Windows Analysis Report
http://www.kalenderpedia.de

Overview

General Information

Sample URL: http://www.kalenderpedia.de
Analysis ID: 1562251
Infos:

Detection

Score: 60
Range: 0 - 100
Whitelisted: false
Confidence: 100%

Signatures

AI detected landing page (webpage, office document or email)
Allocates memory in foreign processes
Loading BitLocker PowerShell Module
Suspicious execution chain found
Writes to foreign memory regions
Allocates memory with a write watch (potentially for evading sandboxes)
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Creates files inside the system directory
Drops PE files
Enables debug privileges
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
HTML page contains hidden javascript code
HTML page contains string obfuscation
May sleep (evasive loops) to hinder dynamic analysis
Queries disk information (often used to detect virtual machines)
Queries the volume information (name, serial number etc) of a device
Searches for user specific document files
Stores files to the Windows start menu directory
Suricata IDS alerts with low severity for network traffic

Classification

Phishing

barindex
Source: https://www.kalenderpedia.de/kalender/kalender-2025-baden-wuerttemberg-pdf-vorlagen.html Joe Sandbox AI: Page contains button: 'Free Download' Source: '2.5.pages.csv'
Source: https://www.kalenderpedia.de/kalender/kalender-2025-baden-wuerttemberg-pdf-vorlagen.html HTTP Parser: Base64 decoded: ai=CNH_v1llEZ4DbGtO6wuIP-vS_uQTPpfy4e_PKtPHEE4qb8uCyDxABIO_x8B1gyQagAZ_6y6EoyAECqAMByAPJBKoEowJP0Bcz8ZwaN5ZiphYMi4i1n-JpZdsaUHe6D0jmwK4xIIFUjeSzgnVGo5RbqteQ9pvLQ6fHvUrvpTtnoyPedkjawXXITI-KyvNCQzRmmKS0upPtr0FMqNJG2ExUT6p3V51rRGdHDvcKV5t5PYw7F6wNfQ8bsBw47yA...
Source: https://770e87a8b147b489f22ffddfe48f7a28.safeframe.googlesyndication.com/safeframe/1-0-40/html/container.html HTTP Parser: Found new string: script (function() {var u = 'https://googleads.g.doubleclick.net/dbm/ad?dbm_c=AKAmf-ACtKcj67W0gEoFi6fZG4L-cFb-wJA5TbhWi6rO_RwdF61thekBXDqcNVc5ijPuI_6ZcdHYlcqdhfNGMl1-8YI2-ipI0xPs725CiqQ-s39rR6FRD3m5b13QKT8j8jOGC4NblvNS1F5LYCc5_9oBUqy67ncWzsTJqotkdwIe6DjwDPaCB39he5_wW6mERj-dz4ZfaL_u6cy9gcLUAm_c3Oiy7tXgFh_YU7oZJ24_ZQyhWaBmlsc&dbm_d=AKAmf-AR1nZ9HbPJz3DZBsq5ugCZ0f57NN7rN_3gT7lOVaavF7t98QQnmdjzu2Xww4lsWflaLAVpc9rn9Xim3Q5Eu3jn0s4d2B1IHD1eMfkRuFOvb6A73KKPJDMu0a0NtyMWTvb5mt4SfKPP3z3wQvsuOHjI__BCDCmKsxsmZ52Nj7U1fi0V8jwmQe5SQqe25Ad48U5I0ayPXSPcUAhhU8w53Hnj1z1nU5Ft86KjPZU6lZoFUlk6faSic8IsXgBQRK4QlzVpvQXLy5SKaOfvjOveyEDJqY7S3miybjXDkNbnn7G8GNO7_4jRucAMa8I63iargqZB_wPI1CTIz4wU4y2Jb6cNJ0zGzRrPC1s9Lqfq3HKnTXrx1HuF4b1fkSm7EyQs8OHgI_tt0ijXLIcgP56gvSevsGCC0-C0t_zzcGBrDPH5J8lOSUT5hCV-yTMaJwXc0sQGsjUWhXvnAT-ruOaSOFWBl1fsAeZv6ZqaPld3LH1zOODc7PY7iKyy59gXiCTyPknHz4_WgUkCEfOc36F9vf6I9XqX1x2vdn-JpqWDEjM-qWSHqNapeOtmFHEfRUdqEZuc1nFxoMQluVAeGsNlZ9cwUVjMIr9gXV2BrhE7ozfnmWb-OPhyPyEulf-H8Im2CQNjuLbfFxQypCSacIqMBaGXccgv1HoiE6Jm8-zRHFARojh3mGqQ5Jq...
Source: https://www.kalenderpedia.de/kalender/kalender-2025-baden-wuerttemberg-pdf-vorlagen.html HTTP Parser: No favicon
Source: https://www.kalenderpedia.de/kalender/kalender-2025-baden-wuerttemberg-pdf-vorlagen.html HTTP Parser: No favicon
Source: https://www.kalenderpedia.de/kalender/kalender-2025-baden-wuerttemberg-pdf-vorlagen.html HTTP Parser: No favicon
Source: https://www.kalenderpedia.de/kalender/kalender-2025-baden-wuerttemberg-pdf-vorlagen.html HTTP Parser: No favicon
Source: https://www.zipthisapp.com/?campaign_id=21618891755&adgroup_id=167980995562&placement_id=www.kalenderpedia.de&creative_id=722419053047&utm_source=google_b2c&gad_source=5&gclid=EAIaIQobChMIgJ7Bnqv3iQMVU51QBh16-i9HEAEYASAAEgLvG_D_BwE HTTP Parser: No favicon
Source: https://www.zipthisapp.com/?campaign_id=21618891755&adgroup_id=167980995562&placement_id=www.kalenderpedia.de&creative_id=722419053047&utm_source=google_b2c&gad_source=5&gclid=EAIaIQobChMIgJ7Bnqv3iQMVU51QBh16-i9HEAEYASAAEgLvG_D_BwE HTTP Parser: No favicon
Source: https://www.zipthisapp.com/?campaign_id=21618891755&adgroup_id=167980995562&placement_id=www.kalenderpedia.de&creative_id=722419053047&utm_source=google_b2c&gad_source=5&gclid=EAIaIQobChMIgJ7Bnqv3iQMVU51QBh16-i9HEAEYASAAEgLvG_D_BwE HTTP Parser: No favicon
Source: https://www.zipthisapp.com/?campaign_id=21618891755&adgroup_id=167980995562&placement_id=www.kalenderpedia.de&creative_id=722419053047&utm_source=google_b2c&gad_source=5&gclid=EAIaIQobChMIgJ7Bnqv3iQMVU51QBh16-i9HEAEYASAAEgLvG_D_BwE HTTP Parser: No favicon
Source: https://www.zipthisapp.com/?campaign_id=21618891755&adgroup_id=167980995562&placement_id=www.kalenderpedia.de&creative_id=722419053047&utm_source=google_b2c&gad_source=5&gclid=EAIaIQobChMIgJ7Bnqv3iQMVU51QBh16-i9HEAEYASAAEgLvG_D_BwE HTTP Parser: No favicon
Source: https://www.zipthisapp.com/?campaign_id=21618891755&adgroup_id=167980995562&placement_id=www.kalenderpedia.de&creative_id=722419053047&utm_source=google_b2c&gad_source=5&gclid=EAIaIQobChMIgJ7Bnqv3iQMVU51QBh16-i9HEAEYASAAEgLvG_D_BwE HTTP Parser: No favicon
Source: https://www.zipthisapp.com/?campaign_id=21618891755&adgroup_id=167980995562&placement_id=www.kalenderpedia.de&creative_id=722419053047&utm_source=google_b2c&gad_source=5&gclid=EAIaIQobChMIgJ7Bnqv3iQMVU51QBh16-i9HEAEYASAAEgLvG_D_BwE HTTP Parser: No favicon
Source: https://www.zipthisapp.com/success?u=c14bc5b0-c4ea-49fa-aae2-e47c61b59c5b HTTP Parser: No favicon
Source: https://www.zipthisapp.com/success?u=c14bc5b0-c4ea-49fa-aae2-e47c61b59c5b HTTP Parser: No favicon
Source: https://www.zipthisapp.com/success?u=c14bc5b0-c4ea-49fa-aae2-e47c61b59c5b HTTP Parser: No favicon
Source: C:\Users\user\Downloads\ZipThis.exe Registry value created: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ZipThis
Source: unknown HTTPS traffic detected: 23.218.208.109:443 -> 192.168.2.16:49731 version: TLS 1.2
Source: unknown HTTPS traffic detected: 23.218.208.109:443 -> 192.168.2.16:49746 version: TLS 1.2
Source: unknown HTTPS traffic detected: 4.175.87.197:443 -> 192.168.2.16:49749 version: TLS 1.2
Source: unknown HTTPS traffic detected: 4.175.87.197:443 -> 192.168.2.16:50019 version: TLS 1.2
Source: unknown HTTPS traffic detected: 45.33.84.9:443 -> 192.168.2.16:50026 version: TLS 1.2
Source: unknown HTTPS traffic detected: 45.33.84.9:443 -> 192.168.2.16:50031 version: TLS 1.2
Source: unknown HTTPS traffic detected: 45.33.84.9:443 -> 192.168.2.16:50068 version: TLS 1.2
Source: unknown HTTPS traffic detected: 45.33.84.9:443 -> 192.168.2.16:50067 version: TLS 1.2
Source: unknown HTTPS traffic detected: 45.33.84.9:443 -> 192.168.2.16:50078 version: TLS 1.2
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe File opened: C:\Users\user
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe File opened: C:\Users\user\AppData\Roaming
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe File opened: C:\Users\user\AppData\Roaming\Microsoft\Windows
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe File opened: C:\Users\user\AppData\Roaming\Microsoft\Windows\Libraries\desktop.ini
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe File opened: C:\Users\user\AppData\Roaming\Microsoft
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe File opened: C:\Users\user\AppData

Software Vulnerabilities

barindex
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Child: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
Source: Network traffic Suricata IDS: 2022112 - Severity 1 - ET EXPLOIT_KIT Possible Nuclear EK Landing Nov 17 2015 : 192.168.2.16:49911 -> 68.183.48.219:80
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown TCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknown TCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknown TCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknown TCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknown TCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknown TCP traffic detected without corresponding DNS query: 192.229.211.108
Source: unknown TCP traffic detected without corresponding DNS query: 23.218.208.109
Source: unknown TCP traffic detected without corresponding DNS query: 23.218.208.109
Source: unknown TCP traffic detected without corresponding DNS query: 23.218.208.109
Source: unknown TCP traffic detected without corresponding DNS query: 23.218.208.109
Source: unknown TCP traffic detected without corresponding DNS query: 23.218.208.109
Source: unknown TCP traffic detected without corresponding DNS query: 23.218.208.109
Source: unknown TCP traffic detected without corresponding DNS query: 23.218.208.109
Source: unknown TCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknown TCP traffic detected without corresponding DNS query: 23.218.208.109
Source: unknown TCP traffic detected without corresponding DNS query: 23.218.208.109
Source: unknown TCP traffic detected without corresponding DNS query: 23.218.208.109
Source: unknown TCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknown TCP traffic detected without corresponding DNS query: 23.218.208.109
Source: unknown TCP traffic detected without corresponding DNS query: 23.218.208.109
Source: unknown TCP traffic detected without corresponding DNS query: 23.218.208.109
Source: unknown TCP traffic detected without corresponding DNS query: 4.175.87.197
Source: unknown TCP traffic detected without corresponding DNS query: 4.175.87.197
Source: unknown TCP traffic detected without corresponding DNS query: 4.175.87.197
Source: unknown TCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknown TCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknown TCP traffic detected without corresponding DNS query: 23.218.208.109
Source: unknown TCP traffic detected without corresponding DNS query: 23.218.208.109
Source: unknown TCP traffic detected without corresponding DNS query: 23.218.208.109
Source: unknown TCP traffic detected without corresponding DNS query: 20.189.173.10
Source: unknown TCP traffic detected without corresponding DNS query: 23.218.208.109
Source: unknown TCP traffic detected without corresponding DNS query: 23.218.208.109
Source: unknown TCP traffic detected without corresponding DNS query: 23.218.208.109
Source: unknown TCP traffic detected without corresponding DNS query: 4.175.87.197
Source: unknown TCP traffic detected without corresponding DNS query: 4.175.87.197
Source: unknown TCP traffic detected without corresponding DNS query: 4.175.87.197
Source: unknown TCP traffic detected without corresponding DNS query: 4.175.87.197
Source: unknown TCP traffic detected without corresponding DNS query: 4.175.87.197
Source: unknown TCP traffic detected without corresponding DNS query: 4.175.87.197
Source: unknown TCP traffic detected without corresponding DNS query: 4.175.87.197
Source: unknown TCP traffic detected without corresponding DNS query: 4.175.87.197
Source: unknown TCP traffic detected without corresponding DNS query: 4.175.87.197
Source: unknown TCP traffic detected without corresponding DNS query: 4.175.87.197
Source: unknown TCP traffic detected without corresponding DNS query: 4.175.87.197
Source: unknown TCP traffic detected without corresponding DNS query: 4.175.87.197
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global traffic HTTP traffic detected: GET / HTTP/1.1Host: www.kalenderpedia.deConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global traffic HTTP traffic detected: GET /?campaign_id=21618891755&adgroup_id=167980995562&placement_id=www.kalenderpedia.de&creative_id=722419053047&utm_source=google_b2c&gad_source=5&gclid=EAIaIQobChMIgJ7Bnqv3iQMVU51QBh16-i9HEAEYASAAEgLvG_D_BwE HTTP/1.1Host: www.zipthisapp.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global traffic DNS traffic detected: DNS query: www.kalenderpedia.de
Source: global traffic DNS traffic detected: DNS query: www.google.com
Source: global traffic DNS traffic detected: DNS query: cdn-a.yieldlove.com
Source: global traffic DNS traffic detected: DNS query: securepubads.g.doubleclick.net
Source: global traffic DNS traffic detected: DNS query: cse.google.com
Source: global traffic DNS traffic detected: DNS query: googleads.g.doubleclick.net
Source: global traffic DNS traffic detected: DNS query: cdn.jsdelivr.net
Source: global traffic DNS traffic detected: DNS query: www.statcounter.com
Source: global traffic DNS traffic detected: DNS query: www.adsensecustomsearchads.com
Source: global traffic DNS traffic detected: DNS query: scatteredstream.com
Source: global traffic DNS traffic detected: DNS query: cdn.confiant-integrations.net
Source: global traffic DNS traffic detected: DNS query: static.adsafeprotected.com
Source: global traffic DNS traffic detected: DNS query: c.statcounter.com
Source: global traffic DNS traffic detected: DNS query: fundingchoicesmessages.google.com
Source: global traffic DNS traffic detected: DNS query: syndicatedsearch.goog
Source: global traffic DNS traffic detected: DNS query: gum.criteo.com
Source: global traffic DNS traffic detected: DNS query: id5-sync.com
Source: global traffic DNS traffic detected: DNS query: hb.adscale.de
Source: global traffic DNS traffic detected: DNS query: fastlane.rubiconproject.com
Source: global traffic DNS traffic detected: DNS query: prg.smartadserver.com
Source: global traffic DNS traffic detected: DNS query: htlb.casalemedia.com
Source: global traffic DNS traffic detected: DNS query: ib.adnxs.com
Source: global traffic DNS traffic detected: DNS query: hbopenbid.pubmatic.com
Source: global traffic DNS traffic detected: DNS query: adx2.adform.net
Source: global traffic DNS traffic detected: DNS query: prod-ingestion.tracking.v2.yieldlove-ad-serving.net
Source: global traffic DNS traffic detected: DNS query: lb.eu-1-id5-sync.com
Source: global traffic DNS traffic detected: DNS query: zipthisapp.com
Source: global traffic DNS traffic detected: DNS query: js.adscale.de
Source: global traffic DNS traffic detected: DNS query: ads.pubmatic.com
Source: global traffic DNS traffic detected: DNS query: js-sec.indexww.com
Source: global traffic DNS traffic detected: DNS query: eus.rubiconproject.com
Source: global traffic DNS traffic detected: DNS query: acdn.adnxs.com
Source: global traffic DNS traffic detected: DNS query: ssum-sec.casalemedia.com
Source: global traffic DNS traffic detected: DNS query: match.adsrvr.org
Source: global traffic DNS traffic detected: DNS query: dis.criteo.com
Source: global traffic DNS traffic detected: DNS query: www.zipthisapp.com
Source: global traffic DNS traffic detected: DNS query: ad.turn.com
Source: global traffic DNS traffic detected: DNS query: widget.us.criteo.com
Source: global traffic DNS traffic detected: DNS query: cm.g.doubleclick.net
Source: global traffic DNS traffic detected: DNS query: cs.lkqd.net
Source: global traffic DNS traffic detected: DNS query: dsum-sec.casalemedia.com
Source: global traffic DNS traffic detected: DNS query: image6.pubmatic.com
Source: global traffic DNS traffic detected: DNS query: rtb-csync.smartadserver.com
Source: global traffic DNS traffic detected: DNS query: a.nel.cloudflare.com
Source: global traffic DNS traffic detected: DNS query: thisdwn.com
Source: global traffic DNS traffic detected: DNS query: td.doubleclick.net
Source: global traffic DNS traffic detected: DNS query: 14918961.fls.doubleclick.net
Source: global traffic DNS traffic detected: DNS query: ad.doubleclick.net
Source: global traffic DNS traffic detected: DNS query: analytics.google.com
Source: global traffic DNS traffic detected: DNS query: bq.zipthisapp.com
Source: global traffic DNS traffic detected: DNS query: publickeyservice.aws.privacysandboxservices.com
Source: global traffic DNS traffic detected: DNS query: stats.g.doubleclick.net
Source: global traffic DNS traffic detected: DNS query: adservice.google.com
Source: global traffic DNS traffic detected: DNS query: apb.thisilient.com
Source: global traffic DNS traffic detected: DNS query: sts.thisilient.com
Source: global traffic DNS traffic detected: DNS query: cdnjs.cloudflare.com
Source: global traffic DNS traffic detected: DNS query: stackpath.bootstrapcdn.com
Source: global traffic DNS traffic detected: DNS query: code.jquery.com
Source: global traffic DNS traffic detected: DNS query: api-advertiser.linkvertise.com
Source: global traffic DNS traffic detected: DNS query: can.thisilient.com
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49744
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49986
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49743
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49985
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49984
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49740
Source: unknown Network traffic detected: HTTP traffic on port 49932 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49898 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49875 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49852 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49739
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49738
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49736
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49857
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49856
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49734
Source: unknown Network traffic detected: HTTP traffic on port 49772 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49855
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49733
Source: unknown Network traffic detected: HTTP traffic on port 49841 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49732
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49853
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49852
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49731
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49851
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49730
Source: unknown Network traffic detected: HTTP traffic on port 50039 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49970
Source: unknown Network traffic detected: HTTP traffic on port 49703 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49749 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50074 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49909 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49806 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49729
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49728
Source: unknown Network traffic detected: HTTP traffic on port 49714 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49727
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49969
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49847
Source: unknown Network traffic detected: HTTP traffic on port 49886 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49846
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49724
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49845
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49966
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49723
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49722
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49843
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49964
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49721
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49842
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49720
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49841
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49840
Source: unknown Network traffic detected: HTTP traffic on port 50015 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50040 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49966 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49989 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49748 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49760 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50073 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50028 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49718
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49839
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49717
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49838
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49959
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49837
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49716
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49958
Source: unknown Network traffic detected: HTTP traffic on port 49921 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49957
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49714
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49956
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49713
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49955
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49712
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49711
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49952
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49830
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49951
Source: unknown Network traffic detected: HTTP traffic on port 49839 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49950
Source: unknown Network traffic detected: HTTP traffic on port 49944 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49910 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49853 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49955 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49829
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49948
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49947
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49704
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49825
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49946
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49703
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49945
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49944
Source: unknown Network traffic detected: HTTP traffic on port 49771 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49822
Source: unknown Network traffic detected: HTTP traffic on port 49945 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49782
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49781
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49780
Source: unknown Network traffic detected: HTTP traffic on port 50049 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50026 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49807 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49713 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49736 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49759 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49779
Source: unknown Network traffic detected: HTTP traffic on port 49885 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49898
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49776
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49775
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49774
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49773
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49894
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49772
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49771
Source: unknown Network traffic detected: HTTP traffic on port 49724 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49957 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49851 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49830 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49769
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49768
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49767
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49766
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49886
Source: unknown Network traffic detected: HTTP traffic on port 49758 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49885
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49884
Source: unknown Network traffic detected: HTTP traffic on port 50038 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49762
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49883
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49881
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49760
Source: unknown Network traffic detected: HTTP traffic on port 49840 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50050 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50005 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49956 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49759
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49758
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49879
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49757
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49999
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49756
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49755
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49997
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49875
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49996
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49753
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49752
Source: unknown Network traffic detected: HTTP traffic on port 49923 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49751
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49872
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49750
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49992
Source: unknown Network traffic detected: HTTP traffic on port 49747 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49829 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50072 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49749
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49748
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49747
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49989
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49746
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49867
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49988
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49745
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49987
Source: unknown Network traffic detected: HTTP traffic on port 50013 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50036 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49746 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49769 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50071 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49699
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49698
Source: unknown Network traffic detected: HTTP traffic on port 49837 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49711 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49929 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49872 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50025 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49964 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49700 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49999 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49712 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49930 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49745 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49986 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49757 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49799
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50007
Source: unknown Network traffic detected: HTTP traffic on port 50037 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49734 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50006
Source: unknown Network traffic detected: HTTP traffic on port 50012 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50009
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50008
Source: unknown Network traffic detected: HTTP traffic on port 49952 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49794
Source: unknown Network traffic detected: HTTP traffic on port 49814 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49792
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50005
Source: unknown Network traffic detected: HTTP traffic on port 49768 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49723 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50048 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49825 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49884 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49907 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49941 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49789
Source: unknown Network traffic detected: HTTP traffic on port 49733 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49997 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49779 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49894 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49799 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49942 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49919 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50014 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50070 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49988 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49767 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49721 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50046 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49756 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49838 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49722 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49908 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50024 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49883 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49755 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49673 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50058 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49744 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49987 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49920 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50069 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50053
Source: unknown Network traffic detected: HTTP traffic on port 49800 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49789 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50056
Source: unknown Network traffic detected: HTTP traffic on port 49766 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50058
Source: unknown Network traffic detected: HTTP traffic on port 49743 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50057
Source: unknown Network traffic detected: HTTP traffic on port 49720 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49984 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50022 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50068 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49881 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49950 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49996 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49732 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50010 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50065
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50067
Source: unknown Network traffic detected: HTTP traffic on port 50056 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50066
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50069
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50068
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50070
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50072
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50071
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50074
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50073
Source: unknown Network traffic detected: HTTP traffic on port 49731 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50009 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50034 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50076
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50075
Source: unknown Network traffic detected: HTTP traffic on port 50057 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50078
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50079
Source: unknown Network traffic detected: HTTP traffic on port 49847 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49822 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50079 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49938 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49699 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50019
Source: unknown Network traffic detected: HTTP traffic on port 49951 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50032 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50010
Source: unknown Network traffic detected: HTTP traffic on port 49916 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50012
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50011
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50014
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50013
Source: unknown Network traffic detected: HTTP traffic on port 50078 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50015
Source: unknown Network traffic detected: HTTP traffic on port 49939 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49776 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49845 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49753 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50029
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50028
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50021
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50020
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50022
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50025
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50024
Source: unknown Network traffic detected: HTTP traffic on port 49780 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49879 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50026
Source: unknown Network traffic detected: HTTP traffic on port 49985 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50021 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50030
Source: unknown Network traffic detected: HTTP traffic on port 50067 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49718 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50039
Source: unknown Network traffic detected: HTTP traffic on port 50011 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49928 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50032
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50031
Source: unknown Network traffic detected: HTTP traffic on port 49857 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50034
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50033
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50036
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50038
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50037
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50041
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50040
Source: unknown Network traffic detected: HTTP traffic on port 50066 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49698 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49730 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50033 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50043
Source: unknown Network traffic detected: HTTP traffic on port 49917 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50042
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50046
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50049
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50048
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 50050
Source: unknown Network traffic detected: HTTP traffic on port 49775 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49846 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49792 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49970 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50042 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50007 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49781 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49958 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49717 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49946 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49728 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49855 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50053 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49752 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49901 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49947 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49729 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50076 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50031 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49751 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49992 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50043 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49774 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49782 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49969 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50020 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49740 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49856 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50006 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50065 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49867 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49942
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49821
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49700
Source: unknown Network traffic detected: HTTP traffic on port 49842 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49941
Source: unknown Network traffic detected: HTTP traffic on port 49727 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49704 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49762 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50075 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49939
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49938
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49937
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49936
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49814
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49932
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49930
Source: unknown Network traffic detected: HTTP traffic on port 50008 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49794 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49936 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49809
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49929
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49807
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49928
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49806
Source: unknown Network traffic detected: HTTP traffic on port 50029 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49773 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49923
Source: unknown Network traffic detected: HTTP traffic on port 49739 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49800
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49921
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49920
Source: unknown Network traffic detected: HTTP traffic on port 49678 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49821 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50019 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49914 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49919
Source: unknown Network traffic detected: HTTP traffic on port 49937 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49917
Source: unknown Network traffic detected: HTTP traffic on port 49809 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49916
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49914
Source: unknown Network traffic detected: HTTP traffic on port 49738 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49910
Source: unknown Network traffic detected: HTTP traffic on port 49948 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 50041 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49843 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49959 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49909
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49908
Source: unknown Network traffic detected: HTTP traffic on port 50030 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49907
Source: unknown Network traffic detected: HTTP traffic on port 49750 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49716 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49901
Source: unknown HTTPS traffic detected: 23.218.208.109:443 -> 192.168.2.16:49731 version: TLS 1.2
Source: unknown HTTPS traffic detected: 23.218.208.109:443 -> 192.168.2.16:49746 version: TLS 1.2
Source: unknown HTTPS traffic detected: 4.175.87.197:443 -> 192.168.2.16:49749 version: TLS 1.2
Source: unknown HTTPS traffic detected: 4.175.87.197:443 -> 192.168.2.16:50019 version: TLS 1.2
Source: unknown HTTPS traffic detected: 45.33.84.9:443 -> 192.168.2.16:50026 version: TLS 1.2
Source: unknown HTTPS traffic detected: 45.33.84.9:443 -> 192.168.2.16:50031 version: TLS 1.2
Source: unknown HTTPS traffic detected: 45.33.84.9:443 -> 192.168.2.16:50068 version: TLS 1.2
Source: unknown HTTPS traffic detected: 45.33.84.9:443 -> 192.168.2.16:50067 version: TLS 1.2
Source: unknown HTTPS traffic detected: 45.33.84.9:443 -> 192.168.2.16:50078 version: TLS 1.2
Source: C:\Windows\System32\svchost.exe File created: C:\Windows\ServiceProfiles\LocalService\AppData\Local\FontCache\Fonts\Download-1.tmp
Source: classification engine Classification label: mal60.expl.win@47/146@202/700
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Mutant created: NULL
Source: C:\Windows\System32\conhost.exe Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:2300:120:WilError_03
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe File created: C:\Users\user\AppData\Local\Temp\__PSScriptPolicyTest_dodz4s2u.xd1.ps1
Source: C:\Users\user\Downloads\ZipThis.exe File read: C:\Users\desktop.ini
Source: C:\Users\user\Downloads\ZipThis.exe Key opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers
Source: unknown Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2036 --field-trial-handle=1936,i,13899727471157137110,2103944552154813019,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknown Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://www.kalenderpedia.de"
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2036 --field-trial-handle=1936,i,13899727471157137110,2103944552154813019,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=chrome.mojom.UtilReadIcon --lang=en-US --service-sandbox-type=icon_reader --mojo-platform-channel-handle=5988 --field-trial-handle=1936,i,13899727471157137110,2103944552154813019,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=chrome.mojom.UtilReadIcon --lang=en-US --service-sandbox-type=icon_reader --mojo-platform-channel-handle=5988 --field-trial-handle=1936,i,13899727471157137110,2103944552154813019,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Users\user\Downloads\ZipThis.exe "C:\Users\user\Downloads\ZipThis.exe"
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: C:\Users\user\Downloads\ZipThis.exe "C:\Users\user\Downloads\ZipThis.exe"
Source: C:\Users\user\Downloads\ZipThis.exe Process created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe "powershell.exe" -ep RemoteSigned -File "C:\Users\user\AppData\Local\ZipThis\update_task_ad.ps1"
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: unknown Process created: C:\Windows\System32\svchost.exe C:\Windows\System32\svchost.exe -k netsvcs -p -s BITS
Source: C:\Users\user\Downloads\ZipThis.exe Process created: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe "C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe"
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Users\user\Downloads\ZipThis.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" https://www.zipthisapp.com/success?u=c14bc5b0-c4ea-49fa-aae2-e47c61b59c5b
Source: C:\Users\user\Downloads\ZipThis.exe Process created: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe "C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe"
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process created: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe "C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe"
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process created: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe "C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe"
Source: C:\Program Files\Google\Chrome\Application\chrome.exe Process created: unknown unknown
Source: C:\Users\user\Downloads\ZipThis.exe Section loaded: mscoree.dll
Source: C:\Users\user\Downloads\ZipThis.exe Section loaded: kernel.appcore.dll
Source: C:\Users\user\Downloads\ZipThis.exe Section loaded: version.dll
Source: C:\Users\user\Downloads\ZipThis.exe Section loaded: vcruntime140_clr0400.dll
Source: C:\Users\user\Downloads\ZipThis.exe Section loaded: ucrtbase_clr0400.dll
Source: C:\Users\user\Downloads\ZipThis.exe Section loaded: ucrtbase_clr0400.dll
Source: C:\Users\user\Downloads\ZipThis.exe Section loaded: uxtheme.dll
Source: C:\Users\user\Downloads\ZipThis.exe Section loaded: cryptsp.dll
Source: C:\Users\user\Downloads\ZipThis.exe Section loaded: rsaenh.dll
Source: C:\Users\user\Downloads\ZipThis.exe Section loaded: cryptbase.dll
Source: C:\Users\user\Downloads\ZipThis.exe Section loaded: dwrite.dll
Source: C:\Users\user\Downloads\ZipThis.exe Section loaded: msvcp140_clr0400.dll
Source: C:\Users\user\Downloads\ZipThis.exe Section loaded: windows.storage.dll
Source: C:\Users\user\Downloads\ZipThis.exe Section loaded: wldp.dll
Source: C:\Users\user\Downloads\ZipThis.exe Section loaded: profapi.dll
Source: C:\Users\user\Downloads\ZipThis.exe Section loaded: dwmapi.dll
Source: C:\Users\user\Downloads\ZipThis.exe Section loaded: d3d9.dll
Source: C:\Users\user\Downloads\ZipThis.exe Section loaded: d3d10warp.dll
Source: C:\Users\user\Downloads\ZipThis.exe Section loaded: urlmon.dll
Source: C:\Users\user\Downloads\ZipThis.exe Section loaded: iertutil.dll
Source: C:\Users\user\Downloads\ZipThis.exe Section loaded: srvcli.dll
Source: C:\Users\user\Downloads\ZipThis.exe Section loaded: netutils.dll
Source: C:\Users\user\Downloads\ZipThis.exe Section loaded: windowscodecs.dll
Source: C:\Users\user\Downloads\ZipThis.exe Section loaded: wtsapi32.dll
Source: C:\Users\user\Downloads\ZipThis.exe Section loaded: winsta.dll
Source: C:\Users\user\Downloads\ZipThis.exe Section loaded: powrprof.dll
Source: C:\Users\user\Downloads\ZipThis.exe Section loaded: umpdc.dll
Source: C:\Users\user\Downloads\ZipThis.exe Section loaded: textshaping.dll
Source: C:\Users\user\Downloads\ZipThis.exe Section loaded: dataexchange.dll
Source: C:\Users\user\Downloads\ZipThis.exe Section loaded: d3d11.dll
Source: C:\Users\user\Downloads\ZipThis.exe Section loaded: dcomp.dll
Source: C:\Users\user\Downloads\ZipThis.exe Section loaded: dxgi.dll
Source: C:\Users\user\Downloads\ZipThis.exe Section loaded: twinapi.appcore.dll
Source: C:\Users\user\Downloads\ZipThis.exe Section loaded: resourcepolicyclient.dll
Source: C:\Users\user\Downloads\ZipThis.exe Section loaded: dxcore.dll
Source: C:\Users\user\Downloads\ZipThis.exe Section loaded: textinputframework.dll
Source: C:\Users\user\Downloads\ZipThis.exe Section loaded: coreuicomponents.dll
Source: C:\Users\user\Downloads\ZipThis.exe Section loaded: coremessaging.dll
Source: C:\Users\user\Downloads\ZipThis.exe Section loaded: ntmarta.dll
Source: C:\Users\user\Downloads\ZipThis.exe Section loaded: wintypes.dll
Source: C:\Users\user\Downloads\ZipThis.exe Section loaded: wintypes.dll
Source: C:\Users\user\Downloads\ZipThis.exe Section loaded: wintypes.dll
Source: C:\Users\user\Downloads\ZipThis.exe Section loaded: msctfui.dll
Source: C:\Users\user\Downloads\ZipThis.exe Section loaded: uiautomationcore.dll
Source: C:\Users\user\Downloads\ZipThis.exe Section loaded: propsys.dll
Source: C:\Users\user\Downloads\ZipThis.exe Section loaded: d3dcompiler_47.dll
Source: C:\Users\user\Downloads\ZipThis.exe Section loaded: iphlpapi.dll
Source: C:\Users\user\Downloads\ZipThis.exe Section loaded: dnsapi.dll
Source: C:\Users\user\Downloads\ZipThis.exe Section loaded: dhcpcsvc6.dll
Source: C:\Users\user\Downloads\ZipThis.exe Section loaded: dhcpcsvc.dll
Source: C:\Users\user\Downloads\ZipThis.exe Section loaded: winnsi.dll
Source: C:\Users\user\Downloads\ZipThis.exe Section loaded: rasapi32.dll
Source: C:\Users\user\Downloads\ZipThis.exe Section loaded: rasman.dll
Source: C:\Users\user\Downloads\ZipThis.exe Section loaded: rtutils.dll
Source: C:\Users\user\Downloads\ZipThis.exe Section loaded: mswsock.dll
Source: C:\Users\user\Downloads\ZipThis.exe Section loaded: winhttp.dll
Source: C:\Users\user\Downloads\ZipThis.exe Section loaded: ondemandconnroutehelper.dll
Source: C:\Users\user\Downloads\ZipThis.exe Section loaded: rasadhlp.dll
Source: C:\Users\user\Downloads\ZipThis.exe Section loaded: fwpuclnt.dll
Source: C:\Users\user\Downloads\ZipThis.exe Section loaded: secur32.dll
Source: C:\Users\user\Downloads\ZipThis.exe Section loaded: sspicli.dll
Source: C:\Users\user\Downloads\ZipThis.exe Section loaded: schannel.dll
Source: C:\Users\user\Downloads\ZipThis.exe Section loaded: mskeyprotect.dll
Source: C:\Users\user\Downloads\ZipThis.exe Section loaded: ntasn1.dll
Source: C:\Users\user\Downloads\ZipThis.exe Section loaded: ncrypt.dll
Source: C:\Users\user\Downloads\ZipThis.exe Section loaded: ncryptsslp.dll
Source: C:\Users\user\Downloads\ZipThis.exe Section loaded: msasn1.dll
Source: C:\Users\user\Downloads\ZipThis.exe Section loaded: gpapi.dll
Source: C:\Users\user\Downloads\ZipThis.exe Section loaded: userenv.dll
Source: C:\Windows\System32\svchost.exe Section loaded: kernel.appcore.dll
Source: C:\Windows\System32\svchost.exe Section loaded: qmgr.dll
Source: C:\Windows\System32\svchost.exe Section loaded: bitsperf.dll
Source: C:\Windows\System32\svchost.exe Section loaded: powrprof.dll
Source: C:\Windows\System32\svchost.exe Section loaded: xmllite.dll
Source: C:\Windows\System32\svchost.exe Section loaded: firewallapi.dll
Source: C:\Windows\System32\svchost.exe Section loaded: esent.dll
Source: C:\Windows\System32\svchost.exe Section loaded: umpdc.dll
Source: C:\Windows\System32\svchost.exe Section loaded: dnsapi.dll
Source: C:\Windows\System32\svchost.exe Section loaded: iphlpapi.dll
Source: C:\Windows\System32\svchost.exe Section loaded: fwbase.dll
Source: C:\Windows\System32\svchost.exe Section loaded: wldp.dll
Source: C:\Windows\System32\svchost.exe Section loaded: ntmarta.dll
Source: C:\Windows\System32\svchost.exe Section loaded: profapi.dll
Source: C:\Windows\System32\svchost.exe Section loaded: flightsettings.dll
Source: C:\Windows\System32\svchost.exe Section loaded: policymanager.dll
Source: C:\Windows\System32\svchost.exe Section loaded: msvcp110_win.dll
Source: C:\Windows\System32\svchost.exe Section loaded: netprofm.dll
Source: C:\Windows\System32\svchost.exe Section loaded: npmproxy.dll
Source: C:\Windows\System32\svchost.exe Section loaded: bitsigd.dll
Source: C:\Windows\System32\svchost.exe Section loaded: upnp.dll
Source: C:\Windows\System32\svchost.exe Section loaded: winhttp.dll
Source: C:\Windows\System32\svchost.exe Section loaded: ssdpapi.dll
Source: C:\Windows\System32\svchost.exe Section loaded: urlmon.dll
Source: C:\Windows\System32\svchost.exe Section loaded: iertutil.dll
Source: C:\Windows\System32\svchost.exe Section loaded: srvcli.dll
Source: C:\Windows\System32\svchost.exe Section loaded: netutils.dll
Source: C:\Windows\System32\svchost.exe Section loaded: appxdeploymentclient.dll
Source: C:\Windows\System32\svchost.exe Section loaded: cryptbase.dll
Source: C:\Windows\System32\svchost.exe Section loaded: wsmauto.dll
Source: C:\Windows\System32\svchost.exe Section loaded: miutils.dll
Source: C:\Windows\System32\svchost.exe Section loaded: wsmsvc.dll
Source: C:\Windows\System32\svchost.exe Section loaded: dsrole.dll
Source: C:\Windows\System32\svchost.exe Section loaded: pcwum.dll
Source: C:\Windows\System32\svchost.exe Section loaded: mi.dll
Source: C:\Windows\System32\svchost.exe Section loaded: userenv.dll
Source: C:\Windows\System32\svchost.exe Section loaded: gpapi.dll
Source: C:\Windows\System32\svchost.exe Section loaded: winhttp.dll
Source: C:\Windows\System32\svchost.exe Section loaded: wkscli.dll
Source: C:\Windows\System32\svchost.exe Section loaded: netutils.dll
Source: C:\Windows\System32\svchost.exe Section loaded: sspicli.dll
Source: C:\Windows\System32\svchost.exe Section loaded: ondemandconnroutehelper.dll
Source: C:\Windows\System32\svchost.exe Section loaded: msv1_0.dll
Source: C:\Windows\System32\svchost.exe Section loaded: ntlmshared.dll
Source: C:\Windows\System32\svchost.exe Section loaded: cryptdll.dll
Source: C:\Windows\System32\svchost.exe Section loaded: webio.dll
Source: C:\Windows\System32\svchost.exe Section loaded: mswsock.dll
Source: C:\Windows\System32\svchost.exe Section loaded: winnsi.dll
Source: C:\Windows\System32\svchost.exe Section loaded: rasadhlp.dll
Source: C:\Windows\System32\svchost.exe Section loaded: fwpuclnt.dll
Source: C:\Windows\System32\svchost.exe Section loaded: rmclient.dll
Source: C:\Windows\System32\svchost.exe Section loaded: usermgrcli.dll
Source: C:\Windows\System32\svchost.exe Section loaded: execmodelclient.dll
Source: C:\Windows\System32\svchost.exe Section loaded: propsys.dll
Source: C:\Windows\System32\svchost.exe Section loaded: coremessaging.dll
Source: C:\Windows\System32\svchost.exe Section loaded: twinapi.appcore.dll
Source: C:\Windows\System32\svchost.exe Section loaded: onecorecommonproxystub.dll
Source: C:\Windows\System32\svchost.exe Section loaded: execmodelproxy.dll
Source: C:\Windows\System32\svchost.exe Section loaded: resourcepolicyclient.dll
Source: C:\Windows\System32\svchost.exe Section loaded: vssapi.dll
Source: C:\Windows\System32\svchost.exe Section loaded: vsstrace.dll
Source: C:\Windows\System32\svchost.exe Section loaded: samcli.dll
Source: C:\Windows\System32\svchost.exe Section loaded: samlib.dll
Source: C:\Windows\System32\svchost.exe Section loaded: es.dll
Source: C:\Windows\System32\svchost.exe Section loaded: bitsproxy.dll
Source: C:\Windows\System32\svchost.exe Section loaded: ondemandconnroutehelper.dll
Source: C:\Windows\System32\svchost.exe Section loaded: dhcpcsvc6.dll
Source: C:\Windows\System32\svchost.exe Section loaded: dhcpcsvc.dll
Source: C:\Windows\System32\svchost.exe Section loaded: schannel.dll
Source: C:\Windows\System32\svchost.exe Section loaded: mskeyprotect.dll
Source: C:\Windows\System32\svchost.exe Section loaded: ntasn1.dll
Source: C:\Windows\System32\svchost.exe Section loaded: ncrypt.dll
Source: C:\Windows\System32\svchost.exe Section loaded: ncryptsslp.dll
Source: C:\Windows\System32\svchost.exe Section loaded: msasn1.dll
Source: C:\Windows\System32\svchost.exe Section loaded: cryptsp.dll
Source: C:\Windows\System32\svchost.exe Section loaded: rsaenh.dll
Source: C:\Windows\System32\svchost.exe Section loaded: dpapi.dll
Source: C:\Windows\System32\svchost.exe Section loaded: mpr.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: atl.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: mscoree.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: kernel.appcore.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: version.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: vcruntime140_clr0400.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: ucrtbase_clr0400.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: ucrtbase_clr0400.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: cryptsp.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: rsaenh.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: cryptbase.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: amsi.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: userenv.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: profapi.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: windows.storage.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: wldp.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: msasn1.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: gpapi.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: msisip.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: wshext.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: appxsip.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: opcservices.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: secur32.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: sspicli.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: uxtheme.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: urlmon.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: iertutil.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: srvcli.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: netutils.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: propsys.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: wininet.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: kdscli.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: ntasn1.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: microsoft.management.infrastructure.native.unmanaged.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: mi.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: miutils.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: wmidcom.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: dpapi.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: wbemcomn.dll
Source: C:\Users\user\Downloads\ZipThis.exe Section loaded: sxs.dll
Source: C:\Users\user\Downloads\ZipThis.exe Section loaded: mpr.dll
Source: C:\Users\user\Downloads\ZipThis.exe Section loaded: scrrun.dll
Source: C:\Users\user\Downloads\ZipThis.exe Section loaded: linkinfo.dll
Source: C:\Users\user\Downloads\ZipThis.exe Section loaded: ntshrui.dll
Source: C:\Users\user\Downloads\ZipThis.exe Section loaded: cscapi.dll
Source: C:\Users\user\Downloads\ZipThis.exe Section loaded: edputil.dll
Source: C:\Users\user\Downloads\ZipThis.exe Section loaded: windows.staterepositoryps.dll
Source: C:\Users\user\Downloads\ZipThis.exe Section loaded: appresolver.dll
Source: C:\Users\user\Downloads\ZipThis.exe Section loaded: bcp47langs.dll
Source: C:\Users\user\Downloads\ZipThis.exe Section loaded: slc.dll
Source: C:\Users\user\Downloads\ZipThis.exe Section loaded: sppc.dll
Source: C:\Users\user\Downloads\ZipThis.exe Section loaded: onecorecommonproxystub.dll
Source: C:\Users\user\Downloads\ZipThis.exe Section loaded: onecoreuapcommonproxystub.dll
Source: C:\Users\user\Downloads\ZipThis.exe Section loaded: apphelp.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: mscoree.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: kernel.appcore.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: version.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: vcruntime140_clr0400.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: ucrtbase_clr0400.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: uxtheme.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: cryptsp.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: rsaenh.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: cryptbase.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: dwrite.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: msvcp140_clr0400.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: windows.storage.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: wldp.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: profapi.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: userenv.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: iphlpapi.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: dnsapi.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: dhcpcsvc6.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: dhcpcsvc.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: winnsi.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: rasapi32.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: rasman.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: rtutils.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: mswsock.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: winhttp.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: ondemandconnroutehelper.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: rasadhlp.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: fwpuclnt.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: secur32.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: sspicli.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: schannel.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: mskeyprotect.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: ntasn1.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: ncrypt.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: ncryptsslp.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: msasn1.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: gpapi.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: dwmapi.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: d3d9.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: d3d10warp.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: urlmon.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: iertutil.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: srvcli.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: netutils.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: windowscodecs.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: wtsapi32.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: winsta.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: powrprof.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: umpdc.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: dataexchange.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: d3d11.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: dcomp.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: dxgi.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: twinapi.appcore.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: resourcepolicyclient.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: dxcore.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: textshaping.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: textinputframework.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: coreuicomponents.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: coremessaging.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: ntmarta.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: wintypes.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: wintypes.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: wintypes.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: msctfui.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: uiautomationcore.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: propsys.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: d3dcompiler_47.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: dui70.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: duser.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: edputil.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: explorerframe.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: thumbcache.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: msftedit.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: windows.globalization.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: bcp47langs.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: bcp47mrm.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: globinputhost.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: assignedaccessruntime.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: xmllite.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: windows.fileexplorer.common.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: linkinfo.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: structuredquery.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: atlthunk.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: windows.storage.search.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: twinapi.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: ntshrui.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: cscapi.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: windows.staterepositoryps.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: winmm.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: actxprxy.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: apphelp.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: networkexplorer.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: ehstorshell.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: cscui.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: policymanager.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: msvcp110_win.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: mrmcorer.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: windows.staterepositorycore.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: appxdeploymentclient.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: windows.ui.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: windowmanagementapi.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: inputhost.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: appxdeploymentclient.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: appxdeploymentclient.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: appxdeploymentclient.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: wkscli.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: provsvc.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: onecoreuapcommonproxystub.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: appresolver.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: slc.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: sppc.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: onecorecommonproxystub.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: mscoree.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: kernel.appcore.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: version.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: vcruntime140_clr0400.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: ucrtbase_clr0400.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: ucrtbase_clr0400.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: uxtheme.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: cryptsp.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: rsaenh.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: cryptbase.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: dwrite.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: msvcp140_clr0400.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: windows.storage.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: wldp.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: profapi.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: userenv.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: iphlpapi.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: dnsapi.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: dhcpcsvc6.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: dhcpcsvc.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: winnsi.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: rasapi32.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: rasman.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: rtutils.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: mswsock.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: winhttp.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: ondemandconnroutehelper.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: rasadhlp.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: fwpuclnt.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: secur32.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: sspicli.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: schannel.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: mskeyprotect.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: ntasn1.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: ncrypt.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: ncryptsslp.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: msasn1.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: gpapi.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: dwmapi.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: d3d9.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: d3d10warp.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: urlmon.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: iertutil.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: srvcli.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: netutils.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: windowscodecs.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: wtsapi32.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: winsta.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: powrprof.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: umpdc.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: dataexchange.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: d3d11.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: dcomp.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: dxgi.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: twinapi.appcore.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: resourcepolicyclient.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: dxcore.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: textshaping.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: textinputframework.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: coreuicomponents.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: coremessaging.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: ntmarta.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: wintypes.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: wintypes.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: wintypes.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: msctfui.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: uiautomationcore.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: propsys.dll
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Section loaded: d3dcompiler_47.dll
Source: C:\Users\user\Downloads\ZipThis.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\InprocServer32
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe File opened: C:\Windows\SYSTEM32\MsftEdit.dll
Source: Window Recorder Window detected: More than 3 window changes detected
Source: C:\Users\user\Downloads\ZipThis.exe File opened: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorrc.dll
Source: C:\Users\user\Downloads\ZipThis.exe Registry value created: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ZipThis
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\Downloads\Unconfirmed 701831.crdownload Jump to dropped file
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\Downloads\0cd46de4-83f4-42f0-9a2c-ff3279c6ebd2.tmp Jump to dropped file
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
Source: C:\Program Files\Google\Chrome\Application\chrome.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk

Hooking and other Techniques for Hiding and Protection

barindex
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe File opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\BitLocker.psd1
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe File opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\BitLocker.psd1
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe File opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\BitLocker.psd1
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe File opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\en-US\BitLocker.psd1
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe File opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\en-US\BitLocker.psd1
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe File opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\BitLocker.psd1
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe File opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\en-US\BitLocker.psd1
Source: C:\Users\user\Downloads\ZipThis.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Downloads\ZipThis.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Downloads\ZipThis.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Downloads\ZipThis.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Downloads\ZipThis.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Downloads\ZipThis.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Downloads\ZipThis.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Downloads\ZipThis.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Downloads\ZipThis.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Downloads\ZipThis.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Downloads\ZipThis.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Downloads\ZipThis.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Downloads\ZipThis.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Downloads\ZipThis.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Downloads\ZipThis.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Downloads\ZipThis.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Downloads\ZipThis.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Downloads\ZipThis.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Downloads\ZipThis.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Downloads\ZipThis.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Downloads\ZipThis.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Downloads\ZipThis.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Downloads\ZipThis.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Downloads\ZipThis.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Downloads\ZipThis.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Downloads\ZipThis.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Downloads\ZipThis.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Downloads\ZipThis.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Downloads\ZipThis.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Downloads\ZipThis.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Downloads\ZipThis.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Downloads\ZipThis.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Downloads\ZipThis.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Downloads\ZipThis.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Downloads\ZipThis.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Downloads\ZipThis.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Downloads\ZipThis.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Downloads\ZipThis.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Downloads\ZipThis.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Downloads\ZipThis.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Downloads\ZipThis.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Downloads\ZipThis.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Downloads\ZipThis.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Downloads\ZipThis.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Downloads\ZipThis.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Downloads\ZipThis.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Downloads\ZipThis.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Downloads\ZipThis.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Downloads\ZipThis.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Downloads\ZipThis.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Downloads\ZipThis.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Downloads\ZipThis.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Downloads\ZipThis.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Downloads\ZipThis.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Downloads\ZipThis.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Downloads\ZipThis.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Downloads\ZipThis.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Downloads\ZipThis.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Downloads\ZipThis.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Downloads\ZipThis.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Downloads\ZipThis.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Downloads\ZipThis.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Downloads\ZipThis.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Downloads\ZipThis.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Downloads\ZipThis.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Downloads\ZipThis.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Downloads\ZipThis.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Downloads\ZipThis.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Downloads\ZipThis.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Downloads\ZipThis.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Downloads\ZipThis.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Downloads\ZipThis.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Downloads\ZipThis.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Downloads\ZipThis.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Downloads\ZipThis.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Downloads\ZipThis.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Downloads\ZipThis.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Downloads\ZipThis.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Downloads\ZipThis.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Downloads\ZipThis.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Downloads\ZipThis.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Downloads\ZipThis.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Downloads\ZipThis.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Downloads\ZipThis.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Downloads\ZipThis.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Downloads\ZipThis.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Downloads\ZipThis.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Downloads\ZipThis.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Downloads\ZipThis.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Downloads\ZipThis.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Downloads\ZipThis.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Downloads\ZipThis.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Downloads\ZipThis.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Downloads\ZipThis.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Downloads\ZipThis.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Downloads\ZipThis.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Downloads\ZipThis.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Downloads\ZipThis.exe Memory allocated: 26EEF130000 memory reserve | memory write watch
Source: C:\Users\user\Downloads\ZipThis.exe Memory allocated: 26EEF1E0000 memory reserve | memory write watch
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Memory allocated: 1F051ED0000 memory reserve | memory write watch
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Memory allocated: 1F06B9A0000 memory reserve | memory write watch
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Memory allocated: 1C0BD520000 memory reserve | memory write watch
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Memory allocated: 1C0D7030000 memory reserve | memory write watch
Source: C:\Users\user\Downloads\ZipThis.exe Thread delayed: delay time: 922337203685477
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Thread delayed: delay time: 922337203685477
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Thread delayed: delay time: 922337203685477
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Thread delayed: delay time: 922337203685477
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Thread delayed: delay time: 922337203685477
Source: C:\Users\user\Downloads\ZipThis.exe Window / User API: threadDelayed 9800
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Window / User API: threadDelayed 8653
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Window / User API: threadDelayed 1243
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Window / User API: threadDelayed 3254
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Window / User API: threadDelayed 461
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Window / User API: threadDelayed 9596
Source: C:\Users\user\Downloads\ZipThis.exe TID: 4368 Thread sleep time: -4611686018427385s >= -30000s
Source: C:\Users\user\Downloads\ZipThis.exe TID: 4368 Thread sleep time: -100000s >= -30000s
Source: C:\Users\user\Downloads\ZipThis.exe TID: 2624 Thread sleep count: 9800 > 30
Source: C:\Users\user\Downloads\ZipThis.exe TID: 2624 Thread sleep count: 79 > 30
Source: C:\Users\user\Downloads\ZipThis.exe TID: 4368 Thread sleep time: -99872s >= -30000s
Source: C:\Users\user\Downloads\ZipThis.exe TID: 4368 Thread sleep time: -99761s >= -30000s
Source: C:\Users\user\Downloads\ZipThis.exe TID: 4368 Thread sleep time: -99649s >= -30000s
Source: C:\Users\user\Downloads\ZipThis.exe TID: 4368 Thread sleep time: -99537s >= -30000s
Source: C:\Users\user\Downloads\ZipThis.exe TID: 4368 Thread sleep time: -99410s >= -30000s
Source: C:\Users\user\Downloads\ZipThis.exe TID: 4368 Thread sleep time: -99282s >= -30000s
Source: C:\Users\user\Downloads\ZipThis.exe TID: 4368 Thread sleep time: -99155s >= -30000s
Source: C:\Users\user\Downloads\ZipThis.exe TID: 4368 Thread sleep time: -99043s >= -30000s
Source: C:\Users\user\Downloads\ZipThis.exe TID: 4368 Thread sleep time: -98931s >= -30000s
Source: C:\Users\user\Downloads\ZipThis.exe TID: 4368 Thread sleep time: -98820s >= -30000s
Source: C:\Users\user\Downloads\ZipThis.exe TID: 4368 Thread sleep time: -98712s >= -30000s
Source: C:\Users\user\Downloads\ZipThis.exe TID: 4368 Thread sleep time: -98600s >= -30000s
Source: C:\Users\user\Downloads\ZipThis.exe TID: 4368 Thread sleep time: -98489s >= -30000s
Source: C:\Users\user\Downloads\ZipThis.exe TID: 4368 Thread sleep time: -98361s >= -30000s
Source: C:\Users\user\Downloads\ZipThis.exe TID: 4368 Thread sleep time: -98235s >= -30000s
Source: C:\Users\user\Downloads\ZipThis.exe TID: 4368 Thread sleep time: -98123s >= -30000s
Source: C:\Users\user\Downloads\ZipThis.exe TID: 4368 Thread sleep time: -98011s >= -30000s
Source: C:\Users\user\Downloads\ZipThis.exe TID: 4368 Thread sleep time: -97900s >= -30000s
Source: C:\Users\user\Downloads\ZipThis.exe TID: 4368 Thread sleep time: -97788s >= -30000s
Source: C:\Users\user\Downloads\ZipThis.exe TID: 4368 Thread sleep time: -97676s >= -30000s
Source: C:\Users\user\Downloads\ZipThis.exe TID: 4368 Thread sleep time: -97548s >= -30000s
Source: C:\Users\user\Downloads\ZipThis.exe TID: 4368 Thread sleep time: -97420s >= -30000s
Source: C:\Users\user\Downloads\ZipThis.exe TID: 4368 Thread sleep time: -97310s >= -30000s
Source: C:\Users\user\Downloads\ZipThis.exe TID: 4368 Thread sleep time: -97200s >= -30000s
Source: C:\Users\user\Downloads\ZipThis.exe TID: 4368 Thread sleep time: -97089s >= -30000s
Source: C:\Windows\System32\svchost.exe TID: 552 Thread sleep time: -30000s >= -30000s
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 2940 Thread sleep count: 8653 > 30
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 2940 Thread sleep count: 1243 > 30
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 4580 Thread sleep time: -4611686018427385s >= -30000s
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe TID: 1948 Thread sleep time: -6456360425798339s >= -30000s
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe TID: 2332 Thread sleep count: 3254 > 30
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe TID: 2332 Thread sleep count: 215 > 30
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe TID: 2332 Thread sleep count: 461 > 30
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe TID: 1948 Thread sleep time: -15679732462653109s >= -30000s
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe TID: 5208 Thread sleep time: -6456360425798339s >= -30000s
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe TID: 2720 Thread sleep count: 9596 > 30
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe TID: 2720 Thread sleep count: 229 > 30
Source: C:\Windows\System32\svchost.exe File opened: PhysicalDrive0
Source: C:\Users\user\Downloads\ZipThis.exe Thread delayed: delay time: 922337203685477
Source: C:\Users\user\Downloads\ZipThis.exe Thread delayed: delay time: 100000
Source: C:\Users\user\Downloads\ZipThis.exe Thread delayed: delay time: 99872
Source: C:\Users\user\Downloads\ZipThis.exe Thread delayed: delay time: 99761
Source: C:\Users\user\Downloads\ZipThis.exe Thread delayed: delay time: 99649
Source: C:\Users\user\Downloads\ZipThis.exe Thread delayed: delay time: 99537
Source: C:\Users\user\Downloads\ZipThis.exe Thread delayed: delay time: 99410
Source: C:\Users\user\Downloads\ZipThis.exe Thread delayed: delay time: 99282
Source: C:\Users\user\Downloads\ZipThis.exe Thread delayed: delay time: 99155
Source: C:\Users\user\Downloads\ZipThis.exe Thread delayed: delay time: 99043
Source: C:\Users\user\Downloads\ZipThis.exe Thread delayed: delay time: 98931
Source: C:\Users\user\Downloads\ZipThis.exe Thread delayed: delay time: 98820
Source: C:\Users\user\Downloads\ZipThis.exe Thread delayed: delay time: 98712
Source: C:\Users\user\Downloads\ZipThis.exe Thread delayed: delay time: 98600
Source: C:\Users\user\Downloads\ZipThis.exe Thread delayed: delay time: 98489
Source: C:\Users\user\Downloads\ZipThis.exe Thread delayed: delay time: 98361
Source: C:\Users\user\Downloads\ZipThis.exe Thread delayed: delay time: 98235
Source: C:\Users\user\Downloads\ZipThis.exe Thread delayed: delay time: 98123
Source: C:\Users\user\Downloads\ZipThis.exe Thread delayed: delay time: 98011
Source: C:\Users\user\Downloads\ZipThis.exe Thread delayed: delay time: 97900
Source: C:\Users\user\Downloads\ZipThis.exe Thread delayed: delay time: 97788
Source: C:\Users\user\Downloads\ZipThis.exe Thread delayed: delay time: 97676
Source: C:\Users\user\Downloads\ZipThis.exe Thread delayed: delay time: 97548
Source: C:\Users\user\Downloads\ZipThis.exe Thread delayed: delay time: 97420
Source: C:\Users\user\Downloads\ZipThis.exe Thread delayed: delay time: 97310
Source: C:\Users\user\Downloads\ZipThis.exe Thread delayed: delay time: 97200
Source: C:\Users\user\Downloads\ZipThis.exe Thread delayed: delay time: 97089
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Thread delayed: delay time: 922337203685477
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Thread delayed: delay time: 922337203685477
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Thread delayed: delay time: 922337203685477
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Thread delayed: delay time: 922337203685477
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe File opened: C:\Users\user
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe File opened: C:\Users\user\AppData\Roaming
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe File opened: C:\Users\user\AppData\Roaming\Microsoft\Windows
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe File opened: C:\Users\user\AppData\Roaming\Microsoft\Windows\Libraries\desktop.ini
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe File opened: C:\Users\user\AppData\Roaming\Microsoft
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe File opened: C:\Users\user\AppData
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information queried: ProcessInformation
Source: C:\Users\user\Downloads\ZipThis.exe Process token adjusted: Debug
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process token adjusted: Debug
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process token adjusted: Debug
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process token adjusted: Debug
Source: C:\Users\user\Downloads\ZipThis.exe Memory allocated: page read and write | page guard

HIPS / PFW / Operating System Protection Evasion

barindex
Source: C:\Users\user\Downloads\ZipThis.exe Memory allocated: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe base: 208A0640000 protect: page read and write
Source: C:\Users\user\Downloads\ZipThis.exe Memory written: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe base: 208A0640000
Source: C:\Users\user\Downloads\ZipThis.exe Memory written: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe base: D0FA8A2D8
Source: C:\Users\user\Downloads\ZipThis.exe Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" https://www.zipthisapp.com/success?u=c14bc5b0-c4ea-49fa-aae2-e47c61b59c5b
Source: C:\Users\user\Downloads\ZipThis.exe Process created: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe "C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe"
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Process created: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe "C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe"
Source: C:\Users\user\Downloads\ZipThis.exe Queries volume information: C:\Users\user\Downloads\ZipThis.exe VolumeInformation
Source: C:\Users\user\Downloads\ZipThis.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework-SystemXml\v4.0_4.0.0.0__b77a5c561934e089\PresentationFramework-SystemXml.dll VolumeInformation
Source: C:\Users\user\Downloads\ZipThis.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\UIAutomationTypes\v4.0_4.0.0.0__31bf3856ad364e35\UIAutomationTypes.dll VolumeInformation
Source: C:\Users\user\Downloads\ZipThis.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\UIAutomationProvider\v4.0_4.0.0.0__31bf3856ad364e35\UIAutomationProvider.dll VolumeInformation
Source: C:\Users\user\Downloads\ZipThis.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.Extensions\v4.0_4.0.0.0__31bf3856ad364e35\System.Web.Extensions.dll VolumeInformation
Source: C:\Users\user\Downloads\ZipThis.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\System.Web\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Web.dll VolumeInformation
Source: C:\Windows\System32\svchost.exe Queries volume information: C:\ProgramData\Microsoft\Network\Downloader\edb.chk VolumeInformation
Source: C:\Windows\System32\svchost.exe Queries volume information: C:\ProgramData\Microsoft\Network\Downloader\edb.log VolumeInformation
Source: C:\Windows\System32\svchost.exe Queries volume information: C:\ProgramData\Microsoft\Network\Downloader\edb.chk VolumeInformation
Source: C:\Windows\System32\svchost.exe Queries volume information: C:\ProgramData\Microsoft\Network\Downloader\edb.log VolumeInformation
Source: C:\Windows\System32\svchost.exe Queries volume information: C:\ProgramData\Microsoft\Network\Downloader\edb.log VolumeInformation
Source: C:\Windows\System32\svchost.exe Queries volume information: C:\ProgramData\Microsoft\Network\Downloader\edb.log VolumeInformation
Source: C:\Windows\System32\svchost.exe Queries volume information: C:\ProgramData\Microsoft\Network\Downloader\edb.chk VolumeInformation
Source: C:\Windows\System32\svchost.exe Queries volume information: C:\ProgramData\Microsoft\Network\Downloader\qmgr.db VolumeInformation
Source: C:\Windows\System32\svchost.exe Queries volume information: C:\ProgramData\Microsoft\Network\Downloader\qmgr.jfm VolumeInformation
Source: C:\Windows\System32\svchost.exe Queries volume information: C:\ProgramData\Microsoft\Network\Downloader\qmgr.db VolumeInformation
Source: C:\Windows\System32\svchost.exe Queries volume information: C:\ProgramData\Microsoft\Network\Downloader\qmgr.db VolumeInformation
Source: C:\Windows\System32\svchost.exe Queries volume information: C:\ VolumeInformation
Source: C:\Windows\System32\svchost.exe Queries volume information: C:\ VolumeInformation
Source: C:\Windows\System32\svchost.exe Queries volume information: C:\ VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost\v4.0_3.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.ConsoleHost.dll VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Management.Automation\v4.0_3.0.0.0__31bf3856ad364e35\System.Management.Automation.dll VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.Management.Infrastructure\v4.0_1.0.0.0__31bf3856ad364e35\Microsoft.Management.Infrastructure.dll VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.PowerShell.Security\v4.0_3.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Security.dll VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\ VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-GroupPolicy-ClientTools-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-AppManagement-AppV-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\Microsoft.Management.Infrastructure.Native\v4.0_1.0.0.0__31bf3856ad364e35\Microsoft.Management.Infrastructure.Native.dll VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\AppvClient\Microsoft.AppV.AppVClientPowerShell.dll VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1865.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-Package~31bf3856ad364e35~amd64~en-GB~10.0.19041.1151.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility\v4.0_3.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Utility.dll VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\BitLocker\Microsoft.BitLocker.Structures.dll VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management\v4.0_3.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Management.dll VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package03~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package03~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package03~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package03~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package0013~31bf3856ad364e35~amd64~~10.0.19041.3208.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0314~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\Microsoft.KeyDistributionService.Cmdlets\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.KeyDistributionService.Cmdlets.dll VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\Microsoft.KeyDistributionService.Cmdlets\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.KeyDistributionService.Cmdlets.dll VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\Microsoft.KeyDistributionService.Cmdlets\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.KeyDistributionService.Cmdlets.dll VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\Microsoft.PowerShell.LocalAccounts\1.0.0.0\Microsoft.PowerShell.LocalAccounts.dll VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package03~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package03~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package03~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package03~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package03~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package03~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package03~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package03~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package03~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package03~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package03~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package0014~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package0014~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package0014~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package0014~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package0014~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package0014~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package00~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0314~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package05113~31bf3856ad364e35~amd64~~10.0.19041.3448.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package05113~31bf3856ad364e35~amd64~~10.0.19041.3448.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package05113~31bf3856ad364e35~amd64~~10.0.19041.3448.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package05113~31bf3856ad364e35~amd64~~10.0.19041.3448.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package05113~31bf3856ad364e35~amd64~~10.0.19041.3448.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package05113~31bf3856ad364e35~amd64~~10.0.19041.3448.cat VolumeInformation
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-Package05113~31bf3856ad364e35~amd64~~10.0.19041.3448.cat VolumeInformation
Source: C:\Users\user\Downloads\ZipThis.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.IO.Compression\v4.0_4.0.0.0__b77a5c561934e089\System.IO.Compression.dll VolumeInformation
Source: C:\Users\user\Downloads\ZipThis.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.IO.Compression.FileSystem\v4.0_4.0.0.0__b77a5c561934e089\System.IO.Compression.FileSystem.dll VolumeInformation
Source: C:\Users\user\Downloads\ZipThis.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.CSharp\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.CSharp.dll VolumeInformation
Source: C:\Users\user\Downloads\ZipThis.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Dynamic\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Dynamic.dll VolumeInformation
Source: C:\Users\user\Downloads\ZipThis.exe Queries volume information: C:\ VolumeInformation
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Queries volume information: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe VolumeInformation
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\System.Web\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Web.dll VolumeInformation
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework-SystemXml\v4.0_4.0.0.0__b77a5c561934e089\PresentationFramework-SystemXml.dll VolumeInformation
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\UIAutomationTypes\v4.0_4.0.0.0__31bf3856ad364e35\UIAutomationTypes.dll VolumeInformation
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\UIAutomationProvider\v4.0_4.0.0.0__31bf3856ad364e35\UIAutomationProvider.dll VolumeInformation
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Queries volume information: C:\ VolumeInformation
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Queries volume information: C:\ VolumeInformation
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Deployment\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll VolumeInformation
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Queries volume information: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe VolumeInformation
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\System.Web\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Web.dll VolumeInformation
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework-SystemXml\v4.0_4.0.0.0__b77a5c561934e089\PresentationFramework-SystemXml.dll VolumeInformation
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\UIAutomationTypes\v4.0_4.0.0.0__31bf3856ad364e35\UIAutomationTypes.dll VolumeInformation
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\UIAutomationProvider\v4.0_4.0.0.0__31bf3856ad364e35\UIAutomationProvider.dll VolumeInformation
Source: C:\Users\user\Downloads\ZipThis.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuid
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Directory queried: C:\Users\user\Documents
Source: C:\Users\user\AppData\Local\ZipThis\ZipThisApp.exe Directory queried: C:\Users\user\Documents\QFAPOWPAFG
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs