSnp', 'lKOG8FVJIn', 'WYBGOsIjVA', 'nb8GaMKfFy' |
Source: 0.2.TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe.45fd470.1.raw.unpack, j7LYTtwUmq2kSe3mU3.cs | High entropy of concatenated method names: 'YbGtWNOd1L', 'FLKtAXxfNV', 'NvktsgnmsX', 'zPrtkVv3rI', 'PULt85cSZV', 'C6AtorPdhg', 'Next', 'Next', 'Next', 'NextBytes' |
Source: 0.2.TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe.45fd470.1.raw.unpack, ns7of4m4T22kQcU5Nm.cs | High entropy of concatenated method names: 'h0vTnik92O', 'CobTDtYk7S', 'T3YPsN1Bxi', 'oF1Pk8jW5X', 'Tw7Poq0ahL', 'SfwP3Np9tC', 'qZ0PKsuXGC', 'BKPPiCe7sB', 'V8hPytjm7x', 'OcjPFSVP1s' |
Source: 0.2.TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe.45fd470.1.raw.unpack, jO0gAth6LXQ4IqyJvc.cs | High entropy of concatenated method names: 'ztttdiG5AS', 'LpBt2Yvjvf', 'VKWtPm63Y6', 'khTtT9NcrD', 'TOAthuxFga', 'dUwt7S8BQe', 'dvKtR1d9M2', 'd8PtwQUkxy', 'EVZtfKRsy1', 'U7Lt6TFfu7' |
Source: 0.2.TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe.45fd470.1.raw.unpack, vqNN8YFCFfqQL6aBZ5H.cs | High entropy of concatenated method names: 'fav5JYFKUS', 'ono5bGF0xe', 'VH35rojooI', 'wss5eusTYN', 'bya5nAEG2Q', 'oLj5vGitbF', 'U5m5DdO3x0', 'SY85gBt50M', 'R3l591KDxO', 'GkI5cwHJe7' |
Source: 0.2.TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe.45fd470.1.raw.unpack, zCNwJdFnQu4puUFchct.cs | High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'dgbZ8cEKSB', 'zQ7ZO1706m', 'FY3Za5nCXY', 'IE3ZmF4FH5', 'kAiZQysu7M', 'YNIZ1BLPUI', 'wOGZEHPB8g' |
Source: 0.2.TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe.45fd470.1.raw.unpack, n6TEH8zCDlVl4HvvYO.cs | High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'ih45NxkWDW', 'FP85psnaKW', 'AFc5lXeqND', 'elM5GeU4di', 'fPs5ttS2Ho', 'qqA55H9qyC', 'u9r5ZCPuaQ' |
Source: 0.2.TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe.45fd470.1.raw.unpack, rC3oiK5rTtspMSI9J1.cs | High entropy of concatenated method names: 'GbmhqLAXWQ', 'w4wh2ynJYM', 'hJFhT6AaXb', 'Rg1h7G0OA5', 'uHchRdmBID', 'I38TQIqQkZ', 'nBgT1pdIWE', 'SUNTEukURZ', 'lTETS1axwi', 'a27T00VZeI' |
Source: 0.2.TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe.45fd470.1.raw.unpack, kG4rDQDRSR9x8fka51.cs | High entropy of concatenated method names: 'Dispose', 'yWdX0a3wNK', 'AQ4LArR3fh', 'K1XxxJ42gs', 'wZ6XBNWLdj', 'OZcXzQ9FkL', 'ProcessDialogKey', 'xf6L4XVVO1', 'IF6LXbwoBN', 'fOWLLYVOFa' |
Source: 0.2.TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe.45fd470.1.raw.unpack, zOP9a9BGA3on5uXvvo.cs | High entropy of concatenated method names: 'mZkNgowxlj', 'UlFN9ov2pV', 'JXuNWWn3fw', 'fZvNAi3n7c', 'E4ZNkSpyP8', 'UTkNonhXMH', 'YqJNKgtGv4', 's1uNiPwjJv', 'K5gNFqPYE4', 'IkBNMrxgyM' |
Source: 0.2.TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe.45fd470.1.raw.unpack, oGQm8v3wF9JwNXXwVH.cs | High entropy of concatenated method names: 'SrZ5XE6Tc5', 'wTX5jTDwuF', 'jap5ILpo1Y', 'g7K5dho5Oh', 'XPE52Kenno', 'ugi5TBgvZ4', 'O7V5hYOpJb', 'T9ftEp89NG', 'GPmtSWNIel', 'u4bt0TceYG' |
Source: 0.2.TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe.45fd470.1.raw.unpack, nUhYvTMom9nagO8Sow.cs | High entropy of concatenated method names: 'o3MX74Mq04', 'uObXReINPD', 'dXTXfBGNYn', 'xPMX6BS3ud', 'u9mXp77NRW', 'KKxXlgLjdq', 'j84tDXVZHiSXNklwPH', 'cBkG1pzyl2MZiLtvHX', 'W0PXXS3Axk', 'UINXj94KpN' |
Source: 0.2.TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe.7cf0000.6.raw.unpack, fb6yvpsy14g5qhnfk0.cs | High entropy of concatenated method names: 'p4hGfKv758', 'CSCG6OxAhe', 'ToString', 'NiEGd2m8Vr', 'ydAG2e4I7P', 'VQbGPg5Jcw', 'O74GTnf35m', 'iw1GhaxxaK', 'l7bG7BXmHP', 'LYPGRrujTx' |
Source: 0.2.TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe.7cf0000.6.raw.unpack, rtPNF2YwxlfdEVDxrl.cs | High entropy of concatenated method names: 'GAN7dExPKi', 'b307PMPUe1', 'k637hhNEMx', 'RwwhBW4Syn', 'KtmhzQSyVO', 'OBH74sqFhx', 'etn7XDI063', 'PgB7LGlfE1', 'TqX7jA5oby', 'TUQ7I4CfOi' |
Source: 0.2.TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe.7cf0000.6.raw.unpack, W5VmDo6HmpAgbNZEiu.cs | High entropy of concatenated method names: 'SUUPeJkw3p', 'CKHPvmlX49', 'riCPgHNqd6', 'PpKP9pyFXx', 'CxkPpyhMR7', 'sBKPlFMr86', 'TUtPGycVFG', 'nv6PtOU4vp', 'YLUP5E0whf', 'yXEPZfDNTF' |
Source: 0.2.TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe.7cf0000.6.raw.unpack, QgUVtmLMw8PpFR9upN.cs | High entropy of concatenated method names: 'JuyjqubICF', 'adGjdiT4VG', 'G1Lj2rg7J9', 'lFdjPqgoqu', 'APKjT2sUI9', 'a8AjhjZblb', 'gfIj73SfM2', 'VJMjRZG6is', 'DI3jwg3pOC', 'eqcjfcB2V2' |
Source: 0.2.TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe.7cf0000.6.raw.unpack, mJTKhIVc7qJwtjTabI.cs | High entropy of concatenated method names: 'cTZ7J7cYNC', 'aDc7bubEX6', 'Gch7rof9kI', 'lXE7eJhLQ3', 'ImL7nb3ykE', 'r227vpCqua', 'X157D4IK4V', 'MCF7gwnQHe', 'XI679DETYL', 'fKZ7cqDSWp' |
Source: 0.2.TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe.7cf0000.6.raw.unpack, FcY9ehqsfh4aVO4DAb.cs | High entropy of concatenated method names: 'D2q28UTrCE', 'Y2B2O1qNAl', 'UsS2aZpC1K', 'vLW2mjcXTs', 'CcM2QesN39', 'Hyi21AZKxl', 'CYk2Erijq4', 'vHf2SZEyva', 'q7F20ALLfy', 'uiZ2BWXMey' |
Source: 0.2.TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe.7cf0000.6.raw.unpack, NfalMhJ8uA3kaHXvgn.cs | High entropy of concatenated method names: 'ToString', 'tdglMUaySS', 'BMclAsdFte', 'hYZlsxPYEP', 'MK1lkJ0diI', 'dCElo5YxH6', 'JQvl3uxecR', 'PrjlK7yYaC', 'k5TliNlb7R', 'QNRlyNnBHo' |
Source: 0.2.TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe.7cf0000.6.raw.unpack, IjoMYfSa29sGRgq0j8.cs | High entropy of concatenated method names: 'vQWr8baQZ', 'Ccae7WApT', 'aVDv3Qkmf', 'aKGDdS7qC', 'Gbm9dAnY8', 'UHGciHeww', 'rtrMBYy51Dp9VwCUMs', 'Cv2kP3WWM0GKyRy3ht', 'z1Lt2Rrlf', 'NgAZ1LGLD' |
Source: 0.2.TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe.7cf0000.6.raw.unpack, x64ZxoKhudRg3sF6Kl.cs | High entropy of concatenated method names: 'EditValue', 'GetEditStyle', 'wOtL0N3Xg9', 'hH5LBRHur0', 'rd1LzlS6QM', 'iobj4TwJRY', 'DrrjXiHUKv', 'bHmjLl2JHQ', 'yMEjjykn2a', 'wQ5Z4AFKj0x1Du6XXWu' |
Source: 0.2.TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe.7cf0000.6.raw.unpack, lq3FlorROTtpd8nMyY.cs | High entropy of concatenated method names: 'q9ZGSivXxZ', 'CK3GBVQrlu', 'mM5t4fJl6W', 'SsatXaa4E4', 'RLOGMNoVjD', 'NmyGUDJQmN', 'wppGYupSnp', 'lKOG8FVJIn', 'WYBGOsIjVA', 'nb8GaMKfFy' |
Source: 0.2.TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe.7cf0000.6.raw.unpack, j7LYTtwUmq2kSe3mU3.cs | High entropy of concatenated method names: 'YbGtWNOd1L', 'FLKtAXxfNV', 'NvktsgnmsX', 'zPrtkVv3rI', 'PULt85cSZV', 'C6AtorPdhg', 'Next', 'Next', 'Next', 'NextBytes' |
Source: 0.2.TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe.7cf0000.6.raw.unpack, ns7of4m4T22kQcU5Nm.cs | High entropy of concatenated method names: 'h0vTnik92O', 'CobTDtYk7S', 'T3YPsN1Bxi', 'oF1Pk8jW5X', 'Tw7Poq0ahL', 'SfwP3Np9tC', 'qZ0PKsuXGC', 'BKPPiCe7sB', 'V8hPytjm7x', 'OcjPFSVP1s' |
Source: 0.2.TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe.7cf0000.6.raw.unpack, jO0gAth6LXQ4IqyJvc.cs | High entropy of concatenated method names: 'ztttdiG5AS', 'LpBt2Yvjvf', 'VKWtPm63Y6', 'khTtT9NcrD', 'TOAthuxFga', 'dUwt7S8BQe', 'dvKtR1d9M2', 'd8PtwQUkxy', 'EVZtfKRsy1', 'U7Lt6TFfu7' |
Source: 0.2.TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe.7cf0000.6.raw.unpack, vqNN8YFCFfqQL6aBZ5H.cs | High entropy of concatenated method names: 'fav5JYFKUS', 'ono5bGF0xe', 'VH35rojooI', 'wss5eusTYN', 'bya5nAEG2Q', 'oLj5vGitbF', 'U5m5DdO3x0', 'SY85gBt50M', 'R3l591KDxO', 'GkI5cwHJe7' |
Source: 0.2.TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe.7cf0000.6.raw.unpack, zCNwJdFnQu4puUFchct.cs | High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'dgbZ8cEKSB', 'zQ7ZO1706m', 'FY3Za5nCXY', 'IE3ZmF4FH5', 'kAiZQysu7M', 'YNIZ1BLPUI', 'wOGZEHPB8g' |
Source: 0.2.TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe.7cf0000.6.raw.unpack, n6TEH8zCDlVl4HvvYO.cs | High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'ih45NxkWDW', 'FP85psnaKW', 'AFc5lXeqND', 'elM5GeU4di', 'fPs5ttS2Ho', 'qqA55H9qyC', 'u9r5ZCPuaQ' |
Source: 0.2.TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe.7cf0000.6.raw.unpack, rC3oiK5rTtspMSI9J1.cs | High entropy of concatenated method names: 'GbmhqLAXWQ', 'w4wh2ynJYM', 'hJFhT6AaXb', 'Rg1h7G0OA5', 'uHchRdmBID', 'I38TQIqQkZ', 'nBgT1pdIWE', 'SUNTEukURZ', 'lTETS1axwi', 'a27T00VZeI' |
Source: 0.2.TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe.7cf0000.6.raw.unpack, kG4rDQDRSR9x8fka51.cs | High entropy of concatenated method names: 'Dispose', 'yWdX0a3wNK', 'AQ4LArR3fh', 'K1XxxJ42gs', 'wZ6XBNWLdj', 'OZcXzQ9FkL', 'ProcessDialogKey', 'xf6L4XVVO1', 'IF6LXbwoBN', 'fOWLLYVOFa' |
Source: 0.2.TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe.7cf0000.6.raw.unpack, zOP9a9BGA3on5uXvvo.cs | High entropy of concatenated method names: 'mZkNgowxlj', 'UlFN9ov2pV', 'JXuNWWn3fw', 'fZvNAi3n7c', 'E4ZNkSpyP8', 'UTkNonhXMH', 'YqJNKgtGv4', 's1uNiPwjJv', 'K5gNFqPYE4', 'IkBNMrxgyM' |
Source: 0.2.TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe.7cf0000.6.raw.unpack, oGQm8v3wF9JwNXXwVH.cs | High entropy of concatenated method names: 'SrZ5XE6Tc5', 'wTX5jTDwuF', 'jap5ILpo1Y', 'g7K5dho5Oh', 'XPE52Kenno', 'ugi5TBgvZ4', 'O7V5hYOpJb', 'T9ftEp89NG', 'GPmtSWNIel', 'u4bt0TceYG' |
Source: 0.2.TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe.7cf0000.6.raw.unpack, nUhYvTMom9nagO8Sow.cs | High entropy of concatenated method names: 'o3MX74Mq04', 'uObXReINPD', 'dXTXfBGNYn', 'xPMX6BS3ud', 'u9mXp77NRW', 'KKxXlgLjdq', 'j84tDXVZHiSXNklwPH', 'cBkG1pzyl2MZiLtvHX', 'W0PXXS3Axk', 'UINXj94KpN' |
Source: 0.2.TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe.4453ec0.4.raw.unpack, fb6yvpsy14g5qhnfk0.cs | High entropy of concatenated method names: 'p4hGfKv758', 'CSCG6OxAhe', 'ToString', 'NiEGd2m8Vr', 'ydAG2e4I7P', 'VQbGPg5Jcw', 'O74GTnf35m', 'iw1GhaxxaK', 'l7bG7BXmHP', 'LYPGRrujTx' |
Source: 0.2.TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe.4453ec0.4.raw.unpack, rtPNF2YwxlfdEVDxrl.cs | High entropy of concatenated method names: 'GAN7dExPKi', 'b307PMPUe1', 'k637hhNEMx', 'RwwhBW4Syn', 'KtmhzQSyVO', 'OBH74sqFhx', 'etn7XDI063', 'PgB7LGlfE1', 'TqX7jA5oby', 'TUQ7I4CfOi' |
Source: 0.2.TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe.4453ec0.4.raw.unpack, W5VmDo6HmpAgbNZEiu.cs | High entropy of concatenated method names: 'SUUPeJkw3p', 'CKHPvmlX49', 'riCPgHNqd6', 'PpKP9pyFXx', 'CxkPpyhMR7', 'sBKPlFMr86', 'TUtPGycVFG', 'nv6PtOU4vp', 'YLUP5E0whf', 'yXEPZfDNTF' |
Source: 0.2.TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe.4453ec0.4.raw.unpack, QgUVtmLMw8PpFR9upN.cs | High entropy of concatenated method names: 'JuyjqubICF', 'adGjdiT4VG', 'G1Lj2rg7J9', 'lFdjPqgoqu', 'APKjT2sUI9', 'a8AjhjZblb', 'gfIj73SfM2', 'VJMjRZG6is', 'DI3jwg3pOC', 'eqcjfcB2V2' |
Source: 0.2.TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe.4453ec0.4.raw.unpack, mJTKhIVc7qJwtjTabI.cs | High entropy of concatenated method names: 'cTZ7J7cYNC', 'aDc7bubEX6', 'Gch7rof9kI', 'lXE7eJhLQ3', 'ImL7nb3ykE', 'r227vpCqua', 'X157D4IK4V', 'MCF7gwnQHe', 'XI679DETYL', 'fKZ7cqDSWp' |
Source: 0.2.TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe.4453ec0.4.raw.unpack, FcY9ehqsfh4aVO4DAb.cs | High entropy of concatenated method names: 'D2q28UTrCE', 'Y2B2O1qNAl', 'UsS2aZpC1K', 'vLW2mjcXTs', 'CcM2QesN39', 'Hyi21AZKxl', 'CYk2Erijq4', 'vHf2SZEyva', 'q7F20ALLfy', 'uiZ2BWXMey' |
Source: 0.2.TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe.4453ec0.4.raw.unpack, NfalMhJ8uA3kaHXvgn.cs | High entropy of concatenated method names: 'ToString', 'tdglMUaySS', 'BMclAsdFte', 'hYZlsxPYEP', 'MK1lkJ0diI', 'dCElo5YxH6', 'JQvl3uxecR', 'PrjlK7yYaC', 'k5TliNlb7R', 'QNRlyNnBHo' |
Source: 0.2.TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe.4453ec0.4.raw.unpack, IjoMYfSa29sGRgq0j8.cs | High entropy of concatenated method names: 'vQWr8baQZ', 'Ccae7WApT', 'aVDv3Qkmf', 'aKGDdS7qC', 'Gbm9dAnY8', 'UHGciHeww', 'rtrMBYy51Dp9VwCUMs', 'Cv2kP3WWM0GKyRy3ht', 'z1Lt2Rrlf', 'NgAZ1LGLD' |
Source: 0.2.TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe.4453ec0.4.raw.unpack, x64ZxoKhudRg3sF6Kl.cs | High entropy of concatenated method names: 'EditValue', 'GetEditStyle', 'wOtL0N3Xg9', 'hH5LBRHur0', 'rd1LzlS6QM', 'iobj4TwJRY', 'DrrjXiHUKv', 'bHmjLl2JHQ', 'yMEjjykn2a', 'wQ5Z4AFKj0x1Du6XXWu' |
Source: 0.2.TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe.4453ec0.4.raw.unpack, lq3FlorROTtpd8nMyY.cs | High entropy of concatenated method names: 'q9ZGSivXxZ', 'CK3GBVQrlu', 'mM5t4fJl6W', 'SsatXaa4E4', 'RLOGMNoVjD', 'NmyGUDJQmN', 'wppGYupSnp', 'lKOG8FVJIn', 'WYBGOsIjVA', 'nb8GaMKfFy' |
Source: 0.2.TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe.4453ec0.4.raw.unpack, j7LYTtwUmq2kSe3mU3.cs | High entropy of concatenated method names: 'YbGtWNOd1L', 'FLKtAXxfNV', 'NvktsgnmsX', 'zPrtkVv3rI', 'PULt85cSZV', 'C6AtorPdhg', 'Next', 'Next', 'Next', 'NextBytes' |
Source: 0.2.TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe.4453ec0.4.raw.unpack, ns7of4m4T22kQcU5Nm.cs | High entropy of concatenated method names: 'h0vTnik92O', 'CobTDtYk7S', 'T3YPsN1Bxi', 'oF1Pk8jW5X', 'Tw7Poq0ahL', 'SfwP3Np9tC', 'qZ0PKsuXGC', 'BKPPiCe7sB', 'V8hPytjm7x', 'OcjPFSVP1s' |
Source: 0.2.TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe.4453ec0.4.raw.unpack, jO0gAth6LXQ4IqyJvc.cs | High entropy of concatenated method names: 'ztttdiG5AS', 'LpBt2Yvjvf', 'VKWtPm63Y6', 'khTtT9NcrD', 'TOAthuxFga', 'dUwt7S8BQe', 'dvKtR1d9M2', 'd8PtwQUkxy', 'EVZtfKRsy1', 'U7Lt6TFfu7' |
Source: 0.2.TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe.4453ec0.4.raw.unpack, vqNN8YFCFfqQL6aBZ5H.cs | High entropy of concatenated method names: 'fav5JYFKUS', 'ono5bGF0xe', 'VH35rojooI', 'wss5eusTYN', 'bya5nAEG2Q', 'oLj5vGitbF', 'U5m5DdO3x0', 'SY85gBt50M', 'R3l591KDxO', 'GkI5cwHJe7' |
Source: 0.2.TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe.4453ec0.4.raw.unpack, zCNwJdFnQu4puUFchct.cs | High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'dgbZ8cEKSB', 'zQ7ZO1706m', 'FY3Za5nCXY', 'IE3ZmF4FH5', 'kAiZQysu7M', 'YNIZ1BLPUI', 'wOGZEHPB8g' |
Source: 0.2.TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe.4453ec0.4.raw.unpack, n6TEH8zCDlVl4HvvYO.cs | High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'ih45NxkWDW', 'FP85psnaKW', 'AFc5lXeqND', 'elM5GeU4di', 'fPs5ttS2Ho', 'qqA55H9qyC', 'u9r5ZCPuaQ' |
Source: 0.2.TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe.4453ec0.4.raw.unpack, rC3oiK5rTtspMSI9J1.cs | High entropy of concatenated method names: 'GbmhqLAXWQ', 'w4wh2ynJYM', 'hJFhT6AaXb', 'Rg1h7G0OA5', 'uHchRdmBID', 'I38TQIqQkZ', 'nBgT1pdIWE', 'SUNTEukURZ', 'lTETS1axwi', 'a27T00VZeI' |
Source: 0.2.TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe.4453ec0.4.raw.unpack, kG4rDQDRSR9x8fka51.cs | High entropy of concatenated method names: 'Dispose', 'yWdX0a3wNK', 'AQ4LArR3fh', 'K1XxxJ42gs', 'wZ6XBNWLdj', 'OZcXzQ9FkL', 'ProcessDialogKey', 'xf6L4XVVO1', 'IF6LXbwoBN', 'fOWLLYVOFa' |
Source: 0.2.TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe.4453ec0.4.raw.unpack, zOP9a9BGA3on5uXvvo.cs | High entropy of concatenated method names: 'mZkNgowxlj', 'UlFN9ov2pV', 'JXuNWWn3fw', 'fZvNAi3n7c', 'E4ZNkSpyP8', 'UTkNonhXMH', 'YqJNKgtGv4', 's1uNiPwjJv', 'K5gNFqPYE4', 'IkBNMrxgyM' |
Source: 0.2.TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe.4453ec0.4.raw.unpack, oGQm8v3wF9JwNXXwVH.cs | High entropy of concatenated method names: 'SrZ5XE6Tc5', 'wTX5jTDwuF', 'jap5ILpo1Y', 'g7K5dho5Oh', 'XPE52Kenno', 'ugi5TBgvZ4', 'O7V5hYOpJb', 'T9ftEp89NG', 'GPmtSWNIel', 'u4bt0TceYG' |
Source: 0.2.TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe.4453ec0.4.raw.unpack, nUhYvTMom9nagO8Sow.cs | High entropy of concatenated method names: 'o3MX74Mq04', 'uObXReINPD', 'dXTXfBGNYn', 'xPMX6BS3ud', 'u9mXp77NRW', 'KKxXlgLjdq', 'j84tDXVZHiSXNklwPH', 'cBkG1pzyl2MZiLtvHX', 'W0PXXS3Axk', 'UINXj94KpN' |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Thread delayed: delay time: 600000 | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Thread delayed: delay time: 599874 | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Thread delayed: delay time: 599764 | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Thread delayed: delay time: 599654 | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Thread delayed: delay time: 599546 | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Thread delayed: delay time: 599437 | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Thread delayed: delay time: 599328 | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Thread delayed: delay time: 599218 | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Thread delayed: delay time: 599109 | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Thread delayed: delay time: 598999 | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Thread delayed: delay time: 598890 | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Thread delayed: delay time: 598781 | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Thread delayed: delay time: 598671 | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Thread delayed: delay time: 598562 | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Thread delayed: delay time: 598453 | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Thread delayed: delay time: 598341 | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Thread delayed: delay time: 598233 | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Thread delayed: delay time: 598124 | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Thread delayed: delay time: 598015 | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Thread delayed: delay time: 597906 | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Thread delayed: delay time: 597796 | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Thread delayed: delay time: 597687 | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Thread delayed: delay time: 597577 | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Thread delayed: delay time: 597468 | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Thread delayed: delay time: 597359 | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Thread delayed: delay time: 597248 | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Thread delayed: delay time: 597140 | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Thread delayed: delay time: 597030 | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Thread delayed: delay time: 596921 | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Thread delayed: delay time: 596812 | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Thread delayed: delay time: 596703 | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Thread delayed: delay time: 596593 | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Thread delayed: delay time: 596484 | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Thread delayed: delay time: 596374 | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Thread delayed: delay time: 596265 | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Thread delayed: delay time: 596156 | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Thread delayed: delay time: 596046 | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Thread delayed: delay time: 595937 | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Thread delayed: delay time: 595828 | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Thread delayed: delay time: 595718 | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Thread delayed: delay time: 595609 | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Thread delayed: delay time: 595499 | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Thread delayed: delay time: 595390 | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Thread delayed: delay time: 595280 | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Thread delayed: delay time: 595171 | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Thread delayed: delay time: 595062 | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Thread delayed: delay time: 594953 | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Thread delayed: delay time: 594843 | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Thread delayed: delay time: 594734 | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Thread delayed: delay time: 594624 | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Thread delayed: delay time: 922337203685477 | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Thread delayed: delay time: 600000 | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Thread delayed: delay time: 599875 | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Thread delayed: delay time: 599765 | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Thread delayed: delay time: 599656 | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Thread delayed: delay time: 599547 | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Thread delayed: delay time: 599437 | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Thread delayed: delay time: 599328 | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Thread delayed: delay time: 599219 | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Thread delayed: delay time: 599094 | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Thread delayed: delay time: 598984 | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Thread delayed: delay time: 598875 | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Thread delayed: delay time: 598765 | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Thread delayed: delay time: 598656 | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Thread delayed: delay time: 598547 | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Thread delayed: delay time: 598438 | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Thread delayed: delay time: 598313 | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Thread delayed: delay time: 598188 | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Thread delayed: delay time: 598078 | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Thread delayed: delay time: 597969 | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Thread delayed: delay time: 597844 | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Thread delayed: delay time: 597734 | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Thread delayed: delay time: 597625 | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Thread delayed: delay time: 597516 | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Thread delayed: delay time: 597406 | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Thread delayed: delay time: 597294 | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Thread delayed: delay time: 597185 | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Thread delayed: delay time: 597074 | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Thread delayed: delay time: 596967 | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Thread delayed: delay time: 596827 | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Thread delayed: delay time: 596650 | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Thread delayed: delay time: 596345 | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Thread delayed: delay time: 596219 | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Thread delayed: delay time: 596109 | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Thread delayed: delay time: 596000 | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Thread delayed: delay time: 595891 | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Thread delayed: delay time: 595781 | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Thread delayed: delay time: 595662 | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Thread delayed: delay time: 595547 | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Thread delayed: delay time: 595437 | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Thread delayed: delay time: 595328 | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Thread delayed: delay time: 595216 | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Thread delayed: delay time: 595109 | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Thread delayed: delay time: 594997 | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Thread delayed: delay time: 594890 | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Thread delayed: delay time: 594781 | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Thread delayed: delay time: 594671 | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Thread delayed: delay time: 594562 | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Thread delayed: delay time: 594452 | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Thread delayed: delay time: 594344 | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Thread delayed: delay time: 594234 | |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe TID: 7484 | Thread sleep time: -922337203685477s >= -30000s | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe TID: 7784 | Thread sleep count: 6211 > 30 | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe TID: 7980 | Thread sleep time: -2767011611056431s >= -30000s | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe TID: 7784 | Thread sleep count: 92 > 30 | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe TID: 7876 | Thread sleep time: -1844674407370954s >= -30000s | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe TID: 8032 | Thread sleep time: -3689348814741908s >= -30000s | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe TID: 7984 | Thread sleep time: -922337203685477s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe TID: 8132 | Thread sleep count: 31 > 30 | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe TID: 8132 | Thread sleep time: -28592453314249787s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe TID: 8132 | Thread sleep time: -600000s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe TID: 8136 | Thread sleep count: 3461 > 30 | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe TID: 8132 | Thread sleep time: -599874s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe TID: 8136 | Thread sleep count: 6395 > 30 | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe TID: 8132 | Thread sleep time: -599764s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe TID: 8132 | Thread sleep time: -599654s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe TID: 8132 | Thread sleep time: -599546s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe TID: 8132 | Thread sleep time: -599437s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe TID: 8132 | Thread sleep time: -599328s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe TID: 8132 | Thread sleep time: -599218s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe TID: 8132 | Thread sleep time: -599109s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe TID: 8132 | Thread sleep time: -598999s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe TID: 8132 | Thread sleep time: -598890s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe TID: 8132 | Thread sleep time: -598781s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe TID: 8132 | Thread sleep time: -598671s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe TID: 8132 | Thread sleep time: -598562s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe TID: 8132 | Thread sleep time: -598453s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe TID: 8132 | Thread sleep time: -598341s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe TID: 8132 | Thread sleep time: -598233s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe TID: 8132 | Thread sleep time: -598124s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe TID: 8132 | Thread sleep time: -598015s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe TID: 8132 | Thread sleep time: -597906s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe TID: 8132 | Thread sleep time: -597796s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe TID: 8132 | Thread sleep time: -597687s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe TID: 8132 | Thread sleep time: -597577s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe TID: 8132 | Thread sleep time: -597468s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe TID: 8132 | Thread sleep time: -597359s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe TID: 8132 | Thread sleep time: -597248s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe TID: 8132 | Thread sleep time: -597140s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe TID: 8132 | Thread sleep time: -597030s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe TID: 8132 | Thread sleep time: -596921s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe TID: 8132 | Thread sleep time: -596812s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe TID: 8132 | Thread sleep time: -596703s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe TID: 8132 | Thread sleep time: -596593s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe TID: 8132 | Thread sleep time: -596484s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe TID: 8132 | Thread sleep time: -596374s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe TID: 8132 | Thread sleep time: -596265s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe TID: 8132 | Thread sleep time: -596156s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe TID: 8132 | Thread sleep time: -596046s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe TID: 8132 | Thread sleep time: -595937s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe TID: 8132 | Thread sleep time: -595828s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe TID: 8132 | Thread sleep time: -595718s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe TID: 8132 | Thread sleep time: -595609s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe TID: 8132 | Thread sleep time: -595499s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe TID: 8132 | Thread sleep time: -595390s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe TID: 8132 | Thread sleep time: -595280s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe TID: 8132 | Thread sleep time: -595171s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe TID: 8132 | Thread sleep time: -595062s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe TID: 8132 | Thread sleep time: -594953s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe TID: 8132 | Thread sleep time: -594843s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe TID: 8132 | Thread sleep time: -594734s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe TID: 8132 | Thread sleep time: -594624s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe TID: 8068 | Thread sleep time: -922337203685477s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe TID: 6896 | Thread sleep count: 35 > 30 | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe TID: 6896 | Thread sleep time: -32281802128991695s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe TID: 6896 | Thread sleep time: -600000s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe TID: 2868 | Thread sleep count: 3586 > 30 | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe TID: 6896 | Thread sleep time: -599875s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe TID: 2868 | Thread sleep count: 6252 > 30 | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe TID: 6896 | Thread sleep time: -599765s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe TID: 6896 | Thread sleep time: -599656s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe TID: 6896 | Thread sleep time: -599547s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe TID: 6896 | Thread sleep time: -599437s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe TID: 6896 | Thread sleep time: -599328s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe TID: 6896 | Thread sleep time: -599219s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe TID: 6896 | Thread sleep time: -599094s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe TID: 6896 | Thread sleep time: -598984s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe TID: 6896 | Thread sleep time: -598875s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe TID: 6896 | Thread sleep time: -598765s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe TID: 6896 | Thread sleep time: -598656s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe TID: 6896 | Thread sleep time: -598547s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe TID: 6896 | Thread sleep time: -598438s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe TID: 6896 | Thread sleep time: -598313s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe TID: 6896 | Thread sleep time: -598188s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe TID: 6896 | Thread sleep time: -598078s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe TID: 6896 | Thread sleep time: -597969s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe TID: 6896 | Thread sleep time: -597844s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe TID: 6896 | Thread sleep time: -597734s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe TID: 6896 | Thread sleep time: -597625s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe TID: 6896 | Thread sleep time: -597516s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe TID: 6896 | Thread sleep time: -597406s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe TID: 6896 | Thread sleep time: -597294s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe TID: 6896 | Thread sleep time: -597185s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe TID: 6896 | Thread sleep time: -597074s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe TID: 6896 | Thread sleep time: -596967s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe TID: 6896 | Thread sleep time: -596827s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe TID: 6896 | Thread sleep time: -596650s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe TID: 6896 | Thread sleep time: -596345s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe TID: 6896 | Thread sleep time: -596219s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe TID: 6896 | Thread sleep time: -596109s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe TID: 6896 | Thread sleep time: -596000s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe TID: 6896 | Thread sleep time: -595891s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe TID: 6896 | Thread sleep time: -595781s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe TID: 6896 | Thread sleep time: -595662s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe TID: 6896 | Thread sleep time: -595547s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe TID: 6896 | Thread sleep time: -595437s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe TID: 6896 | Thread sleep time: -595328s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe TID: 6896 | Thread sleep time: -595216s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe TID: 6896 | Thread sleep time: -595109s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe TID: 6896 | Thread sleep time: -594997s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe TID: 6896 | Thread sleep time: -594890s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe TID: 6896 | Thread sleep time: -594781s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe TID: 6896 | Thread sleep time: -594671s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe TID: 6896 | Thread sleep time: -594562s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe TID: 6896 | Thread sleep time: -594452s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe TID: 6896 | Thread sleep time: -594344s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe TID: 6896 | Thread sleep time: -594234s >= -30000s | |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Thread delayed: delay time: 600000 | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Thread delayed: delay time: 599874 | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Thread delayed: delay time: 599764 | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Thread delayed: delay time: 599654 | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Thread delayed: delay time: 599546 | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Thread delayed: delay time: 599437 | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Thread delayed: delay time: 599328 | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Thread delayed: delay time: 599218 | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Thread delayed: delay time: 599109 | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Thread delayed: delay time: 598999 | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Thread delayed: delay time: 598890 | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Thread delayed: delay time: 598781 | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Thread delayed: delay time: 598671 | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Thread delayed: delay time: 598562 | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Thread delayed: delay time: 598453 | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Thread delayed: delay time: 598341 | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Thread delayed: delay time: 598233 | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Thread delayed: delay time: 598124 | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Thread delayed: delay time: 598015 | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Thread delayed: delay time: 597906 | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Thread delayed: delay time: 597796 | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Thread delayed: delay time: 597687 | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Thread delayed: delay time: 597577 | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Thread delayed: delay time: 597468 | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Thread delayed: delay time: 597359 | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Thread delayed: delay time: 597248 | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Thread delayed: delay time: 597140 | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Thread delayed: delay time: 597030 | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Thread delayed: delay time: 596921 | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Thread delayed: delay time: 596812 | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Thread delayed: delay time: 596703 | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Thread delayed: delay time: 596593 | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Thread delayed: delay time: 596484 | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Thread delayed: delay time: 596374 | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Thread delayed: delay time: 596265 | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Thread delayed: delay time: 596156 | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Thread delayed: delay time: 596046 | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Thread delayed: delay time: 595937 | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Thread delayed: delay time: 595828 | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Thread delayed: delay time: 595718 | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Thread delayed: delay time: 595609 | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Thread delayed: delay time: 595499 | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Thread delayed: delay time: 595390 | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Thread delayed: delay time: 595280 | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Thread delayed: delay time: 595171 | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Thread delayed: delay time: 595062 | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Thread delayed: delay time: 594953 | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Thread delayed: delay time: 594843 | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Thread delayed: delay time: 594734 | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Thread delayed: delay time: 594624 | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Thread delayed: delay time: 922337203685477 | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Thread delayed: delay time: 600000 | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Thread delayed: delay time: 599875 | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Thread delayed: delay time: 599765 | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Thread delayed: delay time: 599656 | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Thread delayed: delay time: 599547 | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Thread delayed: delay time: 599437 | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Thread delayed: delay time: 599328 | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Thread delayed: delay time: 599219 | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Thread delayed: delay time: 599094 | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Thread delayed: delay time: 598984 | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Thread delayed: delay time: 598875 | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Thread delayed: delay time: 598765 | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Thread delayed: delay time: 598656 | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Thread delayed: delay time: 598547 | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Thread delayed: delay time: 598438 | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Thread delayed: delay time: 598313 | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Thread delayed: delay time: 598188 | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Thread delayed: delay time: 598078 | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Thread delayed: delay time: 597969 | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Thread delayed: delay time: 597844 | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Thread delayed: delay time: 597734 | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Thread delayed: delay time: 597625 | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Thread delayed: delay time: 597516 | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Thread delayed: delay time: 597406 | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Thread delayed: delay time: 597294 | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Thread delayed: delay time: 597185 | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Thread delayed: delay time: 597074 | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Thread delayed: delay time: 596967 | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Thread delayed: delay time: 596827 | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Thread delayed: delay time: 596650 | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Thread delayed: delay time: 596345 | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Thread delayed: delay time: 596219 | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Thread delayed: delay time: 596109 | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Thread delayed: delay time: 596000 | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Thread delayed: delay time: 595891 | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Thread delayed: delay time: 595781 | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Thread delayed: delay time: 595662 | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Thread delayed: delay time: 595547 | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Thread delayed: delay time: 595437 | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Thread delayed: delay time: 595328 | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Thread delayed: delay time: 595216 | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Thread delayed: delay time: 595109 | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Thread delayed: delay time: 594997 | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Thread delayed: delay time: 594890 | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Thread delayed: delay time: 594781 | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Thread delayed: delay time: 594671 | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Thread delayed: delay time: 594562 | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Thread delayed: delay time: 594452 | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Thread delayed: delay time: 594344 | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Thread delayed: delay time: 594234 | |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Queries volume information: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Queries volume information: C:\Windows\Fonts\GOTHIC.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Queries volume information: C:\Windows\Fonts\GOTHICI.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Queries volume information: C:\Windows\Fonts\GOTHICB.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Queries volume information: C:\Windows\Fonts\GOTHICBI.TTF VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\ VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-GroupPolicy-ClientTools-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-AppManagement-AppV-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\Microsoft.Management.Infrastructure.Native\v4.0_1.0.0.0__31bf3856ad364e35\Microsoft.Management.Infrastructure.Native.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\AppvClient\Microsoft.AppV.AppVClientPowerShell.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1865.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-WOW64-Package~31bf3856ad364e35~amd64~en-GB~10.0.19041.1.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\BitLocker\Microsoft.BitLocker.Structures.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management\v4.0_3.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Management.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\ VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-GroupPolicy-ClientTools-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-AppManagement-AppV-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\Microsoft.Management.Infrastructure.Native\v4.0_1.0.0.0__31bf3856ad364e35\Microsoft.Management.Infrastructure.Native.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\AppvClient\Microsoft.AppV.AppVClientPowerShell.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1865.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-WOW64-Package~31bf3856ad364e35~amd64~en-GB~10.0.19041.1.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\BitLocker\Microsoft.BitLocker.Structures.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management\v4.0_3.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Management.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Queries volume information: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.Extensions\v4.0_4.0.0.0__31bf3856ad364e35\System.Web.Extensions.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Security\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Security.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\TEKL#U0130F TALEP VE F#U0130YAT TEKL#U0130F#U0130_xlsx.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Queries volume information: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Queries volume information: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe VolumeInformation | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.Extensions\v4.0_4.0.0.0__31bf3856ad364e35\System.Web.Extensions.dll VolumeInformation | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Security\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Security.dll VolumeInformation | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation | |
Source: C:\Users\user\AppData\Roaming\YzkHZRBcm.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation | |