Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Section loaded: mscoree.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Section loaded: vcruntime140_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Section loaded: cryptsp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Section loaded: rsaenh.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Section loaded: cryptbase.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Section loaded: amsi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Section loaded: msasn1.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Section loaded: gpapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Section loaded: windowscodecs.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Section loaded: propsys.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Section loaded: edputil.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Section loaded: urlmon.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Section loaded: iertutil.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Section loaded: srvcli.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Section loaded: netutils.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Section loaded: windows.staterepositoryps.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Section loaded: appresolver.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Section loaded: bcp47langs.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Section loaded: slc.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Section loaded: sppc.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Section loaded: onecorecommonproxystub.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Section loaded: onecoreuapcommonproxystub.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: atl.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: mscoree.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: vcruntime140_clr0400.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: cryptsp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: rsaenh.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: cryptbase.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: amsi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: msasn1.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: msisip.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: wshext.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: appxsip.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: opcservices.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: gpapi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: secur32.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: urlmon.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: iertutil.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: srvcli.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: netutils.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: propsys.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: wininet.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: microsoft.management.infrastructure.native.unmanaged.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: mi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: miutils.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: wmidcom.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: dpapi.dll |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Section loaded: wbemcomn.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Section loaded: mscoree.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Section loaded: vcruntime140_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Section loaded: cryptsp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Section loaded: rsaenh.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Section loaded: cryptbase.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Section loaded: wbemcomn.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Section loaded: amsi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Section loaded: rasapi32.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Section loaded: rasman.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Section loaded: rtutils.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Section loaded: mswsock.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Section loaded: winhttp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Section loaded: ondemandconnroutehelper.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Section loaded: iphlpapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Section loaded: dhcpcsvc6.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Section loaded: dhcpcsvc.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Section loaded: dnsapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Section loaded: winnsi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Section loaded: rasadhlp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Section loaded: fwpuclnt.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Section loaded: vaultcli.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Section loaded: secur32.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Section loaded: schannel.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Section loaded: mskeyprotect.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Section loaded: ntasn1.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Section loaded: ncrypt.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Section loaded: ncryptsslp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Section loaded: msasn1.dll |
Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: fastprox.dll |
Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: ncobjapi.dll |
Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: wbemcomn.dll |
Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: wbemcomn.dll |
Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: mpclient.dll |
Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: msasn1.dll |
Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: wmitomi.dll |
Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: mi.dll |
Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: miutils.dll |
Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: miutils.dll |
Jump to behavior |
Source: C:\Windows\System32\wbem\WmiPrvSE.exe |
Section loaded: gpapi.dll |
Jump to behavior |
Source: 0.2.z81zEuzkJPHHV3KYua.exe.5f20000.5.raw.unpack, EgjJWuawUV8VIQli6e.cs |
High entropy of concatenated method names: 'ToString', 'Be1AimkqOZ', 'p9fAhOOqdF', 'JWaAvaXGQY', 'PfFA63IAsf', 'SFmAJbtWDm', 'dANApQRgCl', 'LscAwp0lEu', 'fOHA8kCyuI', 'GeqAmSmD7D' |
Source: 0.2.z81zEuzkJPHHV3KYua.exe.5f20000.5.raw.unpack, TCYKLZmB9cy4gbvfkU.cs |
High entropy of concatenated method names: 'KTZgsb7RYg', 'wRlgrBY7ZY', 'abFgIxrLMH', 'iuOg0jQpGJ', 'x6lgc5LeDD', 'is8gGFteFP', 'd4QgOMCKaU', 'CQ5gFa3JFh', 'F2qgYeArKB', 'BrIglrNdvH' |
Source: 0.2.z81zEuzkJPHHV3KYua.exe.5f20000.5.raw.unpack, WHeJVtWHd25a3jo1ZT.cs |
High entropy of concatenated method names: 'Dispose', 'mPVPQHFjsZ', 'uvXEhJHj2K', 'x1DcPif94i', 'nK4PMgq3pe', 'QBXPzj9wbP', 'ProcessDialogKey', 'W7AEVaPiR9', 'nyMEPh6cZ7', 'AVyEEcFXeY' |
Source: 0.2.z81zEuzkJPHHV3KYua.exe.5f20000.5.raw.unpack, N2BexxPBx348bC9BET6.cs |
High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'WqQHfIvClV', 'vW4HSvtZgh', 'u1vHjGh3RX', 'pjsHHGRyTP', 'G18HTbwQq1', 'qO5H4eUbgV', 'JgPH2QdBt3' |
Source: 0.2.z81zEuzkJPHHV3KYua.exe.5f20000.5.raw.unpack, xFMHSNtZposDeqssmL.cs |
High entropy of concatenated method names: 'JDTDywNCwV', 'xllDMqN44p', 'irhdVGawiu', 'wUqdPjFDTg', 'AodDi3SOfP', 'BLPDnIFwZQ', 'djkDUSBUSD', 'vlADZh42g6', 'MWFDoZsTNB', 'oHtDaaWvv6' |
Source: 0.2.z81zEuzkJPHHV3KYua.exe.5f20000.5.raw.unpack, PkbD1yF27iOcdZlfR9.cs |
High entropy of concatenated method names: 'molWZkwBEg', 'PhNWoUO2l6', 'gaAWaAdCWm', 'hfCWCMRySO', 'r5tWqIiMyR', 'NYBWtf3ePs', 'M7RWNby2QN', 'SKAWyyMIhZ', 'sU9WQOward', 'ANCWMngjM9' |
Source: 0.2.z81zEuzkJPHHV3KYua.exe.5f20000.5.raw.unpack, P2L4oBNXs9PVHFjsZ9.cs |
High entropy of concatenated method names: 'BfSf15DM0F', 'tFsfDD0MRu', 'akCffUUH7y', 'txcfjEXQRF', 'DUhfTBrpcb', 'Fhpf2GWb0G', 'Dispose', 'i4ud7ORBy3', 'MTldWHp9NE', 'XqEd3CqstS' |
Source: 0.2.z81zEuzkJPHHV3KYua.exe.5f20000.5.raw.unpack, fO1oFSKTWOXP51qUpW.cs |
High entropy of concatenated method names: 'eGxexlYwIh', 'VLTeWYLUv6', 'PQFe5kpt4X', 'CrMegvuXLo', 'hQGeLPE5En', 'qGo5q6vrwF', 'yIj5tpZnjU', 'WPv5NaNSR4', 'w815yRLQKY', 'jW35QT18un' |
Source: 0.2.z81zEuzkJPHHV3KYua.exe.5f20000.5.raw.unpack, JW0klpPPgdnUeqsFK6t.cs |
High entropy of concatenated method names: 'gHYSMKW87Q', 'S1ySzKLpkW', 'bPejVEvUnZ', 'o5ojPN85M4', 'KkYjEEnLXB', 'XCajbu6WZV', 'E2mjBXTVQP', 'rkZjxYE6Kq', 'B8Cj7IPaaW', 'BndjWWKayV' |
Source: 0.2.z81zEuzkJPHHV3KYua.exe.5f20000.5.raw.unpack, OgeqsaUZ6PTppij1Gt.cs |
High entropy of concatenated method names: 'a92XFW0Zra', 'ViNXY2OGjL', 'mAoXK6USFo', 'jtLXha4JZw', 'maTX6bxNcg', 'XJDXJn33sf', 'uBmXw2pmRW', 'fR2X8JBGDh', 'C6QXR9xVW4', 'QmQXi1rOX3' |
Source: 0.2.z81zEuzkJPHHV3KYua.exe.5f20000.5.raw.unpack, zh22NKzsIUSB6yRCT4.cs |
High entropy of concatenated method names: 'lqmSGdGfYG', 'SQsSFldY2B', 'fLBSYxeajx', 'H8LSKtgOQ2', 'nDQSh8AS8g', 'gDdS6LAj57', 'tGlSJBm59i', 'TjhS2PqmEb', 'XlySsBEQTg', 'V5KSr7bT4M' |
Source: 0.2.z81zEuzkJPHHV3KYua.exe.5f20000.5.raw.unpack, fu2cAZE15HapJxOXFl.cs |
High entropy of concatenated method names: 'aNaIqht85', 'fYW01PF7n', 'KLwGZCCu0', 'zjGOQiOdu', 'j6EYqDR9I', 'pselhQDH4', 'zDOlGBb6lcbcxJYv03', 'uPW0o1iednuAUgQElc', 'xhMdaQnkc', 'hcdSOlL1p' |
Source: 0.2.z81zEuzkJPHHV3KYua.exe.5f20000.5.raw.unpack, AFXeYmMRES0FjcYCY4.cs |
High entropy of concatenated method names: 'Y2KS3FXSHd', 'WfUS5ub68T', 'xEGSeqcNFf', 'f2xSgEtm9w', 'Oo7SfVn7p0', 'QfqSLbDqxJ', 'Next', 'Next', 'Next', 'NextBytes' |
Source: 0.2.z81zEuzkJPHHV3KYua.exe.5f20000.5.raw.unpack, qn9GZHwXA1UA5E0qFA.cs |
High entropy of concatenated method names: 'yqcg7B4Tgw', 'Tlkg3XgsEv', 'f1IgeYS5HX', 'HhMeM7Ii3f', 'jZsezLnD1m', 'NG2gV64BIH', 'stngPcVWiH', 'cPtgE4iwKo', 'zqxgbiqbHd', 'uXhgBgGkK5' |
Source: 0.2.z81zEuzkJPHHV3KYua.exe.5f20000.5.raw.unpack, paPiR9Q9yMh6cZ70Vy.cs |
High entropy of concatenated method names: 'nOGfKReCHp', 'PKcfha5wxb', 'pyvfv74qjs', 'gaXf6nIff0', 'cGafJgGRa6', 'zJ7fpZCtam', 'VfnfwKHgRg', 'EXnf8yojQV', 'BHZfmAe5q3', 'rj1fRAJe9k' |
Source: 0.2.z81zEuzkJPHHV3KYua.exe.5f20000.5.raw.unpack, GyoxbTL0R84sRAmXa1.cs |
High entropy of concatenated method names: 'I53bxvSS7Y', 'b5Bb74L4eu', 'jGwbWF2SOu', 'NEHb3vPTiZ', 'HiQb5IcCHt', 'zmpbebJV6g', 'V5obgRWT4b', 'beubLk8ZrZ', 'q60buG55cg', 'i6pbkbabcW' |
Source: 0.2.z81zEuzkJPHHV3KYua.exe.5f20000.5.raw.unpack, rqAGhtBXPQH2N5PTAg.cs |
High entropy of concatenated method names: 'AKnPgkbD1y', 'x7iPLOcdZl', 'ipUPk9VGVE', 'd62P9YQyfQ', 'tswP1qN7O1', 'SFSPATWOXP', 'UOEEYQE2mCuDv70uls', 'eiyxJfZBxHqLnoH0Ct', 'FgvPPjvGgK', 'tKTPbmJrCL' |
Source: 0.2.z81zEuzkJPHHV3KYua.exe.5f20000.5.raw.unpack, pGmfDeYpU9VGVEb62Y.cs |
High entropy of concatenated method names: 'AjQ30V7ofl', 'MHY3GUc5vE', 'VvG3FYAagm', 'glo3Y8SPjW', 'PyH31RJUme', 'pgt3A0RRNm', 'hVG3DI8sIU', 'sW13dDykCL', 'xiV3fDAoJ5', 'f7M3SZRT4C' |
Source: 0.2.z81zEuzkJPHHV3KYua.exe.3c2ccc0.1.raw.unpack, EgjJWuawUV8VIQli6e.cs |
High entropy of concatenated method names: 'ToString', 'Be1AimkqOZ', 'p9fAhOOqdF', 'JWaAvaXGQY', 'PfFA63IAsf', 'SFmAJbtWDm', 'dANApQRgCl', 'LscAwp0lEu', 'fOHA8kCyuI', 'GeqAmSmD7D' |
Source: 0.2.z81zEuzkJPHHV3KYua.exe.3c2ccc0.1.raw.unpack, TCYKLZmB9cy4gbvfkU.cs |
High entropy of concatenated method names: 'KTZgsb7RYg', 'wRlgrBY7ZY', 'abFgIxrLMH', 'iuOg0jQpGJ', 'x6lgc5LeDD', 'is8gGFteFP', 'd4QgOMCKaU', 'CQ5gFa3JFh', 'F2qgYeArKB', 'BrIglrNdvH' |
Source: 0.2.z81zEuzkJPHHV3KYua.exe.3c2ccc0.1.raw.unpack, WHeJVtWHd25a3jo1ZT.cs |
High entropy of concatenated method names: 'Dispose', 'mPVPQHFjsZ', 'uvXEhJHj2K', 'x1DcPif94i', 'nK4PMgq3pe', 'QBXPzj9wbP', 'ProcessDialogKey', 'W7AEVaPiR9', 'nyMEPh6cZ7', 'AVyEEcFXeY' |
Source: 0.2.z81zEuzkJPHHV3KYua.exe.3c2ccc0.1.raw.unpack, N2BexxPBx348bC9BET6.cs |
High entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'WqQHfIvClV', 'vW4HSvtZgh', 'u1vHjGh3RX', 'pjsHHGRyTP', 'G18HTbwQq1', 'qO5H4eUbgV', 'JgPH2QdBt3' |
Source: 0.2.z81zEuzkJPHHV3KYua.exe.3c2ccc0.1.raw.unpack, xFMHSNtZposDeqssmL.cs |
High entropy of concatenated method names: 'JDTDywNCwV', 'xllDMqN44p', 'irhdVGawiu', 'wUqdPjFDTg', 'AodDi3SOfP', 'BLPDnIFwZQ', 'djkDUSBUSD', 'vlADZh42g6', 'MWFDoZsTNB', 'oHtDaaWvv6' |
Source: 0.2.z81zEuzkJPHHV3KYua.exe.3c2ccc0.1.raw.unpack, PkbD1yF27iOcdZlfR9.cs |
High entropy of concatenated method names: 'molWZkwBEg', 'PhNWoUO2l6', 'gaAWaAdCWm', 'hfCWCMRySO', 'r5tWqIiMyR', 'NYBWtf3ePs', 'M7RWNby2QN', 'SKAWyyMIhZ', 'sU9WQOward', 'ANCWMngjM9' |
Source: 0.2.z81zEuzkJPHHV3KYua.exe.3c2ccc0.1.raw.unpack, P2L4oBNXs9PVHFjsZ9.cs |
High entropy of concatenated method names: 'BfSf15DM0F', 'tFsfDD0MRu', 'akCffUUH7y', 'txcfjEXQRF', 'DUhfTBrpcb', 'Fhpf2GWb0G', 'Dispose', 'i4ud7ORBy3', 'MTldWHp9NE', 'XqEd3CqstS' |
Source: 0.2.z81zEuzkJPHHV3KYua.exe.3c2ccc0.1.raw.unpack, fO1oFSKTWOXP51qUpW.cs |
High entropy of concatenated method names: 'eGxexlYwIh', 'VLTeWYLUv6', 'PQFe5kpt4X', 'CrMegvuXLo', 'hQGeLPE5En', 'qGo5q6vrwF', 'yIj5tpZnjU', 'WPv5NaNSR4', 'w815yRLQKY', 'jW35QT18un' |
Source: 0.2.z81zEuzkJPHHV3KYua.exe.3c2ccc0.1.raw.unpack, JW0klpPPgdnUeqsFK6t.cs |
High entropy of concatenated method names: 'gHYSMKW87Q', 'S1ySzKLpkW', 'bPejVEvUnZ', 'o5ojPN85M4', 'KkYjEEnLXB', 'XCajbu6WZV', 'E2mjBXTVQP', 'rkZjxYE6Kq', 'B8Cj7IPaaW', 'BndjWWKayV' |
Source: 0.2.z81zEuzkJPHHV3KYua.exe.3c2ccc0.1.raw.unpack, OgeqsaUZ6PTppij1Gt.cs |
High entropy of concatenated method names: 'a92XFW0Zra', 'ViNXY2OGjL', 'mAoXK6USFo', 'jtLXha4JZw', 'maTX6bxNcg', 'XJDXJn33sf', 'uBmXw2pmRW', 'fR2X8JBGDh', 'C6QXR9xVW4', 'QmQXi1rOX3' |
Source: 0.2.z81zEuzkJPHHV3KYua.exe.3c2ccc0.1.raw.unpack, zh22NKzsIUSB6yRCT4.cs |
High entropy of concatenated method names: 'lqmSGdGfYG', 'SQsSFldY2B', 'fLBSYxeajx', 'H8LSKtgOQ2', 'nDQSh8AS8g', 'gDdS6LAj57', 'tGlSJBm59i', 'TjhS2PqmEb', 'XlySsBEQTg', 'V5KSr7bT4M' |
Source: 0.2.z81zEuzkJPHHV3KYua.exe.3c2ccc0.1.raw.unpack, fu2cAZE15HapJxOXFl.cs |
High entropy of concatenated method names: 'aNaIqht85', 'fYW01PF7n', 'KLwGZCCu0', 'zjGOQiOdu', 'j6EYqDR9I', 'pselhQDH4', 'zDOlGBb6lcbcxJYv03', 'uPW0o1iednuAUgQElc', 'xhMdaQnkc', 'hcdSOlL1p' |
Source: 0.2.z81zEuzkJPHHV3KYua.exe.3c2ccc0.1.raw.unpack, AFXeYmMRES0FjcYCY4.cs |
High entropy of concatenated method names: 'Y2KS3FXSHd', 'WfUS5ub68T', 'xEGSeqcNFf', 'f2xSgEtm9w', 'Oo7SfVn7p0', 'QfqSLbDqxJ', 'Next', 'Next', 'Next', 'NextBytes' |
Source: 0.2.z81zEuzkJPHHV3KYua.exe.3c2ccc0.1.raw.unpack, qn9GZHwXA1UA5E0qFA.cs |
High entropy of concatenated method names: 'yqcg7B4Tgw', 'Tlkg3XgsEv', 'f1IgeYS5HX', 'HhMeM7Ii3f', 'jZsezLnD1m', 'NG2gV64BIH', 'stngPcVWiH', 'cPtgE4iwKo', 'zqxgbiqbHd', 'uXhgBgGkK5' |
Source: 0.2.z81zEuzkJPHHV3KYua.exe.3c2ccc0.1.raw.unpack, paPiR9Q9yMh6cZ70Vy.cs |
High entropy of concatenated method names: 'nOGfKReCHp', 'PKcfha5wxb', 'pyvfv74qjs', 'gaXf6nIff0', 'cGafJgGRa6', 'zJ7fpZCtam', 'VfnfwKHgRg', 'EXnf8yojQV', 'BHZfmAe5q3', 'rj1fRAJe9k' |
Source: 0.2.z81zEuzkJPHHV3KYua.exe.3c2ccc0.1.raw.unpack, GyoxbTL0R84sRAmXa1.cs |
High entropy of concatenated method names: 'I53bxvSS7Y', 'b5Bb74L4eu', 'jGwbWF2SOu', 'NEHb3vPTiZ', 'HiQb5IcCHt', 'zmpbebJV6g', 'V5obgRWT4b', 'beubLk8ZrZ', 'q60buG55cg', 'i6pbkbabcW' |
Source: 0.2.z81zEuzkJPHHV3KYua.exe.3c2ccc0.1.raw.unpack, rqAGhtBXPQH2N5PTAg.cs |
High entropy of concatenated method names: 'AKnPgkbD1y', 'x7iPLOcdZl', 'ipUPk9VGVE', 'd62P9YQyfQ', 'tswP1qN7O1', 'SFSPATWOXP', 'UOEEYQE2mCuDv70uls', 'eiyxJfZBxHqLnoH0Ct', 'FgvPPjvGgK', 'tKTPbmJrCL' |
Source: 0.2.z81zEuzkJPHHV3KYua.exe.3c2ccc0.1.raw.unpack, pGmfDeYpU9VGVEb62Y.cs |
High entropy of concatenated method names: 'AjQ30V7ofl', 'MHY3GUc5vE', 'VvG3FYAagm', 'glo3Y8SPjW', 'PyH31RJUme', 'pgt3A0RRNm', 'hVG3DI8sIU', 'sW13dDykCL', 'xiV3fDAoJ5', 'f7M3SZRT4C' |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe TID: 7424 |
Thread sleep time: -922337203685477s >= -30000s |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe TID: 7684 |
Thread sleep time: -8301034833169293s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe TID: 7820 |
Thread sleep count: 42 > 30 |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe TID: 7820 |
Thread sleep time: -38738162554790034s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe TID: 7820 |
Thread sleep time: -100000s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe TID: 7824 |
Thread sleep count: 2017 > 30 |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe TID: 7820 |
Thread sleep time: -99891s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe TID: 7824 |
Thread sleep count: 7817 > 30 |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe TID: 7820 |
Thread sleep time: -99781s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe TID: 7820 |
Thread sleep time: -99672s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe TID: 7820 |
Thread sleep time: -99560s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe TID: 7820 |
Thread sleep time: -99451s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe TID: 7820 |
Thread sleep time: -99275s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe TID: 7820 |
Thread sleep time: -99164s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe TID: 7820 |
Thread sleep time: -99053s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe TID: 7820 |
Thread sleep time: -98922s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe TID: 7820 |
Thread sleep time: -98813s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe TID: 7820 |
Thread sleep time: -98703s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe TID: 7820 |
Thread sleep time: -98594s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe TID: 7820 |
Thread sleep time: -98469s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe TID: 7820 |
Thread sleep time: -98360s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe TID: 7820 |
Thread sleep time: -98235s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe TID: 7820 |
Thread sleep time: -98110s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe TID: 7820 |
Thread sleep time: -97985s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe TID: 7820 |
Thread sleep time: -97860s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe TID: 7820 |
Thread sleep time: -97735s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe TID: 7820 |
Thread sleep time: -97610s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe TID: 7820 |
Thread sleep time: -97485s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe TID: 7820 |
Thread sleep time: -97360s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe TID: 7820 |
Thread sleep time: -97235s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe TID: 7820 |
Thread sleep time: -97110s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe TID: 7820 |
Thread sleep time: -96985s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe TID: 7820 |
Thread sleep time: -96860s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe TID: 7820 |
Thread sleep time: -96735s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe TID: 7820 |
Thread sleep time: -96545s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe TID: 7820 |
Thread sleep time: -96323s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe TID: 7820 |
Thread sleep time: -96210s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe TID: 7820 |
Thread sleep time: -96094s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe TID: 7820 |
Thread sleep time: -95984s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe TID: 7820 |
Thread sleep time: -95875s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe TID: 7820 |
Thread sleep time: -95765s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe TID: 7820 |
Thread sleep time: -95641s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe TID: 7820 |
Thread sleep time: -95531s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe TID: 7820 |
Thread sleep time: -95422s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe TID: 7820 |
Thread sleep time: -95313s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe TID: 7820 |
Thread sleep time: -95203s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe TID: 7820 |
Thread sleep time: -95094s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe TID: 7820 |
Thread sleep time: -94984s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe TID: 7820 |
Thread sleep time: -94875s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe TID: 7820 |
Thread sleep time: -94766s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe TID: 7820 |
Thread sleep time: -94656s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe TID: 7820 |
Thread sleep time: -94536s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe TID: 7820 |
Thread sleep time: -94406s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe TID: 7820 |
Thread sleep time: -94297s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe TID: 7820 |
Thread sleep time: -94172s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe TID: 7820 |
Thread sleep time: -94062s >= -30000s |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Thread delayed: delay time: 922337203685477 |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Thread delayed: delay time: 922337203685477 |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Thread delayed: delay time: 922337203685477 |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Thread delayed: delay time: 100000 |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Thread delayed: delay time: 99891 |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Thread delayed: delay time: 99781 |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Thread delayed: delay time: 99672 |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Thread delayed: delay time: 99560 |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Thread delayed: delay time: 99451 |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Thread delayed: delay time: 99275 |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Thread delayed: delay time: 99164 |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Thread delayed: delay time: 99053 |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Thread delayed: delay time: 98922 |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Thread delayed: delay time: 98813 |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Thread delayed: delay time: 98703 |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Thread delayed: delay time: 98594 |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Thread delayed: delay time: 98469 |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Thread delayed: delay time: 98360 |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Thread delayed: delay time: 98235 |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Thread delayed: delay time: 98110 |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Thread delayed: delay time: 97985 |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Thread delayed: delay time: 97860 |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Thread delayed: delay time: 97735 |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Thread delayed: delay time: 97610 |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Thread delayed: delay time: 97485 |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Thread delayed: delay time: 97360 |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Thread delayed: delay time: 97235 |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Thread delayed: delay time: 97110 |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Thread delayed: delay time: 96985 |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Thread delayed: delay time: 96860 |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Thread delayed: delay time: 96735 |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Thread delayed: delay time: 96545 |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Thread delayed: delay time: 96323 |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Thread delayed: delay time: 96210 |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Thread delayed: delay time: 96094 |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Thread delayed: delay time: 95984 |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Thread delayed: delay time: 95875 |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Thread delayed: delay time: 95765 |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Thread delayed: delay time: 95641 |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Thread delayed: delay time: 95531 |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Thread delayed: delay time: 95422 |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Thread delayed: delay time: 95313 |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Thread delayed: delay time: 95203 |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Thread delayed: delay time: 95094 |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Thread delayed: delay time: 94984 |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Thread delayed: delay time: 94875 |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Thread delayed: delay time: 94766 |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Thread delayed: delay time: 94656 |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Thread delayed: delay time: 94536 |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Thread delayed: delay time: 94406 |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Thread delayed: delay time: 94297 |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Thread delayed: delay time: 94172 |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Thread delayed: delay time: 94062 |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Queries volume information: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\ VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-GroupPolicy-ClientTools-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-AppManagement-AppV-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\Microsoft.Management.Infrastructure.Native\v4.0_1.0.0.0__31bf3856ad364e35\Microsoft.Management.Infrastructure.Native.dll VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\AppvClient\Microsoft.AppV.AppVClientPowerShell.dll VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-WOW64-Package~31bf3856ad364e35~amd64~en-GB~10.0.19041.1.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\BitLocker\Microsoft.BitLocker.Structures.dll VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management\v4.0_3.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Management.dll VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation |
Jump to behavior |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Queries volume information: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Security\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Security.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation |
Jump to behavior |
Source: C:\Users\user\Desktop\z81zEuzkJPHHV3KYua.exe |
Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation |
Jump to behavior |