Source: 11.2.PROFORMA + PENDENTES.exe.400000.0.unpack, type: UNPACKEDPE | Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: 11.2.PROFORMA + PENDENTES.exe.400000.0.unpack, type: UNPACKEDPE | Matched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/ |
Source: 11.2.PROFORMA + PENDENTES.exe.400000.0.unpack, type: UNPACKEDPE | Matched rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook author = ditekSHen, description = Detects executables with potential process hoocking |
Source: 11.2.PROFORMA + PENDENTES.exe.400000.0.unpack, type: UNPACKEDPE | Matched rule: MALWARE_Win_SnakeKeylogger author = ditekSHen, description = Detects Snake Keylogger, clamav_sig = MALWARE.Win.Trojan.SnakeKeylogger |
Source: 0.2.PROFORMA + PENDENTES.exe.395e8d0.1.unpack, type: UNPACKEDPE | Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: 0.2.PROFORMA + PENDENTES.exe.395e8d0.1.unpack, type: UNPACKEDPE | Matched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/ |
Source: 0.2.PROFORMA + PENDENTES.exe.395e8d0.1.unpack, type: UNPACKEDPE | Matched rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook author = ditekSHen, description = Detects executables with potential process hoocking |
Source: 0.2.PROFORMA + PENDENTES.exe.395e8d0.1.unpack, type: UNPACKEDPE | Matched rule: MALWARE_Win_SnakeKeylogger author = ditekSHen, description = Detects Snake Keylogger, clamav_sig = MALWARE.Win.Trojan.SnakeKeylogger |
Source: 0.2.PROFORMA + PENDENTES.exe.393deb0.3.unpack, type: UNPACKEDPE | Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: 0.2.PROFORMA + PENDENTES.exe.393deb0.3.unpack, type: UNPACKEDPE | Matched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/ |
Source: 0.2.PROFORMA + PENDENTES.exe.393deb0.3.unpack, type: UNPACKEDPE | Matched rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook author = ditekSHen, description = Detects executables with potential process hoocking |
Source: 0.2.PROFORMA + PENDENTES.exe.393deb0.3.unpack, type: UNPACKEDPE | Matched rule: MALWARE_Win_SnakeKeylogger author = ditekSHen, description = Detects Snake Keylogger, clamav_sig = MALWARE.Win.Trojan.SnakeKeylogger |
Source: 0.2.PROFORMA + PENDENTES.exe.395e8d0.1.raw.unpack, type: UNPACKEDPE | Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: 0.2.PROFORMA + PENDENTES.exe.395e8d0.1.raw.unpack, type: UNPACKEDPE | Matched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/ |
Source: 0.2.PROFORMA + PENDENTES.exe.395e8d0.1.raw.unpack, type: UNPACKEDPE | Matched rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook author = ditekSHen, description = Detects executables with potential process hoocking |
Source: 0.2.PROFORMA + PENDENTES.exe.395e8d0.1.raw.unpack, type: UNPACKEDPE | Matched rule: MALWARE_Win_SnakeKeylogger author = ditekSHen, description = Detects Snake Keylogger, clamav_sig = MALWARE.Win.Trojan.SnakeKeylogger |
Source: 0.2.PROFORMA + PENDENTES.exe.393deb0.3.raw.unpack, type: UNPACKEDPE | Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: 0.2.PROFORMA + PENDENTES.exe.393deb0.3.raw.unpack, type: UNPACKEDPE | Matched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/ |
Source: 0.2.PROFORMA + PENDENTES.exe.393deb0.3.raw.unpack, type: UNPACKEDPE | Matched rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook author = ditekSHen, description = Detects executables with potential process hoocking |
Source: 0.2.PROFORMA + PENDENTES.exe.393deb0.3.raw.unpack, type: UNPACKEDPE | Matched rule: MALWARE_Win_SnakeKeylogger author = ditekSHen, description = Detects Snake Keylogger, clamav_sig = MALWARE.Win.Trojan.SnakeKeylogger |
Source: 0000000B.00000002.1626917322.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY | Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: 0000000B.00000002.1626917322.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY | Matched rule: MALWARE_Win_SnakeKeylogger author = ditekSHen, description = Detects Snake Keylogger, clamav_sig = MALWARE.Win.Trojan.SnakeKeylogger |
Source: 00000000.00000002.1484282889.0000000003791000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY | Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: 00000000.00000002.1484282889.0000000003791000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY | Matched rule: MALWARE_Win_SnakeKeylogger author = ditekSHen, description = Detects Snake Keylogger, clamav_sig = MALWARE.Win.Trojan.SnakeKeylogger |
Source: Process Memory Space: PROFORMA + PENDENTES.exe PID: 7924, type: MEMORYSTR | Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: Process Memory Space: PROFORMA + PENDENTES.exe PID: 7924, type: MEMORYSTR | Matched rule: MALWARE_Win_SnakeKeylogger author = ditekSHen, description = Detects Snake Keylogger, clamav_sig = MALWARE.Win.Trojan.SnakeKeylogger |
Source: Process Memory Space: PROFORMA + PENDENTES.exe PID: 3636, type: MEMORYSTR | Matched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23 |
Source: Process Memory Space: PROFORMA + PENDENTES.exe PID: 3636, type: MEMORYSTR | Matched rule: MALWARE_Win_SnakeKeylogger author = ditekSHen, description = Detects Snake Keylogger, clamav_sig = MALWARE.Win.Trojan.SnakeKeylogger |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Section loaded: winmm.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Section loaded: msacm32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Section loaded: msdmo.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Section loaded: winmmbase.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Section loaded: winmmbase.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Section loaded: wtsapi32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Section loaded: winsta.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Section loaded: dwrite.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Section loaded: windowscodecs.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Section loaded: edputil.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Section loaded: windows.staterepositoryps.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Section loaded: appresolver.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Section loaded: bcp47langs.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Section loaded: slc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Section loaded: sppc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Section loaded: onecorecommonproxystub.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Section loaded: onecoreuapcommonproxystub.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: atl.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: msisip.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wshext.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: appxsip.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: opcservices.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: secur32.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: atl.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: msisip.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wshext.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: appxsip.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: opcservices.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: secur32.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: microsoft.management.infrastructure.native.unmanaged.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: mi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: miutils.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wmidcom.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: dpapi.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wbemcomn.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\schtasks.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\schtasks.exe | Section loaded: taskschd.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\schtasks.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Section loaded: rasapi32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Section loaded: rasman.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Section loaded: rtutils.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Section loaded: dhcpcsvc6.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Section loaded: dhcpcsvc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Section loaded: dnsapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Section loaded: winnsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Section loaded: rasadhlp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Section loaded: fwpuclnt.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Section loaded: secur32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Section loaded: schannel.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Section loaded: mskeyprotect.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Section loaded: ntasn1.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Section loaded: ncrypt.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Section loaded: ncryptsslp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Section loaded: edputil.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Section loaded: windows.staterepositoryps.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Section loaded: appresolver.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Section loaded: bcp47langs.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Section loaded: slc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Section loaded: sppc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Section loaded: onecorecommonproxystub.dll | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Section loaded: onecoreuapcommonproxystub.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Section loaded: winmm.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Section loaded: msacm32.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Section loaded: msdmo.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Section loaded: winmmbase.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Section loaded: winmmbase.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Section loaded: wtsapi32.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Section loaded: winsta.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Section loaded: dwrite.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Section loaded: windowscodecs.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Section loaded: edputil.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Section loaded: windows.staterepositoryps.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Section loaded: appresolver.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Section loaded: bcp47langs.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Section loaded: slc.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Section loaded: sppc.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Section loaded: onecorecommonproxystub.dll | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Section loaded: onecoreuapcommonproxystub.dll | Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: fastprox.dll | |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: ncobjapi.dll | |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: wbemcomn.dll | |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: wbemcomn.dll | |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: mpclient.dll | |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: userenv.dll | |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: version.dll | |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: msasn1.dll | |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: wmitomi.dll | |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: mi.dll | |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: miutils.dll | |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: miutils.dll | |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe | Section loaded: gpapi.dll | |
Source: C:\Windows\SysWOW64\schtasks.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\SysWOW64\schtasks.exe | Section loaded: taskschd.dll | |
Source: C:\Windows\SysWOW64\schtasks.exe | Section loaded: sspicli.dll | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Section loaded: mscoree.dll | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Section loaded: version.dll | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Section loaded: vcruntime140_clr0400.dll | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Section loaded: ucrtbase_clr0400.dll | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Section loaded: uxtheme.dll | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Section loaded: windows.storage.dll | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Section loaded: wldp.dll | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Section loaded: profapi.dll | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Section loaded: cryptsp.dll | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Section loaded: rsaenh.dll | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Section loaded: cryptbase.dll | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Section loaded: rasapi32.dll | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Section loaded: rasman.dll | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Section loaded: rtutils.dll | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Section loaded: mswsock.dll | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Section loaded: winhttp.dll | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Section loaded: ondemandconnroutehelper.dll | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Section loaded: iphlpapi.dll | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Section loaded: dhcpcsvc6.dll | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Section loaded: dhcpcsvc.dll | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Section loaded: dnsapi.dll | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Section loaded: winnsi.dll | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Section loaded: rasadhlp.dll | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Section loaded: fwpuclnt.dll | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Section loaded: secur32.dll | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Section loaded: sspicli.dll | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Section loaded: schannel.dll | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Section loaded: mskeyprotect.dll | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Section loaded: ntasn1.dll | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Section loaded: ncrypt.dll | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Section loaded: ncryptsslp.dll | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Section loaded: msasn1.dll | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Section loaded: gpapi.dll | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Section loaded: propsys.dll | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Section loaded: edputil.dll | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Section loaded: urlmon.dll | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Section loaded: iertutil.dll | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Section loaded: srvcli.dll | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Section loaded: netutils.dll | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Section loaded: windows.staterepositoryps.dll | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Section loaded: wintypes.dll | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Section loaded: appresolver.dll | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Section loaded: bcp47langs.dll | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Section loaded: slc.dll | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Section loaded: userenv.dll | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Section loaded: sppc.dll | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Section loaded: onecorecommonproxystub.dll | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Section loaded: onecoreuapcommonproxystub.dll | |
Source: C:\Windows\SysWOW64\choice.exe | Section loaded: version.dll | |
Source: C:\Windows\SysWOW64\choice.exe | Section loaded: version.dll | |
Source: 0.2.PROFORMA + PENDENTES.exe.39a2ad0.2.raw.unpack, P9YhaUQTPWGmrkJYOM.cs | High entropy of concatenated method names: 'XIVp6ONf92cjxwcseuR', 'qoC1rfNeGjdpd8pKvlj', 'PGxaLkNxItsr69fUPsO', 'hD6b84ho97', 'NqDbE8YaP5', 'jAFbvfIW7F', 'YQSaXbNbxSDTfYZ4m4w', 'Qm8np7NyHuBI2beEffw' |
Source: 0.2.PROFORMA + PENDENTES.exe.39a2ad0.2.raw.unpack, X8UiX2cvtnoE290aLy.cs | High entropy of concatenated method names: 'RHyl0mtZMt', 'zgFlP4G9OF', 'jQXldykwxZ', 'CMMloiqeV6', 'eHHlyMSkho', 'rRglLpIJvC', 'M2Qlpk5R6V', 'gj2ln5646D', 'uOplN2Y6Xn', 'imWlWgDR5k' |
Source: 0.2.PROFORMA + PENDENTES.exe.39a2ad0.2.raw.unpack, OPHIWV1rONTdneeeKQ.cs | High entropy of concatenated method names: 'EuGV6Er0jb', 'REaVKLtjUw', 'jHxVbh2hT2', 'cYNb9QXQda', 'XLlbzbIToe', 'PlsVcGB1hk', 'oV5VjIaSbm', 'a6UVu7G666', 'qupVXrICXs', 'd1nVB4f1LA' |
Source: 0.2.PROFORMA + PENDENTES.exe.39a2ad0.2.raw.unpack, LhTHsGF4RMAZGCa8kn.cs | High entropy of concatenated method names: 'FQnjVoQgwf', 'ltxjFCoTG0', 'H7yjfXKfBO', 'WaRjSZLE8e', 'K0DjldFJwK', 'C6fjA7va4P', 'VvV8Rud3PZC59uom7a', 'VPd6f1cXlKyQQJTTwa', 'KttjjPFT0d', 'vlYjXT8kOD' |
Source: 0.2.PROFORMA + PENDENTES.exe.39a2ad0.2.raw.unpack, E9LtPwuKpQi6ZoWWhl.cs | High entropy of concatenated method names: 'wfYVi21BK4', 'uWYVsWu3Yg', 'jvRVMKAp96', 'oZjVxNKDhY', 'FAVVrXwCEu', 'yoAVYLJWlX', 'vbCVq3k0aP', 'F1PVGr39aY', 'i5xVTPIPI4', 'DlNVgg2fTg' |
Source: 0.2.PROFORMA + PENDENTES.exe.39a2ad0.2.raw.unpack, BPtRuoLrWtp4vXFCxG.cs | High entropy of concatenated method names: 'Dispose', 'nZkjhY1GO0', 'EHruy2SgwE', 'uv45mmTDbZ', 'vA9j9EQ7C1', 'xuwjzt5Zyn', 'ProcessDialogKey', 'QU1ucmawwh', 't6XujIX2KD', 'homuutT4ts' |
Source: 0.2.PROFORMA + PENDENTES.exe.39a2ad0.2.raw.unpack, Q5ojRjNNt049wiCCLRb.cs | High entropy of concatenated method names: 'Cgvv9ZWicw', 'EeAvzDPtNd', 'jr5Rc2TKpq', 'tZ8RjekCQ7', 'l1PRujXYFj', 'BjERXT4aP6', 'rNSRBnDrkT', 'FYjRCOLIjV', 'Yp7R6oD75u', 'wpZRe31uW0' |
Source: 0.2.PROFORMA + PENDENTES.exe.39a2ad0.2.raw.unpack, oqyhYmNFX41kCRZNwVY.cs | High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'XmJ5EmQLI7', 'YTN5vdGShl', 'MnO5Ry4s4r', 'sCG55Zomaj', 'nyi5w67GGc', 'AY052DtqJS', 'aV95QPHSbB' |
Source: 0.2.PROFORMA + PENDENTES.exe.39a2ad0.2.raw.unpack, QBD6LeWqfNbDZDo1Gy.cs | High entropy of concatenated method names: 'wiwvKVcg9c', 'xWQvJARZIy', 'pnPvbWDZAr', 'pa1vV9Gt4t', 'IV8vEqYCOk', 'xrJvFS5dai', 'Next', 'Next', 'Next', 'NextBytes' |
Source: 0.2.PROFORMA + PENDENTES.exe.39a2ad0.2.raw.unpack, gcGUX2Bedx6QaYS31J.cs | High entropy of concatenated method names: 'DL4XCGrFc2', 'FyrX6GnVT5', 'q2DXe7LTNV', 'WkHXKURASD', 'OXPXJ6OPI2', 'geVXbhn7x3', 'jqiXVZGnum', 'sl1XFbali2', 'SJDXahHKn4', 'Fe2XfGNhEv' |
Source: 0.2.PROFORMA + PENDENTES.exe.39a2ad0.2.raw.unpack, IYGkQihKqcCcxHNjdZ.cs | High entropy of concatenated method names: 'ToString', 'MyRAUgvlob', 'nNJAyHk491', 'crUALZaJJ9', 'BgaApLO5Ay', 'FOVAn1n3Go', 'KguAN3cXZY', 'YoaAW8hJDe', 'XcpAHNWmY8', 'JGoA3mscTG' |
Source: 0.2.PROFORMA + PENDENTES.exe.39a2ad0.2.raw.unpack, frWEPPZXcI6c8G7QYF.cs | High entropy of concatenated method names: 'QIMMwSIJX', 'Gg0x1JcmF', 'SlnYPgxAj', 'MkHqWFJf1', 'fSJTB8RFf', 'XBxgPAQsx', 'KVWBhZVwCb97fdle7g', 'lIQ5ij3OjSyYSBkHbu', 'Fqd8gkhdy', 'r5svhZkKt' |
Source: 0.2.PROFORMA + PENDENTES.exe.39a2ad0.2.raw.unpack, v9ObnkTULXnVyWfjQA.cs | High entropy of concatenated method names: 'JJa4fxXhCk', 'eNo4SgrDmI', 'ToString', 'c6G46TjmZy', 'ceD4eN1UaD', 'zW64KfgV2l', 'AIR4JRH7bd', 'KVN4bDmbGI', 'YKK4V95clx', 'JHM4FteeUN' |
Source: 0.2.PROFORMA + PENDENTES.exe.39a2ad0.2.raw.unpack, UXkvgCEsWpXnGZrTp9.cs | High entropy of concatenated method names: 'OVvbC6SvZS', 'oDVbeR2v0C', 'EEHbJOxKZI', 'KkabVk1kR4', 'jjAbFMhHx8', 'v3kJmBZxNr', 'fRJJk2i9oZ', 'nyLJIkUOA8', 'Mf7JtCj5TD', 'lN3Jh5AhQI' |
Source: 0.2.PROFORMA + PENDENTES.exe.39a2ad0.2.raw.unpack, bpHb30nysGa21mKvTL.cs | High entropy of concatenated method names: 'EditValue', 'GetEditStyle', 'n0PuhgmEo8', 'p4cu9e4d37', 'iHuuz3ERNt', 'XksXcH1dxB', 'RpGXjrJeFm', 'of3XuHyykB', 'Ea3XXxB5MF', 'VDggKGYF84Q68AYS8I6' |
Source: 0.2.PROFORMA + PENDENTES.exe.39a2ad0.2.raw.unpack, zgBjQosOJogGKDUmJH.cs | High entropy of concatenated method names: 'uVjKxFNrQi', 'ThoKYAbV7S', 'xymKGdA9GE', 'XgmKTKU1Y0', 'FWJKln8yxQ', 'soiKAQTKJR', 'GbMK4RiOlT', 'EtMK880qDI', 'lP3KEIEAse', 'FTgKvyCTUE' |
Source: 0.2.PROFORMA + PENDENTES.exe.39a2ad0.2.raw.unpack, iAdH3LXHdlUDhWWghq.cs | High entropy of concatenated method names: 'lq87GZttOD', 'VLD7T3gOGR', 'XEs7DSvsJ2', 'L9j7ym97aL', 'L0W7pdvPfu', 'I1Z7nT5UZh', 'dGU7WppYMO', 'gPd7HHPQWh', 'RQG703XAma', 'cVl7UYDGtA' |
Source: 0.2.PROFORMA + PENDENTES.exe.39a2ad0.2.raw.unpack, ncXHr6HjWNrsHiQysJ.cs | High entropy of concatenated method names: 'iTyEDaiqHH', 'pR0Eyq0gTF', 'loGELJLEhc', 'zTLEpAMcbS', 'mJ4En8yYZX', 's95ENtxAm8', 'De9EWKJ921', 'uZ6EH5dk1K', 'LyTE3y9T0s', 'UpAE0Ey6uF' |
Source: 0.2.PROFORMA + PENDENTES.exe.39a2ad0.2.raw.unpack, TmssbSfd3CWhJyrnTB.cs | High entropy of concatenated method names: 'QOjEl5yDtM', 'TA4E4v4T3r', 'IFgEEQho8E', 'JFDERKnkEX', 'ztYEw3IRV1', 'M2EEQf6hmW', 'Dispose', 'naJ86jBahl', 'h2o8eiXGmK', 'eSQ8KBCL4R' |
Source: 0.2.PROFORMA + PENDENTES.exe.39a2ad0.2.raw.unpack, sh5n6iRcoyLbwQk1Ge.cs | High entropy of concatenated method names: 'kIIJr098Pi', 'o4WJqN9MCy', 'kjgKL7HdMZ', 'i5PKp0vwdn', 'jg0KnuZPgQ', 'zS9KNVrn4M', 'FoFKWqvnf0', 'kGPKHUJGhb', 'IAAK3Y2mAc', 'h1uK0XDoAx' |
Source: 0.2.PROFORMA + PENDENTES.exe.39a2ad0.2.raw.unpack, R8pj7n9eaeWMWbYccx.cs | High entropy of concatenated method names: 'c1n4tp5xxn', 'jMW49ByLhn', 'Yws8csqOsA', 'T2e8jxBoea', 'sMI4UaprmD', 'BNQ4PZ5XoP', 'daS4ZMVt9J', 'HT04dvn7jO', 'Gpc4oncKRk', 'AtM41BSCq6' |
Source: 0.2.PROFORMA + PENDENTES.exe.39a2ad0.2.raw.unpack, fChceiCHC87KuGpc8k.cs | High entropy of concatenated method names: 'FWcbQAdiDw', 'I4gbibEHV5', 'AKybMG6PDU', 'SRebxhnBte', 'IcgbYX2FcR', 'XEkbqjn0Jd', 'SmlbTAw23U', 'RV3bgl9Xlf', 'x1jfkVNDTFYBMLhCQPh', 'a39g0rNmD926so1NT3r' |
Source: 0.2.PROFORMA + PENDENTES.exe.39a2ad0.2.raw.unpack, qnqHVqNKvdgemhNcIJx.cs | High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'HAZvUZlXT7', 'TE8vP593lF', 'giTvZrSafo', 'tC6vdKyndM', 'EbEvoffrtF', 'nQOv1NLlhc', 'cn0vOgh5Mr' |
Source: 0.2.PROFORMA + PENDENTES.exe.39a2ad0.2.raw.unpack, uKGLrW3QqA3lP5biGX.cs | High entropy of concatenated method names: 'cvsedJodIT', 'VadeoPF5B4', 'O5Be1yL9a3', 'ukOeO5duR8', 'fVCemFDjPS', 'U7pekviT5c', 'iQaeIa4jVQ', 'px0et6QQ7E', 'iDFehiDlNC', 'KG6e9pehHD' |
Source: 0.2.PROFORMA + PENDENTES.exe.70c0000.5.raw.unpack, P9YhaUQTPWGmrkJYOM.cs | High entropy of concatenated method names: 'XIVp6ONf92cjxwcseuR', 'qoC1rfNeGjdpd8pKvlj', 'PGxaLkNxItsr69fUPsO', 'hD6b84ho97', 'NqDbE8YaP5', 'jAFbvfIW7F', 'YQSaXbNbxSDTfYZ4m4w', 'Qm8np7NyHuBI2beEffw' |
Source: 0.2.PROFORMA + PENDENTES.exe.70c0000.5.raw.unpack, X8UiX2cvtnoE290aLy.cs | High entropy of concatenated method names: 'RHyl0mtZMt', 'zgFlP4G9OF', 'jQXldykwxZ', 'CMMloiqeV6', 'eHHlyMSkho', 'rRglLpIJvC', 'M2Qlpk5R6V', 'gj2ln5646D', 'uOplN2Y6Xn', 'imWlWgDR5k' |
Source: 0.2.PROFORMA + PENDENTES.exe.70c0000.5.raw.unpack, OPHIWV1rONTdneeeKQ.cs | High entropy of concatenated method names: 'EuGV6Er0jb', 'REaVKLtjUw', 'jHxVbh2hT2', 'cYNb9QXQda', 'XLlbzbIToe', 'PlsVcGB1hk', 'oV5VjIaSbm', 'a6UVu7G666', 'qupVXrICXs', 'd1nVB4f1LA' |
Source: 0.2.PROFORMA + PENDENTES.exe.70c0000.5.raw.unpack, LhTHsGF4RMAZGCa8kn.cs | High entropy of concatenated method names: 'FQnjVoQgwf', 'ltxjFCoTG0', 'H7yjfXKfBO', 'WaRjSZLE8e', 'K0DjldFJwK', 'C6fjA7va4P', 'VvV8Rud3PZC59uom7a', 'VPd6f1cXlKyQQJTTwa', 'KttjjPFT0d', 'vlYjXT8kOD' |
Source: 0.2.PROFORMA + PENDENTES.exe.70c0000.5.raw.unpack, E9LtPwuKpQi6ZoWWhl.cs | High entropy of concatenated method names: 'wfYVi21BK4', 'uWYVsWu3Yg', 'jvRVMKAp96', 'oZjVxNKDhY', 'FAVVrXwCEu', 'yoAVYLJWlX', 'vbCVq3k0aP', 'F1PVGr39aY', 'i5xVTPIPI4', 'DlNVgg2fTg' |
Source: 0.2.PROFORMA + PENDENTES.exe.70c0000.5.raw.unpack, BPtRuoLrWtp4vXFCxG.cs | High entropy of concatenated method names: 'Dispose', 'nZkjhY1GO0', 'EHruy2SgwE', 'uv45mmTDbZ', 'vA9j9EQ7C1', 'xuwjzt5Zyn', 'ProcessDialogKey', 'QU1ucmawwh', 't6XujIX2KD', 'homuutT4ts' |
Source: 0.2.PROFORMA + PENDENTES.exe.70c0000.5.raw.unpack, Q5ojRjNNt049wiCCLRb.cs | High entropy of concatenated method names: 'Cgvv9ZWicw', 'EeAvzDPtNd', 'jr5Rc2TKpq', 'tZ8RjekCQ7', 'l1PRujXYFj', 'BjERXT4aP6', 'rNSRBnDrkT', 'FYjRCOLIjV', 'Yp7R6oD75u', 'wpZRe31uW0' |
Source: 0.2.PROFORMA + PENDENTES.exe.70c0000.5.raw.unpack, oqyhYmNFX41kCRZNwVY.cs | High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'XmJ5EmQLI7', 'YTN5vdGShl', 'MnO5Ry4s4r', 'sCG55Zomaj', 'nyi5w67GGc', 'AY052DtqJS', 'aV95QPHSbB' |
Source: 0.2.PROFORMA + PENDENTES.exe.70c0000.5.raw.unpack, QBD6LeWqfNbDZDo1Gy.cs | High entropy of concatenated method names: 'wiwvKVcg9c', 'xWQvJARZIy', 'pnPvbWDZAr', 'pa1vV9Gt4t', 'IV8vEqYCOk', 'xrJvFS5dai', 'Next', 'Next', 'Next', 'NextBytes' |
Source: 0.2.PROFORMA + PENDENTES.exe.70c0000.5.raw.unpack, gcGUX2Bedx6QaYS31J.cs | High entropy of concatenated method names: 'DL4XCGrFc2', 'FyrX6GnVT5', 'q2DXe7LTNV', 'WkHXKURASD', 'OXPXJ6OPI2', 'geVXbhn7x3', 'jqiXVZGnum', 'sl1XFbali2', 'SJDXahHKn4', 'Fe2XfGNhEv' |
Source: 0.2.PROFORMA + PENDENTES.exe.70c0000.5.raw.unpack, IYGkQihKqcCcxHNjdZ.cs | High entropy of concatenated method names: 'ToString', 'MyRAUgvlob', 'nNJAyHk491', 'crUALZaJJ9', 'BgaApLO5Ay', 'FOVAn1n3Go', 'KguAN3cXZY', 'YoaAW8hJDe', 'XcpAHNWmY8', 'JGoA3mscTG' |
Source: 0.2.PROFORMA + PENDENTES.exe.70c0000.5.raw.unpack, frWEPPZXcI6c8G7QYF.cs | High entropy of concatenated method names: 'QIMMwSIJX', 'Gg0x1JcmF', 'SlnYPgxAj', 'MkHqWFJf1', 'fSJTB8RFf', 'XBxgPAQsx', 'KVWBhZVwCb97fdle7g', 'lIQ5ij3OjSyYSBkHbu', 'Fqd8gkhdy', 'r5svhZkKt' |
Source: 0.2.PROFORMA + PENDENTES.exe.70c0000.5.raw.unpack, v9ObnkTULXnVyWfjQA.cs | High entropy of concatenated method names: 'JJa4fxXhCk', 'eNo4SgrDmI', 'ToString', 'c6G46TjmZy', 'ceD4eN1UaD', 'zW64KfgV2l', 'AIR4JRH7bd', 'KVN4bDmbGI', 'YKK4V95clx', 'JHM4FteeUN' |
Source: 0.2.PROFORMA + PENDENTES.exe.70c0000.5.raw.unpack, UXkvgCEsWpXnGZrTp9.cs | High entropy of concatenated method names: 'OVvbC6SvZS', 'oDVbeR2v0C', 'EEHbJOxKZI', 'KkabVk1kR4', 'jjAbFMhHx8', 'v3kJmBZxNr', 'fRJJk2i9oZ', 'nyLJIkUOA8', 'Mf7JtCj5TD', 'lN3Jh5AhQI' |
Source: 0.2.PROFORMA + PENDENTES.exe.70c0000.5.raw.unpack, bpHb30nysGa21mKvTL.cs | High entropy of concatenated method names: 'EditValue', 'GetEditStyle', 'n0PuhgmEo8', 'p4cu9e4d37', 'iHuuz3ERNt', 'XksXcH1dxB', 'RpGXjrJeFm', 'of3XuHyykB', 'Ea3XXxB5MF', 'VDggKGYF84Q68AYS8I6' |
Source: 0.2.PROFORMA + PENDENTES.exe.70c0000.5.raw.unpack, zgBjQosOJogGKDUmJH.cs | High entropy of concatenated method names: 'uVjKxFNrQi', 'ThoKYAbV7S', 'xymKGdA9GE', 'XgmKTKU1Y0', 'FWJKln8yxQ', 'soiKAQTKJR', 'GbMK4RiOlT', 'EtMK880qDI', 'lP3KEIEAse', 'FTgKvyCTUE' |
Source: 0.2.PROFORMA + PENDENTES.exe.70c0000.5.raw.unpack, iAdH3LXHdlUDhWWghq.cs | High entropy of concatenated method names: 'lq87GZttOD', 'VLD7T3gOGR', 'XEs7DSvsJ2', 'L9j7ym97aL', 'L0W7pdvPfu', 'I1Z7nT5UZh', 'dGU7WppYMO', 'gPd7HHPQWh', 'RQG703XAma', 'cVl7UYDGtA' |
Source: 0.2.PROFORMA + PENDENTES.exe.70c0000.5.raw.unpack, ncXHr6HjWNrsHiQysJ.cs | High entropy of concatenated method names: 'iTyEDaiqHH', 'pR0Eyq0gTF', 'loGELJLEhc', 'zTLEpAMcbS', 'mJ4En8yYZX', 's95ENtxAm8', 'De9EWKJ921', 'uZ6EH5dk1K', 'LyTE3y9T0s', 'UpAE0Ey6uF' |
Source: 0.2.PROFORMA + PENDENTES.exe.70c0000.5.raw.unpack, TmssbSfd3CWhJyrnTB.cs | High entropy of concatenated method names: 'QOjEl5yDtM', 'TA4E4v4T3r', 'IFgEEQho8E', 'JFDERKnkEX', 'ztYEw3IRV1', 'M2EEQf6hmW', 'Dispose', 'naJ86jBahl', 'h2o8eiXGmK', 'eSQ8KBCL4R' |
Source: 0.2.PROFORMA + PENDENTES.exe.70c0000.5.raw.unpack, sh5n6iRcoyLbwQk1Ge.cs | High entropy of concatenated method names: 'kIIJr098Pi', 'o4WJqN9MCy', 'kjgKL7HdMZ', 'i5PKp0vwdn', 'jg0KnuZPgQ', 'zS9KNVrn4M', 'FoFKWqvnf0', 'kGPKHUJGhb', 'IAAK3Y2mAc', 'h1uK0XDoAx' |
Source: 0.2.PROFORMA + PENDENTES.exe.70c0000.5.raw.unpack, R8pj7n9eaeWMWbYccx.cs | High entropy of concatenated method names: 'c1n4tp5xxn', 'jMW49ByLhn', 'Yws8csqOsA', 'T2e8jxBoea', 'sMI4UaprmD', 'BNQ4PZ5XoP', 'daS4ZMVt9J', 'HT04dvn7jO', 'Gpc4oncKRk', 'AtM41BSCq6' |
Source: 0.2.PROFORMA + PENDENTES.exe.70c0000.5.raw.unpack, fChceiCHC87KuGpc8k.cs | High entropy of concatenated method names: 'FWcbQAdiDw', 'I4gbibEHV5', 'AKybMG6PDU', 'SRebxhnBte', 'IcgbYX2FcR', 'XEkbqjn0Jd', 'SmlbTAw23U', 'RV3bgl9Xlf', 'x1jfkVNDTFYBMLhCQPh', 'a39g0rNmD926so1NT3r' |
Source: 0.2.PROFORMA + PENDENTES.exe.70c0000.5.raw.unpack, qnqHVqNKvdgemhNcIJx.cs | High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'HAZvUZlXT7', 'TE8vP593lF', 'giTvZrSafo', 'tC6vdKyndM', 'EbEvoffrtF', 'nQOv1NLlhc', 'cn0vOgh5Mr' |
Source: 0.2.PROFORMA + PENDENTES.exe.70c0000.5.raw.unpack, uKGLrW3QqA3lP5biGX.cs | High entropy of concatenated method names: 'cvsedJodIT', 'VadeoPF5B4', 'O5Be1yL9a3', 'ukOeO5duR8', 'fVCemFDjPS', 'U7pekviT5c', 'iQaeIa4jVQ', 'px0et6QQ7E', 'iDFehiDlNC', 'KG6e9pehHD' |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Thread delayed: delay time: 600000 | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Thread delayed: delay time: 599891 | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Thread delayed: delay time: 599766 | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Thread delayed: delay time: 599641 | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Thread delayed: delay time: 599531 | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Thread delayed: delay time: 599422 | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Thread delayed: delay time: 599313 | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Thread delayed: delay time: 599188 | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Thread delayed: delay time: 599063 | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Thread delayed: delay time: 598953 | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Thread delayed: delay time: 598844 | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Thread delayed: delay time: 598719 | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Thread delayed: delay time: 598610 | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Thread delayed: delay time: 598485 | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Thread delayed: delay time: 598360 | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Thread delayed: delay time: 598235 | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Thread delayed: delay time: 598110 | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Thread delayed: delay time: 597985 | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Thread delayed: delay time: 597860 | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Thread delayed: delay time: 597735 | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Thread delayed: delay time: 597610 | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Thread delayed: delay time: 597485 | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Thread delayed: delay time: 597360 | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Thread delayed: delay time: 597235 | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Thread delayed: delay time: 597110 | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Thread delayed: delay time: 596985 | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Thread delayed: delay time: 596860 | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Thread delayed: delay time: 596735 | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Thread delayed: delay time: 596620 | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Thread delayed: delay time: 596500 | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Thread delayed: delay time: 596391 | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Thread delayed: delay time: 596266 | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Thread delayed: delay time: 596156 | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Thread delayed: delay time: 596047 | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Thread delayed: delay time: 595935 | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Thread delayed: delay time: 595828 | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Thread delayed: delay time: 595719 | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Thread delayed: delay time: 595609 | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Thread delayed: delay time: 595500 | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Thread delayed: delay time: 595391 | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Thread delayed: delay time: 595276 | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Thread delayed: delay time: 595156 | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Thread delayed: delay time: 595047 | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Thread delayed: delay time: 594938 | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Thread delayed: delay time: 594828 | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Thread delayed: delay time: 594719 | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Thread delayed: delay time: 594610 | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Thread delayed: delay time: 594485 | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Thread delayed: delay time: 594360 | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Thread delayed: delay time: 594235 | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Thread delayed: delay time: 922337203685477 | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Thread delayed: delay time: 600000 | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Thread delayed: delay time: 599890 | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Thread delayed: delay time: 599781 | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Thread delayed: delay time: 599672 | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Thread delayed: delay time: 599562 | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Thread delayed: delay time: 599453 | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Thread delayed: delay time: 599344 | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Thread delayed: delay time: 599219 | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Thread delayed: delay time: 599109 | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Thread delayed: delay time: 599000 | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Thread delayed: delay time: 598884 | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Thread delayed: delay time: 598780 | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Thread delayed: delay time: 598672 | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Thread delayed: delay time: 598562 | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Thread delayed: delay time: 598453 | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Thread delayed: delay time: 598343 | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Thread delayed: delay time: 598232 | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Thread delayed: delay time: 598124 | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Thread delayed: delay time: 598015 | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Thread delayed: delay time: 597905 | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Thread delayed: delay time: 597797 | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Thread delayed: delay time: 597687 | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Thread delayed: delay time: 597578 | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Thread delayed: delay time: 597468 | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Thread delayed: delay time: 597359 | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Thread delayed: delay time: 597250 | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Thread delayed: delay time: 597140 | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Thread delayed: delay time: 597028 | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Thread delayed: delay time: 596921 | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Thread delayed: delay time: 596812 | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Thread delayed: delay time: 596703 | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Thread delayed: delay time: 596593 | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Thread delayed: delay time: 596483 | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Thread delayed: delay time: 596374 | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Thread delayed: delay time: 596265 | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Thread delayed: delay time: 596132 | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Thread delayed: delay time: 596031 | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Thread delayed: delay time: 595921 | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Thread delayed: delay time: 595812 | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Thread delayed: delay time: 595703 | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Thread delayed: delay time: 595593 | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Thread delayed: delay time: 595484 | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Thread delayed: delay time: 595375 | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Thread delayed: delay time: 595265 | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Thread delayed: delay time: 595156 | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Thread delayed: delay time: 595047 | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Thread delayed: delay time: 594937 | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Thread delayed: delay time: 594827 | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Thread delayed: delay time: 594716 | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Thread delayed: delay time: 593751 | |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe TID: 7952 | Thread sleep time: -922337203685477s >= -30000s | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe TID: 1152 | Thread sleep count: 6148 > 30 | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe TID: 1848 | Thread sleep time: -1844674407370954s >= -30000s | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe TID: 432 | Thread sleep count: 243 > 30 | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe TID: 1036 | Thread sleep time: -922337203685477s >= -30000s | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe TID: 3232 | Thread sleep time: -8301034833169293s >= -30000s | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe TID: 3568 | Thread sleep time: -922337203685477s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe TID: 3324 | Thread sleep count: 35 > 30 | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe TID: 3324 | Thread sleep time: -32281802128991695s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe TID: 3324 | Thread sleep time: -600000s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe TID: 3324 | Thread sleep time: -599891s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe TID: 3120 | Thread sleep count: 6876 > 30 | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe TID: 3120 | Thread sleep count: 2952 > 30 | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe TID: 3324 | Thread sleep time: -599766s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe TID: 3324 | Thread sleep time: -599641s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe TID: 3324 | Thread sleep time: -599531s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe TID: 3324 | Thread sleep time: -599422s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe TID: 3324 | Thread sleep time: -599313s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe TID: 3324 | Thread sleep time: -599188s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe TID: 3324 | Thread sleep time: -599063s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe TID: 3324 | Thread sleep time: -598953s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe TID: 3324 | Thread sleep time: -598844s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe TID: 3324 | Thread sleep time: -598719s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe TID: 3324 | Thread sleep time: -598610s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe TID: 3324 | Thread sleep time: -598485s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe TID: 3324 | Thread sleep time: -598360s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe TID: 3324 | Thread sleep time: -598235s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe TID: 3324 | Thread sleep time: -598110s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe TID: 3324 | Thread sleep time: -597985s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe TID: 3324 | Thread sleep time: -597860s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe TID: 3324 | Thread sleep time: -597735s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe TID: 3324 | Thread sleep time: -597610s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe TID: 3324 | Thread sleep time: -597485s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe TID: 3324 | Thread sleep time: -597360s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe TID: 3324 | Thread sleep time: -597235s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe TID: 3324 | Thread sleep time: -597110s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe TID: 3324 | Thread sleep time: -596985s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe TID: 3324 | Thread sleep time: -596860s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe TID: 3324 | Thread sleep time: -596735s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe TID: 3324 | Thread sleep time: -596620s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe TID: 3324 | Thread sleep time: -596500s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe TID: 3324 | Thread sleep time: -596391s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe TID: 3324 | Thread sleep time: -596266s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe TID: 3324 | Thread sleep time: -596156s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe TID: 3324 | Thread sleep time: -596047s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe TID: 3324 | Thread sleep time: -595935s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe TID: 3324 | Thread sleep time: -595828s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe TID: 3324 | Thread sleep time: -595719s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe TID: 3324 | Thread sleep time: -595609s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe TID: 3324 | Thread sleep time: -595500s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe TID: 3324 | Thread sleep time: -595391s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe TID: 3324 | Thread sleep time: -595276s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe TID: 3324 | Thread sleep time: -595156s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe TID: 3324 | Thread sleep time: -595047s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe TID: 3324 | Thread sleep time: -594938s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe TID: 3324 | Thread sleep time: -594828s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe TID: 3324 | Thread sleep time: -594719s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe TID: 3324 | Thread sleep time: -594610s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe TID: 3324 | Thread sleep time: -594485s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe TID: 3324 | Thread sleep time: -594360s >= -30000s | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe TID: 3324 | Thread sleep time: -594235s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe TID: 4152 | Thread sleep time: -922337203685477s >= -30000s | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe TID: 6736 | Thread sleep time: -27670116110564310s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe TID: 6736 | Thread sleep time: -600000s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe TID: 6736 | Thread sleep time: -599890s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe TID: 4520 | Thread sleep count: 7618 > 30 | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe TID: 4520 | Thread sleep count: 2237 > 30 | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe TID: 6736 | Thread sleep time: -599781s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe TID: 6736 | Thread sleep time: -599672s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe TID: 6736 | Thread sleep time: -599562s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe TID: 6736 | Thread sleep time: -599453s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe TID: 6736 | Thread sleep time: -599344s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe TID: 6736 | Thread sleep time: -599219s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe TID: 6736 | Thread sleep time: -599109s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe TID: 6736 | Thread sleep time: -599000s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe TID: 6736 | Thread sleep time: -598884s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe TID: 6736 | Thread sleep time: -598780s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe TID: 6736 | Thread sleep time: -598672s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe TID: 6736 | Thread sleep time: -598562s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe TID: 6736 | Thread sleep time: -598453s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe TID: 6736 | Thread sleep time: -598343s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe TID: 6736 | Thread sleep time: -598232s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe TID: 6736 | Thread sleep time: -598124s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe TID: 6736 | Thread sleep time: -598015s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe TID: 6736 | Thread sleep time: -597905s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe TID: 6736 | Thread sleep time: -597797s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe TID: 6736 | Thread sleep time: -597687s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe TID: 6736 | Thread sleep time: -597578s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe TID: 6736 | Thread sleep time: -597468s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe TID: 6736 | Thread sleep time: -597359s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe TID: 6736 | Thread sleep time: -597250s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe TID: 6736 | Thread sleep time: -597140s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe TID: 6736 | Thread sleep time: -597028s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe TID: 6736 | Thread sleep time: -596921s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe TID: 6736 | Thread sleep time: -596812s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe TID: 6736 | Thread sleep time: -596703s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe TID: 6736 | Thread sleep time: -596593s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe TID: 6736 | Thread sleep time: -596483s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe TID: 6736 | Thread sleep time: -596374s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe TID: 6736 | Thread sleep time: -596265s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe TID: 6736 | Thread sleep time: -596132s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe TID: 6736 | Thread sleep time: -596031s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe TID: 6736 | Thread sleep time: -595921s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe TID: 6736 | Thread sleep time: -595812s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe TID: 6736 | Thread sleep time: -595703s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe TID: 6736 | Thread sleep time: -595593s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe TID: 6736 | Thread sleep time: -595484s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe TID: 6736 | Thread sleep time: -595375s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe TID: 6736 | Thread sleep time: -595265s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe TID: 6736 | Thread sleep time: -595156s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe TID: 6736 | Thread sleep time: -595047s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe TID: 6736 | Thread sleep time: -594937s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe TID: 6736 | Thread sleep time: -594827s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe TID: 6736 | Thread sleep time: -594716s >= -30000s | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe TID: 6736 | Thread sleep time: -593751s >= -30000s | |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Thread delayed: delay time: 600000 | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Thread delayed: delay time: 599891 | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Thread delayed: delay time: 599766 | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Thread delayed: delay time: 599641 | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Thread delayed: delay time: 599531 | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Thread delayed: delay time: 599422 | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Thread delayed: delay time: 599313 | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Thread delayed: delay time: 599188 | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Thread delayed: delay time: 599063 | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Thread delayed: delay time: 598953 | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Thread delayed: delay time: 598844 | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Thread delayed: delay time: 598719 | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Thread delayed: delay time: 598610 | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Thread delayed: delay time: 598485 | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Thread delayed: delay time: 598360 | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Thread delayed: delay time: 598235 | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Thread delayed: delay time: 598110 | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Thread delayed: delay time: 597985 | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Thread delayed: delay time: 597860 | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Thread delayed: delay time: 597735 | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Thread delayed: delay time: 597610 | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Thread delayed: delay time: 597485 | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Thread delayed: delay time: 597360 | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Thread delayed: delay time: 597235 | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Thread delayed: delay time: 597110 | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Thread delayed: delay time: 596985 | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Thread delayed: delay time: 596860 | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Thread delayed: delay time: 596735 | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Thread delayed: delay time: 596620 | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Thread delayed: delay time: 596500 | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Thread delayed: delay time: 596391 | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Thread delayed: delay time: 596266 | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Thread delayed: delay time: 596156 | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Thread delayed: delay time: 596047 | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Thread delayed: delay time: 595935 | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Thread delayed: delay time: 595828 | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Thread delayed: delay time: 595719 | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Thread delayed: delay time: 595609 | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Thread delayed: delay time: 595500 | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Thread delayed: delay time: 595391 | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Thread delayed: delay time: 595276 | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Thread delayed: delay time: 595156 | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Thread delayed: delay time: 595047 | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Thread delayed: delay time: 594938 | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Thread delayed: delay time: 594828 | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Thread delayed: delay time: 594719 | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Thread delayed: delay time: 594610 | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Thread delayed: delay time: 594485 | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Thread delayed: delay time: 594360 | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Thread delayed: delay time: 594235 | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Thread delayed: delay time: 922337203685477 | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Thread delayed: delay time: 922337203685477 | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Thread delayed: delay time: 600000 | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Thread delayed: delay time: 599890 | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Thread delayed: delay time: 599781 | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Thread delayed: delay time: 599672 | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Thread delayed: delay time: 599562 | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Thread delayed: delay time: 599453 | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Thread delayed: delay time: 599344 | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Thread delayed: delay time: 599219 | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Thread delayed: delay time: 599109 | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Thread delayed: delay time: 599000 | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Thread delayed: delay time: 598884 | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Thread delayed: delay time: 598780 | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Thread delayed: delay time: 598672 | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Thread delayed: delay time: 598562 | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Thread delayed: delay time: 598453 | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Thread delayed: delay time: 598343 | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Thread delayed: delay time: 598232 | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Thread delayed: delay time: 598124 | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Thread delayed: delay time: 598015 | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Thread delayed: delay time: 597905 | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Thread delayed: delay time: 597797 | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Thread delayed: delay time: 597687 | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Thread delayed: delay time: 597578 | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Thread delayed: delay time: 597468 | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Thread delayed: delay time: 597359 | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Thread delayed: delay time: 597250 | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Thread delayed: delay time: 597140 | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Thread delayed: delay time: 597028 | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Thread delayed: delay time: 596921 | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Thread delayed: delay time: 596812 | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Thread delayed: delay time: 596703 | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Thread delayed: delay time: 596593 | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Thread delayed: delay time: 596483 | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Thread delayed: delay time: 596374 | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Thread delayed: delay time: 596265 | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Thread delayed: delay time: 596132 | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Thread delayed: delay time: 596031 | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Thread delayed: delay time: 595921 | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Thread delayed: delay time: 595812 | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Thread delayed: delay time: 595703 | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Thread delayed: delay time: 595593 | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Thread delayed: delay time: 595484 | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Thread delayed: delay time: 595375 | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Thread delayed: delay time: 595265 | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Thread delayed: delay time: 595156 | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Thread delayed: delay time: 595047 | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Thread delayed: delay time: 594937 | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Thread delayed: delay time: 594827 | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Thread delayed: delay time: 594716 | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Thread delayed: delay time: 593751 | |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Queries volume information: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Speech\v4.0_4.0.0.0__31bf3856ad364e35\System.Speech.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Queries volume information: C:\Windows\Fonts\micross.ttf VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Queries volume information: C:\Windows\Fonts\SHOWG.TTF VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\ VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-GroupPolicy-ClientTools-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-AppManagement-AppV-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\Microsoft.Management.Infrastructure.Native\v4.0_1.0.0.0__31bf3856ad364e35\Microsoft.Management.Infrastructure.Native.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\AppvClient\Microsoft.AppV.AppVClientPowerShell.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1865.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-WOW64-Package~31bf3856ad364e35~amd64~en-GB~10.0.19041.1.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\BitLocker\Microsoft.BitLocker.Structures.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management\v4.0_3.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Management.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\ VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-GroupPolicy-ClientTools-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-AppManagement-AppV-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\Microsoft.Management.Infrastructure.Native\v4.0_1.0.0.0__31bf3856ad364e35\Microsoft.Management.Infrastructure.Native.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\AppvClient\Microsoft.AppV.AppVClientPowerShell.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1865.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-WOW64-Package~31bf3856ad364e35~amd64~en-GB~10.0.19041.1.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\BitLocker\Microsoft.BitLocker.Structures.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management\v4.0_3.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Management.dll VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Queries volume information: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\Desktop\PROFORMA + PENDENTES.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Queries volume information: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Speech\v4.0_4.0.0.0__31bf3856ad364e35\System.Speech.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Queries volume information: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe VolumeInformation | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation | |
Source: C:\Users\user\AppData\Roaming\WYqxTmjfOgdZ.exe | Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation | |