Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Code function: 9_2_6FDCEFE1 _stat32,__doserrno,_errno,_invalid_parameter_noinfo,_mbspbrk,_errno,__doserrno,_mbctolower,_getdrive,FindFirstFileExA,_mbspbrk,strlen,GetDriveTypeA,free,free,_sopen_s,_fstat32,_close,FileTimeToLocalFileTime,FileTimeToSystemTime,FileTimeToLocalFileTime,FileTimeToSystemTime,FileTimeToLocalFileTime,FileTimeToSystemTime,FindClose,GetLastError,_dosmaperr,FindClose, |
9_2_6FDCEFE1 |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Code function: 9_2_6FDD0F84 _wstat32i64,__doserrno,_errno,_invalid_parameter_noinfo,wcspbrk,_errno,__doserrno,towlower,_getdrive,FindFirstFileExW,wcspbrk,wcslen,GetDriveTypeW,free,free,_wsopen_s,_fstat32i64,_close,FileTimeToLocalFileTime,FileTimeToSystemTime,FileTimeToLocalFileTime,FileTimeToSystemTime,FileTimeToLocalFileTime,FileTimeToSystemTime,FindClose,GetLastError,_dosmaperr,FindClose, |
9_2_6FDD0F84 |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Code function: 9_2_6FDD0B33 _wstat64,__doserrno,_errno,_invalid_parameter_noinfo,wcspbrk,_errno,__doserrno,towlower,_getdrive,FindFirstFileExW,wcspbrk,wcslen,GetDriveTypeW,free,free,_wsopen_s,_fstat64,_close,FileTimeToLocalFileTime,FileTimeToSystemTime,FileTimeToLocalFileTime,FileTimeToSystemTime,FileTimeToLocalFileTime,FileTimeToSystemTime,FindClose,GetLastError,_dosmaperr,FindClose, |
9_2_6FDD0B33 |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Code function: 9_2_6FDCCA9B _malloc_crt,FindClose,FindFirstFileExW,FindNextFileW,FindClose, |
9_2_6FDCCA9B |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Code function: 9_2_6FDCC775 _malloc_crt,FindClose,FindFirstFileExA,FindNextFileA,FindClose, |
9_2_6FDCC775 |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Code function: 9_2_6FDD0702 _wstat32,__doserrno,_errno,_invalid_parameter_noinfo,wcspbrk,_errno,__doserrno,towlower,_getdrive,FindFirstFileExW,wcspbrk,wcslen,GetDriveTypeW,free,free,_wsopen_s,_fstat32,_close,FileTimeToLocalFileTime,FileTimeToSystemTime,FileTimeToLocalFileTime,FileTimeToSystemTime,FileTimeToLocalFileTime,FileTimeToSystemTime,FindClose,GetLastError,_dosmaperr,FindClose, |
9_2_6FDD0702 |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Code function: 9_2_6FDCDF35 _wfindfirst32,_errno,_invalid_parameter_noinfo,FindFirstFileExW,GetLastError,_errno,_errno,_errno,wcscpy_s,_invoke_watson,_wfindnext32,_errno,_invalid_parameter_noinfo,_errno,_invalid_parameter_noinfo,FindNextFileW,GetLastError,_errno,_errno,_errno,wcscpy_s,_invoke_watson,_wfindfirst64,_errno,_invalid_parameter_noinfo,FindFirstFileExW,GetLastError,_errno,_errno,_errno,wcscpy_s,_invoke_watson,_wfindnext64,_errno,_invalid_parameter_noinfo,_errno,_invalid_parameter_noinfo,FindNextFileW,GetLastError,_errno,_errno,_errno,wcscpy_s,_invoke_watson,_wfindfirst64i32,_errno,_invalid_parameter_noinfo,FindFirstFileExW,GetLastError,_errno,_errno,_errno,wcscpy_s,_invoke_watson,_wfindnext64i32,_errno,_invalid_parameter_noinfo,_errno,_invalid_parameter_noinfo,FindNextFileW,GetLastError,_errno,_errno,_errno,wcscpy_s,_invoke_watson,_wfindfirst32i64,_errno,_invalid_parameter_noinfo,FindFirstFileExW,GetLastError,_errno,_errno,_errno,wcscpy_s,_invoke_watson,_wfindnext32i64,_errno,_invalid_parameter_noinfo,_errno,_invalid_parameter_noinfo,FindNextFileW,GetLastError,_errno,_errno,_errno,wcscpy_s,_invoke_watson, |
9_2_6FDCDF35 |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Code function: 9_2_6FDCFD86 _stat32i64,__doserrno,_errno,_invalid_parameter_noinfo,_mbspbrk,_errno,__doserrno,_mbctolower,_getdrive,FindFirstFileExA,_mbspbrk,strlen,GetDriveTypeA,free,free,_sopen_s,_fstat32i64,_close,FileTimeToLocalFileTime,FileTimeToSystemTime,FileTimeToLocalFileTime,FileTimeToSystemTime,FileTimeToLocalFileTime,FileTimeToSystemTime,FindClose,GetLastError,_dosmaperr,FindClose, |
9_2_6FDCFD86 |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Code function: 9_2_6FD97C6D _wstat64i32,wcspbrk,_getdrive,FindFirstFileExW,wcspbrk,wcslen,_errno,__doserrno,__doserrno,_errno,_invalid_parameter_noinfo,towlower,GetDriveTypeW,free,free,_wsopen_s,_fstat64i32,_close,FileTimeToLocalFileTime,FileTimeToSystemTime,FileTimeToLocalFileTime,FileTimeToSystemTime,FileTimeToLocalFileTime,FileTimeToSystemTime,FindClose,GetLastError,_dosmaperr,FindClose, |
9_2_6FD97C6D |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Code function: 9_2_6FDCDA38 _findfirst64i32,_errno,_invalid_parameter_noinfo,FindFirstFileExA,GetLastError,_errno,_errno,_errno,strcpy_s,_invoke_watson,_findnext64i32,_errno,_invalid_parameter_noinfo,_errno,_invalid_parameter_noinfo,FindNextFileA,GetLastError,_errno,_errno,_errno,strcpy_s,_invoke_watson,_findfirst32i64,_errno,_invalid_parameter_noinfo,FindFirstFileExA,GetLastError,_errno,_errno,_errno,strcpy_s,_invoke_watson,_findnext32i64,_errno,_invalid_parameter_noinfo,_errno,_invalid_parameter_noinfo,FindNextFileA,GetLastError,_errno,_errno,_errno,strcpy_s,_invoke_watson,_seterrormode,SetErrorMode, |
9_2_6FDCDA38 |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Code function: 9_2_6FDCF8B5 _stat64i32,__doserrno,_errno,_invalid_parameter_noinfo,_mbspbrk,_errno,__doserrno,_mbctolower,_getdrive,FindFirstFileExA,_mbspbrk,strlen,GetDriveTypeA,free,free,_sopen_s,_fstat64i32,_close,FileTimeToLocalFileTime,FileTimeToSystemTime,FileTimeToLocalFileTime,FileTimeToSystemTime,FileTimeToLocalFileTime,FileTimeToSystemTime,FindClose,GetLastError,_dosmaperr,FindClose, |
9_2_6FDCF8B5 |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Code function: 9_2_6FDCD4FF _findfirst32,_errno,_invalid_parameter_noinfo,FindFirstFileExA,GetLastError,_errno,_errno,_errno,strcpy_s,_invoke_watson,_findnext32,_errno,_invalid_parameter_noinfo,_errno,_invalid_parameter_noinfo,FindNextFileA,GetLastError,_errno,_errno,_errno,strcpy_s,_invoke_watson,_findfirst64,_errno,_invalid_parameter_noinfo,FindFirstFileExA,GetLastError,_errno,_errno,_errno,strcpy_s,_invoke_watson,_findnext64,_errno,_invalid_parameter_noinfo,_errno,_invalid_parameter_noinfo,FindNextFileA,GetLastError,_errno,_errno,_errno,strcpy_s,_invoke_watson, |
9_2_6FDCD4FF |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Code function: 9_2_6FDCF40B _stat64,__doserrno,_errno,_invalid_parameter_noinfo,_mbspbrk,_errno,__doserrno,_mbctolower,_getdrive,FindFirstFileExA,_mbspbrk,strlen,GetDriveTypeA,free,free,_sopen_s,_fstat64,_close,FileTimeToLocalFileTime,FileTimeToSystemTime,FileTimeToLocalFileTime,FileTimeToSystemTime,FileTimeToLocalFileTime,FileTimeToSystemTime,FindClose,GetLastError,_dosmaperr,FindClose, |
9_2_6FDCF40B |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Code function: 11_2_6FDCEFE1 _stat32,__doserrno,_errno,_invalid_parameter_noinfo,_mbspbrk,_errno,__doserrno,_mbctolower,_getdrive,FindFirstFileExA,_mbspbrk,strlen,GetDriveTypeA,free,free,_sopen_s,_fstat32,_close,FileTimeToLocalFileTime,FileTimeToSystemTime,FileTimeToLocalFileTime,FileTimeToSystemTime,FileTimeToLocalFileTime,FileTimeToSystemTime,FindClose,GetLastError,_dosmaperr,FindClose, |
11_2_6FDCEFE1 |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Code function: 11_2_6FDD0F84 _wstat32i64,__doserrno,_errno,_invalid_parameter_noinfo,wcspbrk,_errno,__doserrno,towlower,_getdrive,FindFirstFileExW,wcspbrk,wcslen,GetDriveTypeW,free,free,_wsopen_s,_fstat32i64,_close,FileTimeToLocalFileTime,FileTimeToSystemTime,FileTimeToLocalFileTime,FileTimeToSystemTime,FileTimeToLocalFileTime,FileTimeToSystemTime,FindClose,GetLastError,_dosmaperr,FindClose, |
11_2_6FDD0F84 |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Code function: 11_2_6FDD0B33 _wstat64,__doserrno,_errno,_invalid_parameter_noinfo,wcspbrk,_errno,__doserrno,towlower,_getdrive,FindFirstFileExW,wcspbrk,wcslen,GetDriveTypeW,free,free,_wsopen_s,_fstat64,_close,FileTimeToLocalFileTime,FileTimeToSystemTime,FileTimeToLocalFileTime,FileTimeToSystemTime,FileTimeToLocalFileTime,FileTimeToSystemTime,FindClose,GetLastError,_dosmaperr,FindClose, |
11_2_6FDD0B33 |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Code function: 11_2_6FDCCA9B _malloc_crt,FindClose,FindFirstFileExW,FindNextFileW,FindClose, |
11_2_6FDCCA9B |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Code function: 11_2_6FDCC775 _malloc_crt,FindClose,FindFirstFileExA,FindNextFileA,FindClose, |
11_2_6FDCC775 |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Code function: 11_2_6FDD0702 _wstat32,__doserrno,_errno,_invalid_parameter_noinfo,wcspbrk,_errno,__doserrno,towlower,_getdrive,FindFirstFileExW,wcspbrk,wcslen,GetDriveTypeW,free,free,_wsopen_s,_fstat32,_close,FileTimeToLocalFileTime,FileTimeToSystemTime,FileTimeToLocalFileTime,FileTimeToSystemTime,FileTimeToLocalFileTime,FileTimeToSystemTime,FindClose,GetLastError,_dosmaperr,FindClose, |
11_2_6FDD0702 |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Code function: 11_2_6FDCDF35 _wfindfirst32,_errno,_invalid_parameter_noinfo,FindFirstFileExW,GetLastError,_errno,_errno,_errno,wcscpy_s,_invoke_watson,_wfindnext32,_errno,_invalid_parameter_noinfo,_errno,_invalid_parameter_noinfo,FindNextFileW,GetLastError,_errno,_errno,_errno,wcscpy_s,_invoke_watson,_wfindfirst64,_errno,_invalid_parameter_noinfo,FindFirstFileExW,GetLastError,_errno,_errno,_errno,wcscpy_s,_invoke_watson,_wfindnext64,_errno,_invalid_parameter_noinfo,_errno,_invalid_parameter_noinfo,FindNextFileW,GetLastError,_errno,_errno,_errno,wcscpy_s,_invoke_watson,_wfindfirst64i32,_errno,_invalid_parameter_noinfo,FindFirstFileExW,GetLastError,_errno,_errno,_errno,wcscpy_s,_invoke_watson,_wfindnext64i32,_errno,_invalid_parameter_noinfo,_errno,_invalid_parameter_noinfo,FindNextFileW,GetLastError,_errno,_errno,_errno,wcscpy_s,_invoke_watson,_wfindfirst32i64,_errno,_invalid_parameter_noinfo,FindFirstFileExW,GetLastError,_errno,_errno,_errno,wcscpy_s,_invoke_watson,_wfindnext32i64,_errno,_invalid_parameter_noinfo,_errno,_invalid_parameter_noinfo,FindNextFileW,GetLastError,_errno,_errno,_errno,wcscpy_s,_invoke_watson, |
11_2_6FDCDF35 |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Code function: 11_2_6FDCFD86 _stat32i64,__doserrno,_errno,_invalid_parameter_noinfo,_mbspbrk,_errno,__doserrno,_mbctolower,_getdrive,FindFirstFileExA,_mbspbrk,strlen,GetDriveTypeA,free,free,_sopen_s,_fstat32i64,_close,FileTimeToLocalFileTime,FileTimeToSystemTime,FileTimeToLocalFileTime,FileTimeToSystemTime,FileTimeToLocalFileTime,FileTimeToSystemTime,FindClose,GetLastError,_dosmaperr,FindClose, |
11_2_6FDCFD86 |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Code function: 11_2_6FD97C6D _wstat64i32,wcspbrk,_getdrive,FindFirstFileExW,wcspbrk,wcslen,_errno,__doserrno,__doserrno,_errno,_invalid_parameter_noinfo,towlower,GetDriveTypeW,free,free,_wsopen_s,_fstat64i32,_close,FileTimeToLocalFileTime,FileTimeToSystemTime,FileTimeToLocalFileTime,FileTimeToSystemTime,FileTimeToLocalFileTime,FileTimeToSystemTime,FindClose,GetLastError,_dosmaperr,FindClose, |
11_2_6FD97C6D |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Code function: 11_2_6FDCDA38 _findfirst64i32,_errno,_invalid_parameter_noinfo,FindFirstFileExA,GetLastError,_errno,_errno,_errno,strcpy_s,_invoke_watson,_findnext64i32,_errno,_invalid_parameter_noinfo,_errno,_invalid_parameter_noinfo,FindNextFileA,GetLastError,_errno,_errno,_errno,strcpy_s,_invoke_watson,_findfirst32i64,_errno,_invalid_parameter_noinfo,FindFirstFileExA,GetLastError,_errno,_errno,_errno,strcpy_s,_invoke_watson,_findnext32i64,_errno,_invalid_parameter_noinfo,_errno,_invalid_parameter_noinfo,FindNextFileA,GetLastError,_errno,_errno,_errno,strcpy_s,_invoke_watson,_seterrormode,SetErrorMode, |
11_2_6FDCDA38 |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Code function: 11_2_6FDCF8B5 _stat64i32,__doserrno,_errno,_invalid_parameter_noinfo,_mbspbrk,_errno,__doserrno,_mbctolower,_getdrive,FindFirstFileExA,_mbspbrk,strlen,GetDriveTypeA,free,free,_sopen_s,_fstat64i32,_close,FileTimeToLocalFileTime,FileTimeToSystemTime,FileTimeToLocalFileTime,FileTimeToSystemTime,FileTimeToLocalFileTime,FileTimeToSystemTime,FindClose,GetLastError,_dosmaperr,FindClose, |
11_2_6FDCF8B5 |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Code function: 11_2_6FDCD4FF _findfirst32,_errno,_invalid_parameter_noinfo,FindFirstFileExA,GetLastError,_errno,_errno,_errno,strcpy_s,_invoke_watson,_findnext32,_errno,_invalid_parameter_noinfo,_errno,_invalid_parameter_noinfo,FindNextFileA,GetLastError,_errno,_errno,_errno,strcpy_s,_invoke_watson,_findfirst64,_errno,_invalid_parameter_noinfo,FindFirstFileExA,GetLastError,_errno,_errno,_errno,strcpy_s,_invoke_watson,_findnext64,_errno,_invalid_parameter_noinfo,_errno,_invalid_parameter_noinfo,FindNextFileA,GetLastError,_errno,_errno,_errno,strcpy_s,_invoke_watson, |
11_2_6FDCD4FF |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Code function: 11_2_6FDCF40B _stat64,__doserrno,_errno,_invalid_parameter_noinfo,_mbspbrk,_errno,__doserrno,_mbctolower,_getdrive,FindFirstFileExA,_mbspbrk,strlen,GetDriveTypeA,free,free,_sopen_s,_fstat64,_close,FileTimeToLocalFileTime,FileTimeToSystemTime,FileTimeToLocalFileTime,FileTimeToSystemTime,FileTimeToLocalFileTime,FileTimeToSystemTime,FindClose,GetLastError,_dosmaperr,FindClose, |
11_2_6FDCF40B |
Source: powershell.exe, 00000004.00000002.30087129699.000001E792E56000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://62.72.3.210 |
Source: powershell.exe, 00000004.00000002.30087129699.000001E792A77000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://86.38.217.167 |
Source: powershell.exe, 0000000D.00000002.29797055442.000000000052B000.00000004.00000020.00020000.00000000.sdmp, powershell.exe, 00000014.00000002.30385728857.0000014C514FD000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://crl.comodoca.com/AAACertificateServices.crl06 |
Source: powershell.exe, 0000000D.00000002.29797055442.000000000052B000.00000004.00000020.00020000.00000000.sdmp, powershell.exe, 00000014.00000002.30385075264.0000014C514D0000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://crl.globalsign.net/root-r2.crl0 |
Source: powershell.exe, 00000004.00000002.30086145780.000001E790A45000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://crl.microsoft.co: |
Source: powershell.exe, 00000004.00000002.30098453152.000001E7A28C5000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://nuget.org/NuGet.exe |
Source: powershell.exe, 00000004.00000002.30087129699.000001E792A77000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://pesterbdd.com/images/Pester.png |
Source: powershell.exe, 00000004.00000002.30087129699.000001E792A77000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://pesterbdd.com/images/Pester.pngXzi |
Source: powershell.exe, 00000004.00000002.30087129699.000001E7930C6000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000D.00000002.29798541069.00000000043E7000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://schemas.xmlsoap.org/soap/encoding/ |
Source: powershell.exe, 00000004.00000002.30087129699.000001E792851000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000D.00000002.29798541069.0000000004291000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000014.00000002.30351811914.0000014C393C1000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name |
Source: powershell.exe, 00000004.00000002.30087129699.000001E7930C6000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000D.00000002.29798541069.00000000043E7000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://schemas.xmlsoap.org/wsdl/ |
Source: powershell.exe, 00000004.00000002.30087129699.000001E792A77000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://www.apache.org/licenses/LICENSE-2.0.html |
Source: powershell.exe, 00000004.00000002.30087129699.000001E792A77000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://www.apache.org/licenses/LICENSE-2.0.htmlXzi |
Source: powershell.exe, 0000000D.00000002.29797055442.000000000052B000.00000004.00000020.00020000.00000000.sdmp, powershell.exe, 00000014.00000002.30385728857.0000014C514FD000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://www.quovadis.bm0 |
Source: powershell.exe, 00000004.00000002.30087129699.000001E792851000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000014.00000002.30351811914.0000014C393C1000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://aka.ms/pscore68 |
Source: powershell.exe, 0000000D.00000002.29798541069.0000000004291000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://aka.ms/pscore6lB |
Source: powershell.exe, 00000004.00000002.30098453152.000001E7A28C5000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://contoso.com/ |
Source: powershell.exe, 00000004.00000002.30098453152.000001E7A28C5000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://contoso.com/Icon |
Source: powershell.exe, 00000004.00000002.30098453152.000001E7A28C5000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://contoso.com/License |
Source: powershell.exe, 00000004.00000002.30087129699.000001E792FBC000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://firebasestorage.googleapis.com |
Source: curl.exe, 00000002.00000002.29379756087.000001AA88A90000.00000004.00000020.00020000.00000000.sdmp, Factura-2410-CFDI.bat |
String found in binary or memory: https://firebasestorage.googleapis.com/v0/b/antonidesil.appspot.com/o/at3?alt=media&token=0c52e418-0 |
Source: powershell.exe, 00000004.00000002.30087129699.000001E792E56000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://firebasestorage.googleapis.com/v0/b/ggsabadon.appspot.com/o/md1910_.zip?alt=media&token=0c46 |
Source: powershell.exe, 00000004.00000002.30087129699.000001E792A77000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://github.com/Pester/Pester |
Source: powershell.exe, 00000004.00000002.30087129699.000001E792A77000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://github.com/Pester/PesterXzi |
Source: powershell.exe, 00000004.00000002.30098453152.000001E7A28C5000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://nuget.org/nuget.exe |
Source: powershell.exe, 0000000D.00000002.29797055442.000000000052B000.00000004.00000020.00020000.00000000.sdmp, powershell.exe, 00000014.00000002.30385728857.0000014C514FD000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://ocsp.quovadisoffshore.com0 |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Code function: 9_2_6FDE6E18 |
9_2_6FDE6E18 |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Code function: 9_2_6FD86E28 |
9_2_6FD86E28 |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Code function: 9_2_6FD86E24 |
9_2_6FD86E24 |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Code function: 9_2_6FDBEB1A |
9_2_6FDBEB1A |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Code function: 9_2_6FDA0919 |
9_2_6FDA0919 |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Code function: 9_2_6FE00915 |
9_2_6FE00915 |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Code function: 9_2_6FE167FF |
9_2_6FE167FF |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Code function: 9_2_6FDEE7F1 |
9_2_6FDEE7F1 |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Code function: 9_2_6FD945AE |
9_2_6FD945AE |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Code function: 9_2_6FD88468 |
9_2_6FD88468 |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Code function: 9_2_6FD8839B |
9_2_6FD8839B |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Code function: 9_2_6FDE22CD |
9_2_6FDE22CD |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Code function: 9_2_6FD8828B |
9_2_6FD8828B |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Code function: 9_2_6FDCA277 |
9_2_6FDCA277 |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Code function: 9_2_6FE08220 |
9_2_6FE08220 |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Code function: 9_2_6FD8A1DD |
9_2_6FD8A1DD |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Code function: 9_2_6FD721F0 |
9_2_6FD721F0 |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Code function: 9_2_6FDE4159 |
9_2_6FDE4159 |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Code function: 9_2_6FDCDF35 |
9_2_6FDCDF35 |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Code function: 9_2_6FD85E20 |
9_2_6FD85E20 |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Code function: 9_2_6FD83DB1 |
9_2_6FD83DB1 |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Code function: 9_2_6FD87D20 |
9_2_6FD87D20 |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Code function: 9_2_6FE01CEF |
9_2_6FE01CEF |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Code function: 9_2_6FD89C8E |
9_2_6FD89C8E |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Code function: 9_2_6FD83B1D |
9_2_6FD83B1D |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Code function: 9_2_6FE17B2A |
9_2_6FE17B2A |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Code function: 9_2_6FE11AE0 |
9_2_6FE11AE0 |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Code function: 9_2_6FDCDA38 |
9_2_6FDCDA38 |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Code function: 9_2_6FE03968 |
9_2_6FE03968 |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Code function: 9_2_6FDEF8BA |
9_2_6FDEF8BA |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Code function: 9_2_6FDE9877 |
9_2_6FDE9877 |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Code function: 9_2_6FD85795 |
9_2_6FD85795 |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Code function: 9_2_6FE0D754 |
9_2_6FE0D754 |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Code function: 9_2_6FDEB723 |
9_2_6FDEB723 |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Code function: 9_2_6FD896C9 |
9_2_6FD896C9 |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Code function: 9_2_6FE196A7 |
9_2_6FE196A7 |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Code function: 9_2_6FD875C1 |
9_2_6FD875C1 |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Code function: 9_2_6FD835FA |
9_2_6FD835FA |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Code function: 9_2_6FDCD4FF |
9_2_6FDCD4FF |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Code function: 9_2_6FDED43B |
9_2_6FDED43B |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Code function: 9_2_6FE19295 |
9_2_6FE19295 |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Code function: 9_2_6FD87210 |
9_2_6FD87210 |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Code function: 9_2_6FDE31BA |
9_2_6FDE31BA |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Code function: 9_2_6FDE516D |
9_2_6FDE516D |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Code function: 9_2_6FD9911E |
9_2_6FD9911E |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Code function: 11_2_6FDE6E18 |
11_2_6FDE6E18 |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Code function: 11_2_6FD86E28 |
11_2_6FD86E28 |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Code function: 11_2_6FD86E24 |
11_2_6FD86E24 |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Code function: 11_2_6FDBEB1A |
11_2_6FDBEB1A |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Code function: 11_2_6FDA0919 |
11_2_6FDA0919 |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Code function: 11_2_6FE00915 |
11_2_6FE00915 |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Code function: 11_2_6FE167FF |
11_2_6FE167FF |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Code function: 11_2_6FDEE7F1 |
11_2_6FDEE7F1 |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Code function: 11_2_6FD945AE |
11_2_6FD945AE |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Code function: 11_2_6FD88468 |
11_2_6FD88468 |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Code function: 11_2_6FD8839B |
11_2_6FD8839B |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Code function: 11_2_6FDE22CD |
11_2_6FDE22CD |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Code function: 11_2_6FD8828B |
11_2_6FD8828B |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Code function: 11_2_6FDCA277 |
11_2_6FDCA277 |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Code function: 11_2_6FE08220 |
11_2_6FE08220 |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Code function: 11_2_6FD8A1DD |
11_2_6FD8A1DD |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Code function: 11_2_6FD721F0 |
11_2_6FD721F0 |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Code function: 11_2_6FDE4159 |
11_2_6FDE4159 |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Code function: 11_2_6FDCDF35 |
11_2_6FDCDF35 |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Code function: 11_2_6FD85E20 |
11_2_6FD85E20 |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Code function: 11_2_6FD83DB1 |
11_2_6FD83DB1 |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Code function: 11_2_6FD87D20 |
11_2_6FD87D20 |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Code function: 11_2_6FE01CEF |
11_2_6FE01CEF |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Code function: 11_2_6FD89C8E |
11_2_6FD89C8E |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Code function: 11_2_6FD83B1D |
11_2_6FD83B1D |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Code function: 11_2_6FE17B2A |
11_2_6FE17B2A |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Code function: 11_2_6FE11AE0 |
11_2_6FE11AE0 |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Code function: 11_2_6FDCDA38 |
11_2_6FDCDA38 |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Code function: 11_2_6FE03968 |
11_2_6FE03968 |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Code function: 11_2_6FDEF8BA |
11_2_6FDEF8BA |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Code function: 11_2_6FDE9877 |
11_2_6FDE9877 |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Code function: 11_2_6FD85795 |
11_2_6FD85795 |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Code function: 11_2_6FE0D754 |
11_2_6FE0D754 |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Code function: 11_2_6FDEB723 |
11_2_6FDEB723 |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Code function: 11_2_6FD896C9 |
11_2_6FD896C9 |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Code function: 11_2_6FE196A7 |
11_2_6FE196A7 |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Code function: 11_2_6FD875C1 |
11_2_6FD875C1 |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Code function: 11_2_6FD835FA |
11_2_6FD835FA |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Code function: 11_2_6FDCD4FF |
11_2_6FDCD4FF |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Code function: 11_2_6FDED43B |
11_2_6FDED43B |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Code function: 11_2_6FE19295 |
11_2_6FE19295 |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Code function: 11_2_6FD87210 |
11_2_6FD87210 |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Code function: 11_2_6FDE31BA |
11_2_6FDE31BA |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Code function: 11_2_6FDE516D |
11_2_6FDE516D |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Code function: 11_2_6FD9911E |
11_2_6FD9911E |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Code function: 13_2_0419A550 |
13_2_0419A550 |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Code function: 13_2_0419E488 |
13_2_0419E488 |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Code function: 13_2_0419A541 |
13_2_0419A541 |
Source: C:\Windows\System32\cmd.exe |
Section loaded: cmdext.dll |
Jump to behavior |
Source: C:\Windows\System32\curl.exe |
Section loaded: cryptsp.dll |
Jump to behavior |
Source: C:\Windows\System32\curl.exe |
Section loaded: secur32.dll |
Jump to behavior |
Source: C:\Windows\System32\curl.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Windows\System32\curl.exe |
Section loaded: mswsock.dll |
Jump to behavior |
Source: C:\Windows\System32\curl.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Windows\System32\curl.exe |
Section loaded: dnsapi.dll |
Jump to behavior |
Source: C:\Windows\System32\curl.exe |
Section loaded: iphlpapi.dll |
Jump to behavior |
Source: C:\Windows\System32\curl.exe |
Section loaded: rasadhlp.dll |
Jump to behavior |
Source: C:\Windows\System32\curl.exe |
Section loaded: fwpuclnt.dll |
Jump to behavior |
Source: C:\Windows\System32\curl.exe |
Section loaded: schannel.dll |
Jump to behavior |
Source: C:\Windows\System32\curl.exe |
Section loaded: mskeyprotect.dll |
Jump to behavior |
Source: C:\Windows\System32\curl.exe |
Section loaded: ntasn1.dll |
Jump to behavior |
Source: C:\Windows\System32\curl.exe |
Section loaded: ncrypt.dll |
Jump to behavior |
Source: C:\Windows\System32\curl.exe |
Section loaded: ncryptsslp.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: atl.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: mscoree.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: edgegdi.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: vcruntime140_clr0400.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: cryptsp.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: rsaenh.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: cryptbase.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: amsi.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: msasn1.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: gpapi.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: msisip.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: wshext.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: appxsip.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: opcservices.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: urlmon.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: xmllite.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: iertutil.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: srvcli.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: netutils.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: secur32.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: wbemcomn.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: napinsp.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: pnrpnsp.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: wshbth.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: nlaapi.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: iphlpapi.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: mswsock.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: dnsapi.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: winrnr.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: fwpuclnt.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: rasadhlp.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: napinsp.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: pnrpnsp.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: wshbth.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: nlaapi.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: winrnr.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: fwpuclnt.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: rasapi32.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: rasman.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: rtutils.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: winhttp.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: ondemandconnroutehelper.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: dhcpcsvc6.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: dhcpcsvc.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: napinsp.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: pnrpnsp.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: wshbth.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: nlaapi.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: winrnr.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: fwpuclnt.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: ntmarta.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: sxs.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: mpr.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: scrrun.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: propsys.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: linkinfo.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: ntshrui.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: cscapi.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: winnsi.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: schannel.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: mskeyprotect.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: ntasn1.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: ncrypt.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: ncryptsslp.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: msisip.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: wshext.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: appxsip.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: opcservices.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: urlmon.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: xmllite.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: iertutil.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: netutils.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: wininet.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: kdscli.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: edputil.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: windows.staterepositoryps.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: appresolver.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: bcp47langs.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: slc.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: sppc.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: onecorecommonproxystub.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: onecoreuapcommonproxystub.dll |
Jump to behavior |
Source: C:\Windows\System32\cmd.exe |
Section loaded: cmdext.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: atl.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: mscoree.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: edgegdi.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: vcruntime140_clr0400.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: cryptsp.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: rsaenh.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: cryptbase.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: amsi.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: msasn1.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: gpapi.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: msisip.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: wshext.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: appxsip.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: opcservices.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: urlmon.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: xmllite.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: iertutil.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: srvcli.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: netutils.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: secur32.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: propsys.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: rasapi32.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: rasman.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: rtutils.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: mswsock.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: winhttp.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: ondemandconnroutehelper.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: iphlpapi.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: dhcpcsvc6.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: dhcpcsvc.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: dnsapi.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: winnsi.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: rasadhlp.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: fwpuclnt.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: schannel.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: mskeyprotect.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: ntasn1.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: ncrypt.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: ncryptsslp.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: wbemcomn.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: napinsp.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: pnrpnsp.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: wshbth.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: nlaapi.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: winrnr.dll |
Jump to behavior |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Section loaded: jli.dll |
Jump to behavior |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Section loaded: msvcr100.dll |
Jump to behavior |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Section loaded: jli.dll |
Jump to behavior |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Section loaded: msvcr100.dll |
Jump to behavior |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Section loaded: edgegdi.dll |
Jump to behavior |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Section loaded: propsys.dll |
Jump to behavior |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Section loaded: edputil.dll |
Jump to behavior |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Section loaded: urlmon.dll |
Jump to behavior |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Section loaded: iertutil.dll |
Jump to behavior |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Section loaded: srvcli.dll |
Jump to behavior |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Section loaded: netutils.dll |
Jump to behavior |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Section loaded: windows.staterepositoryps.dll |
Jump to behavior |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Section loaded: appresolver.dll |
Jump to behavior |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Section loaded: bcp47langs.dll |
Jump to behavior |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Section loaded: slc.dll |
Jump to behavior |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Section loaded: sppc.dll |
Jump to behavior |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Section loaded: onecorecommonproxystub.dll |
Jump to behavior |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Section loaded: onecoreuapcommonproxystub.dll |
Jump to behavior |
Source: C:\_kjfech8_V\_kjfech8_Vi7.exe |
Section loaded: dwmapi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: atl.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: mscoree.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: edgegdi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: vcruntime140_clr0400.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: cryptsp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: rsaenh.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: cryptbase.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: msasn1.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: amsi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: gpapi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: msisip.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: wshext.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: appxsip.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: opcservices.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: urlmon.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: xmllite.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: iertutil.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: srvcli.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: netutils.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: secur32.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: propsys.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: wininet.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: microsoft.management.infrastructure.native.unmanaged.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: mi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: miutils.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: wmidcom.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: dpapi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: wbemcomn.dll |
Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: fastprox.dll |
Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: ncobjapi.dll |
Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: wbemcomn.dll |
Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: wbemcomn.dll |
Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: edgegdi.dll |
Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: mpclient.dll |
Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: wmitomi.dll |
Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: mi.dll |
Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: miutils.dll |
Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: miutils.dll |
Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: gpapi.dll |
Jump to behavior |
Source: C:\Windows\System32\shutdown.exe |
Section loaded: shutdownext.dll |
Jump to behavior |
Source: C:\Windows\System32\shutdown.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Windows\System32\shutdown.exe |
Section loaded: edgegdi.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: atl.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: mscoree.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: edgegdi.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: vcruntime140_clr0400.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: cryptsp.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: rsaenh.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: cryptbase.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: msasn1.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: amsi.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: gpapi.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: msisip.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: wshext.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: appxsip.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: opcservices.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: urlmon.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: xmllite.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: iertutil.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: srvcli.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: netutils.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: secur32.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: uxtheme.dll |
Jump to behavior |