Source: 7bXVSwc9dp.exe, 00000000.00000002.2152685133.00000000034BB000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-soap-message-security-1.0#Base64Binary |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2152685133.00000000034BB000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-soap-message-security-1.0#HexBinary |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2152685133.00000000034BB000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-soap-message-security-1.0#Text |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2152685133.00000000034BB000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-secext-1.0.xsd |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2152685133.00000000034BB000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-utility-1.0.xsd |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2152685133.00000000034BB000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-x509-token-profile-1.0#X509SubjectKeyIdentif |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2152685133.00000000034BB000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://docs.oasis-open.org/wss/oasis-wss-kerberos-token-profile-1.1#GSS_Kerberosv5_AP_REQ |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2152685133.00000000034BB000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://docs.oasis-open.org/wss/oasis-wss-kerberos-token-profile-1.1#GSS_Kerberosv5_AP_REQ1510 |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2152685133.00000000034BB000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://docs.oasis-open.org/wss/oasis-wss-kerberos-token-profile-1.1#Kerberosv5APREQSHA1 |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2152685133.00000000034BB000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://docs.oasis-open.org/wss/oasis-wss-rel-token-profile-1.0.pdf#license |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2152685133.00000000034BB000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://docs.oasis-open.org/wss/oasis-wss-saml-token-profile-1.0#SAMLAssertionID |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2152685133.00000000034BB000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://docs.oasis-open.org/wss/oasis-wss-saml-token-profile-1.1#SAMLID |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2152685133.00000000034BB000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://docs.oasis-open.org/wss/oasis-wss-saml-token-profile-1.1#SAMLV1.1 |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2152685133.00000000034BB000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://docs.oasis-open.org/wss/oasis-wss-saml-token-profile-1.1#SAMLV2.0 |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2152685133.00000000034BB000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://docs.oasis-open.org/wss/oasis-wss-soap-message-security-1.1#EncryptedKey |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2152685133.00000000034BB000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://docs.oasis-open.org/wss/oasis-wss-soap-message-security-1.1#EncryptedKeySHA1 |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2152685133.00000000034BB000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://docs.oasis-open.org/wss/oasis-wss-soap-message-security-1.1#ThumbprintSHA1 |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2152685133.00000000034BB000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://docs.oasis-open.org/wss/oasis-wss-wssecurity-secext-1.1.xsd |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2152163170.0000000001AAE000.00000004.00000020.00020000.00000000.sdmp, 7bXVSwc9dp.exe, 00000000.00000003.2149342982.0000000001AAC000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://purl.oen |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2152685133.00000000034BB000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/2005/02/trust/spnego#GSS_Wrap |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2152685133.00000000034BB000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/2005/02/trust/tlsnego#TLS_Wrap |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2152685133.0000000003451000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/soap/actor/next |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2152685133.0000000003451000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/soap/envelope/ |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2152685133.00000000034BB000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2002/12/policy |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2152685133.00000000034BB000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2004/04/sc |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2152685133.00000000034BB000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2004/04/security/sc/dk |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2152685133.00000000034BB000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2004/04/security/sc/sct |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2152685133.00000000034BB000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2004/04/security/trust/CK/PSHA1 |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2152685133.00000000034BB000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2004/04/security/trust/Issue |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2152685133.00000000034BB000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2004/04/security/trust/Nonce |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2152685133.00000000034BB000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2004/04/security/trust/RST/Issue |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2152685133.00000000034BB000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2004/04/security/trust/RST/SCT |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2152685133.00000000034BB000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2004/04/security/trust/RSTR/Issue |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2152685133.00000000034BB000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2004/04/security/trust/RSTR/SCT |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2152685133.00000000034BB000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2004/04/security/trust/SymmetricKey |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2152685133.00000000034BB000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2004/04/trust |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2152685133.00000000034BB000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2004/04/trust/PublicKey |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2152685133.00000000034BB000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2004/04/trust/SymmetricKey |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2152685133.00000000034BB000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2004/06/addressingex |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2152685133.0000000003451000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2004/08/addressing |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2152685133.0000000003451000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2004/08/addressing/fault |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2152685133.0000000003451000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2152685133.00000000034BB000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2004/10/wsat |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2152685133.00000000034BB000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2004/10/wsat/Aborted |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2152685133.00000000034BB000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2004/10/wsat/Commit |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2152685133.00000000034BB000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2004/10/wsat/Committed |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2152685133.00000000034BB000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2004/10/wsat/Completion |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2152685133.00000000034BB000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2004/10/wsat/Durable2PC |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2152685133.00000000034BB000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2004/10/wsat/Prepare |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2152685133.00000000034BB000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2004/10/wsat/Prepared |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2152685133.00000000034BB000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2004/10/wsat/ReadOnly |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2152685133.00000000034BB000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2004/10/wsat/Replay |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2152685133.00000000034BB000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2004/10/wsat/Rollback |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2152685133.00000000034BB000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2004/10/wsat/Volatile2PC |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2152685133.00000000034BB000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2004/10/wsat/fault |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2152685133.00000000034BB000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2004/10/wscoor |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2152685133.00000000034BB000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2004/10/wscoor/CreateCoordinationContext |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2152685133.00000000034BB000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2004/10/wscoor/CreateCoordinationContextResponse |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2152685133.00000000034BB000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2004/10/wscoor/Register |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2152685133.00000000034BB000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2004/10/wscoor/RegisterResponse |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2152685133.00000000034BB000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2004/10/wscoor/fault |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2152685133.0000000003451000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/02/rm |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2152685133.0000000003451000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/02/rm/AckRequested |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2152685133.0000000003451000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/02/rm/CreateSequence |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2152685133.0000000003451000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/02/rm/CreateSequenceResponse |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2152685133.0000000003451000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/02/rm/LastMessage |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2152685133.0000000003451000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/02/rm/SequenceAcknowledgement |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2152685133.0000000003451000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/02/rm/TerminateSequence |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2152685133.00000000034BB000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/02/sc |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2152685133.00000000034BB000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/02/sc/dk |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2152685133.00000000034BB000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/02/sc/dk/p_sha1 |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2152685133.00000000034BB000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/02/sc/sct |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2152685133.00000000034BB000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/02/trust |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2152685133.00000000034BB000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/02/trust#BinarySecret |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2152685133.00000000034BB000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/02/trust/CK/PSHA1 |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2152685133.00000000034BB000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/02/trust/Cancel |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2152685133.00000000034BB000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/02/trust/Issue |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2152685133.00000000034BB000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/02/trust/Nonce |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2152685133.00000000034BB000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/02/trust/PublicKey |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2152685133.00000000034BB000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/02/trust/RST/Issue |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2152685133.00000000034BB000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/02/trust/RST/SCT |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2152685133.00000000034BB000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/02/trust/RST/SCT/Cancel |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2152685133.00000000034BB000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/02/trust/RST/SCT/Renew |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2152685133.00000000034BB000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/02/trust/RSTR/Issue |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2152685133.00000000034BB000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/02/trust/RSTR/SCT |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2152685133.00000000034BB000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/02/trust/RSTR/SCT/Cancel |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2152685133.00000000034BB000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/02/trust/RSTR/SCT/Renew |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2152685133.00000000034BB000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/02/trust/Renew |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2152685133.00000000034BB000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/02/trust/SymmetricKey |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2152685133.00000000034BB000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/02/trust/spnego |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2152685133.00000000034BB000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/02/trust/tlsnego |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2152685133.0000000003451000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/dns |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2152685133.00000000034BB000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2152685133.0000000003451000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/right/possessproperty |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2152685133.00000000034BB000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2006/02/addressingidentity |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2152685133.0000000003451000.00000004.00000800.00020000.00000000.sdmp, 7bXVSwc9dp.exe, 00000000.00000002.2152685133.00000000034BB000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/ |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2152685133.00000000034BB000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/D |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2152685133.0000000003451000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/RestAPI/TreeObject1 |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2152685133.0000000003451000.00000004.00000800.00020000.00000000.sdmp, 7bXVSwc9dp.exe, 00000000.00000002.2152685133.00000000034BB000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/RestAPI/TreeObject1Response |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2152685133.00000000034BB000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/RestAPI/TreeObject1ResponseD |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2152685133.0000000003451000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/RestAPI/TreeObject2 |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2152685133.0000000003451000.00000004.00000800.00020000.00000000.sdmp, 7bXVSwc9dp.exe, 00000000.00000002.2152685133.00000000034BB000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/RestAPI/TreeObject2Response |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2152685133.00000000034BB000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/RestAPI/TreeObject2ResponseD |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2152685133.0000000003451000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/RestAPI/TreeObject3 |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2152685133.0000000003451000.00000004.00000800.00020000.00000000.sdmp, 7bXVSwc9dp.exe, 00000000.00000002.2152685133.00000000034BB000.00000004.00000800.00020000.00000000.sdmp, 7bXVSwc9dp.exe, 00000000.00000002.2152685133.0000000003877000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/RestAPI/TreeObject3Response |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2152685133.0000000003877000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://tempuri.org/RestAPI/TreeObject3ResponseD |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2152685133.0000000003877000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.w3.o |
Source: 7bXVSwc9dp.exe, 00000000.00000003.2097739660.0000000004A58000.00000004.00000800.00020000.00000000.sdmp, 7bXVSwc9dp.exe, 00000000.00000003.2096561582.0000000004A6B000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ac.ecosia.org/autocomplete?q= |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2152685133.0000000003451000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://api.ip.sb/ip |
Source: 7bXVSwc9dp.exe, 00000000.00000003.2097739660.0000000004A58000.00000004.00000800.00020000.00000000.sdmp, 7bXVSwc9dp.exe, 00000000.00000003.2096561582.0000000004A6B000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://cdn.ecosia.org/assets/images/ico/favicon.icohttps://www.ecosia.org/search?q= |
Source: 7bXVSwc9dp.exe, 00000000.00000003.2097739660.0000000004A58000.00000004.00000800.00020000.00000000.sdmp, 7bXVSwc9dp.exe, 00000000.00000003.2096561582.0000000004A6B000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ch.search.yahoo.com/favicon.icohttps://ch.search.yahoo.com/search |
Source: 7bXVSwc9dp.exe, 00000000.00000003.2097739660.0000000004A58000.00000004.00000800.00020000.00000000.sdmp, 7bXVSwc9dp.exe, 00000000.00000003.2096561582.0000000004A6B000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ch.search.yahoo.com/sugg/chrome?output=fxjson&appid=crmas&command= |
Source: 7bXVSwc9dp.exe, 00000000.00000003.2097739660.0000000004A58000.00000004.00000800.00020000.00000000.sdmp, 7bXVSwc9dp.exe, 00000000.00000003.2096561582.0000000004A6B000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://duckduckgo.com/ac/?q= |
Source: 7bXVSwc9dp.exe, 00000000.00000003.2097739660.0000000004A58000.00000004.00000800.00020000.00000000.sdmp, 7bXVSwc9dp.exe, 00000000.00000003.2096561582.0000000004A6B000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://duckduckgo.com/chrome_newtab |
Source: 7bXVSwc9dp.exe, 00000000.00000003.2097739660.0000000004A58000.00000004.00000800.00020000.00000000.sdmp, 7bXVSwc9dp.exe, 00000000.00000003.2096561582.0000000004A6B000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://duckduckgo.com/favicon.icohttps://duckduckgo.com/?q= |
Source: 7bXVSwc9dp.exe, 00000000.00000003.2097739660.0000000004A58000.00000004.00000800.00020000.00000000.sdmp, 7bXVSwc9dp.exe, 00000000.00000003.2096561582.0000000004A6B000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://www.ecosia.org/newtab/ |
Source: 7bXVSwc9dp.exe, 00000000.00000003.2097739660.0000000004A58000.00000004.00000800.00020000.00000000.sdmp, 7bXVSwc9dp.exe, 00000000.00000003.2096561582.0000000004A6B000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://www.google.com/images/branding/product/ico/googleg_lodp.ico |
Source: C:\Users\user\Desktop\7bXVSwc9dp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\7bXVSwc9dp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\7bXVSwc9dp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\7bXVSwc9dp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\7bXVSwc9dp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\7bXVSwc9dp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\7bXVSwc9dp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\7bXVSwc9dp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\7bXVSwc9dp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\7bXVSwc9dp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\7bXVSwc9dp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\7bXVSwc9dp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\7bXVSwc9dp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\7bXVSwc9dp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\7bXVSwc9dp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\7bXVSwc9dp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\7bXVSwc9dp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\7bXVSwc9dp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\7bXVSwc9dp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\7bXVSwc9dp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\7bXVSwc9dp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\7bXVSwc9dp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\7bXVSwc9dp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\7bXVSwc9dp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\7bXVSwc9dp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\7bXVSwc9dp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\7bXVSwc9dp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\7bXVSwc9dp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\7bXVSwc9dp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\7bXVSwc9dp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\7bXVSwc9dp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\7bXVSwc9dp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\7bXVSwc9dp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\7bXVSwc9dp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\7bXVSwc9dp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\7bXVSwc9dp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\7bXVSwc9dp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\7bXVSwc9dp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\7bXVSwc9dp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\7bXVSwc9dp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\7bXVSwc9dp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\7bXVSwc9dp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\7bXVSwc9dp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\7bXVSwc9dp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\7bXVSwc9dp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\7bXVSwc9dp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\7bXVSwc9dp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\7bXVSwc9dp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\7bXVSwc9dp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\7bXVSwc9dp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\7bXVSwc9dp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\7bXVSwc9dp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\7bXVSwc9dp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\7bXVSwc9dp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\7bXVSwc9dp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\7bXVSwc9dp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\7bXVSwc9dp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\7bXVSwc9dp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\7bXVSwc9dp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\7bXVSwc9dp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\7bXVSwc9dp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\7bXVSwc9dp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\7bXVSwc9dp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\7bXVSwc9dp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\7bXVSwc9dp.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: qemu-ga.exe, 00000003.00000002.3224563673.0000000002E31000.00000004.00000800.00020000.00000000.sdmp, qemu-ga.exe, 00000005.00000002.3224439455.0000000002271000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: YC:\USERS\user\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\STARTUP\QEMU-GA.EXE |
Source: qemu-ga.exe, 00000003.00000002.3223012208.0000000000D5C000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\USERS\user\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\STARTUP\QEMU-GA.EXE0\MODULES;C:\PROGRAM FILES (X86)\AUTOIT3\AUTOITXPUBLIC=C:\USERS\PUBLICSESSIONNAME=CONSOLESYSTEMDRIVE=C:SYSTEMROOT=C:\WINDOWSTEMP=C:\USERS\user\APPDATA\LOCAL\TEMPT |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2160002093.00000000059F0000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\USERS\user\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\STARTUP\QEMU-GA.EXE@ |
Source: 7bXVSwc9dp.exe, 00000000.00000003.2148970965.000000000149B000.00000004.00000020.00020000.00000000.sdmp, 7bXVSwc9dp.exe, 00000000.00000002.2150867701.000000000149C000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: ILENAMEQEMU-GA.EXE0 |
Source: qemu-ga.exe, 00000003.00000002.3223012208.0000000000D50000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\WINDOWS\TEMP\ASLLOG_SHIMENGSTATE_QEMU-GA.EXE_2828.TXT |
Source: qemu-ga.exe, 00000003.00000002.3223012208.0000000000DC5000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:/USERS/user/APPDATA/ROAMING/MICROSOFT/WINDOWS/START MENU/PROGRAMS/STARTUP/QEMU-GA.EXE.CONFIGG |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2150906526.00000000014DB000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: FILE:///C:/USERS/user/APPDATA/ROAMING/MICROSOFT/WINDOWS/START%20MENU/PROGRAMS/STARTUP/QEMU-GA.EXE1 |
Source: qemu-ga.exe, 00000003.00000002.3223012208.0000000000D5C000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\USERS\user\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\STARTUP\QEMU-GA.EXEI |
Source: qemu-ga.exe, 00000005.00000002.3223167225.0000000000489000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\USERS\user\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\STARTUP\QEMU-GA.EXEJ |
Source: qemu-ga.exe, 00000003.00000002.3223012208.0000000000D5C000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\USERS\user\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\STARTUP\QEMU-GA.EXEH |
Source: qemu-ga.exe, 00000005.00000002.3223167225.00000000004EB000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: QEMU-GA.EXEP |
Source: 7bXVSwc9dp.exe, 00000000.00000003.2148970965.000000000149B000.00000004.00000020.00020000.00000000.sdmp, 7bXVSwc9dp.exe, 00000000.00000002.2150867701.000000000149C000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\USERS\user\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\STARTUP\QEMU-GA.EXEE |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2150906526.00000000014CB000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: /C:/USERS/user/APPDATA/ROAMING/MICROSOFT/WINDOWS/START%20MENU/PROGRAMS/STARTUP/QEMU-GA.EXEL |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2150906526.00000000014CB000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\USERS\user\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\STARTUP\QEMU-GA.EXEF |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2150137777.00000000010EE000.00000004.00000010.00020000.00000000.sdmp, 7bXVSwc9dp.exe, 00000000.00000002.2150298072.0000000001282000.00000020.00001000.00020000.00000000.sdmp | Binary or memory string: \QEMU-GA.EXE |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2150906526.00000000014CB000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: /C:/USERS/user/APPDATA/ROAMING/MICROSOFT/WINDOWS/START%20MENU/PROGRAMS/STARTUP/QEMU-GA.EXER |
Source: qemu-ga.exe, 00000003.00000002.3223012208.0000000000D5C000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\USERS\user\APPDATA\LOCAL\MICROSOFT\CLR_V4.0\USAGELOGS\QEMU-GA.EXE.LOG |
Source: qemu-ga.exe, 00000005.00000002.3223167225.00000000004EB000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\USERS\user\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\STARTUP\QEMU-GA.EXENH |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2150906526.00000000014CB000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: /C:/USERS/user/APPDATA/ROAMING/MICROSOFT/WINDOWS/START%20MENU/PROGRAMS/STARTUP/QEMU-GA.EXES |
Source: qemu-ga.exe, 00000003.00000002.3223012208.0000000000DC5000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\USERS\user\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\STARTUP\QEMU-GA.EXEN |
Source: qemu-ga.exe, 00000003.00000002.3224563673.0000000002E31000.00000004.00000800.00020000.00000000.sdmp, qemu-ga.exe, 00000005.00000002.3224439455.0000000002271000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: QEMU-GA.EXE2! |
Source: qemu-ga.exe, 00000003.00000002.3223012208.0000000000D50000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\USERS\user\DESKTOP\C:\USERS\user\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\STARTUP\QEMU-GA.EXE"C:\USERS\user\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\STARTUP\QEMU-GA.EXE" C:\USERS\user\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\STARTUP\QEMU-GA.EXEWINSTA0\DEFAULT |
Source: qemu-ga.exe, 00000003.00000002.3223012208.0000000000DC5000.00000004.00000020.00020000.00000000.sdmp, qemu-ga.exe, 00000005.00000002.3223167225.00000000004EB000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\USERS\user\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\STARTUP\QEMU-GA.EXE.CONFIG |
Source: qemu-ga.exe, 00000005.00000002.3223167225.00000000004EB000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: FQ\user\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\STARTUP\QEMU-GA.EXE.CONFIGL |
Source: qemu-ga.exe, 00000003.00000002.3223012208.0000000000D5C000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: \??\C:\USERS\user\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\STARTUP\QEMU-GA.EXE.CONFIG2.DLL |
Source: 7bXVSwc9dp.exe, 00000000.00000003.2148970965.000000000149B000.00000004.00000020.00020000.00000000.sdmp, 7bXVSwc9dp.exe, 00000000.00000002.2150867701.000000000149C000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: ERNALNAMEQEMU-GA.EXEH |
Source: qemu-ga.exe, 00000003.00000002.3223012208.0000000000D50000.00000004.00000020.00020000.00000000.sdmp, qemu-ga.exe, 00000005.00000002.3223167225.0000000000480000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: "C:\USERS\user\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\STARTUP\QEMU-GA.EXE" |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2160807057.0000000005ACE000.00000004.00000020.00020000.00000000.sdmp, 7bXVSwc9dp.exe, 00000000.00000003.2149088208.0000000005ACD000.00000004.00000020.00020000.00000000.sdmp, 7bXVSwc9dp.exe, 00000000.00000003.2148749486.0000000005AA1000.00000004.00000020.00020000.00000000.sdmp, 7bXVSwc9dp.exe, 00000000.00000002.2164115712.00000000072B8000.00000004.00000020.00020000.00000000.sdmp, 7bXVSwc9dp.exe, 00000000.00000003.2149036097.00000000072B7000.00000004.00000020.00020000.00000000.sdmp, 7bXVSwc9dp.exe, 00000000.00000002.2160159846.0000000005A76000.00000004.00000020.00020000.00000000.sdmp, 7bXVSwc9dp.exe, 00000000.00000003.2148475586.00000000072AA000.00000004.00000020.00020000.00000000.sdmp, 7bXVSwc9dp.exe, 00000000.00000002.2160584253.0000000005AA1000.00000004.00000020.00020000.00000000.sdmp, 7bXVSwc9dp.exe, 00000000.00000003.2148923577.0000000005AC1000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: :QEMU-GA.EXE |
Source: qemu-ga.exe, 00000005.00000002.3223167225.00000000004EB000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: FQC:/USERS/user/APPDATA/ROAMING/MICROSOFT/WINDOWS/START%20MENU/PROGRAMS/STARTUP/QEMU-GA.EXE.CONFIG |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2150388965.0000000001305000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\USERS\user\DESKTOP\C:\USERS\user\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\STARTUP\QEMU-GA.EXE"C:\USERS\user\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\STARTUP\QEMU-GA.EXE" |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2152685133.0000000003877000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: \QEMU-GA.EXE0 |
Source: qemu-ga.exe, 00000003.00000002.3224563673.0000000002E31000.00000004.00000800.00020000.00000000.sdmp, qemu-ga.exe, 00000005.00000002.3224439455.0000000002271000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: `C:\USERS\user\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\STARTUP\QEMU-GA.EXE.CONFIG`_! |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2160002093.00000000059F0000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: \REGISTRY\MACHINE\SOFTWARE\CLASSES\APPLICATIONS\QEMU-GA.EXE |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2152685133.0000000003877000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: $]QYC:\USERS\user\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\STARTUP\QEMU-GA.EXE |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2160002093.00000000059F0000.00000004.00000020.00020000.00000000.sdmp, qemu-ga.exe, 00000003.00000002.3223012208.0000000000D5C000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\USERS\user\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\STARTUP\QEMU-GA.EXE, |
Source: qemu-ga.exe, 00000005.00000002.3223167225.00000000004EB000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: FQC:USERSuserAPPDATAROAMINGMICROSOFTWINDOWSSTART%20MENUPROGRAMSSTARTUPQEMU-GA.EXE.CONFIG! |
Source: qemu-ga.exe, 00000003.00000002.3223012208.0000000000DC5000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\USERS\user\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\STARTUP\QEMU-GA.EXE* |
Source: qemu-ga.exe, 00000003.00000002.3223012208.0000000000DBF000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: QEMU-GA.EXEN |
Source: qemu-ga.exe, 00000005.00000002.3223167225.0000000000489000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\USERS\user\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\STARTUP\QEMU-GA.EXE2 |
Source: qemu-ga.exe, 00000003.00000002.3223012208.0000000000DC5000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:/USERS/user/APPDATA/ROAMING/MICROSOFT/WINDOWS/START%20MENU/PROGRAMS/STARTUP/QEMU-GA.EXE.CONFIGL |
Source: 7bXVSwc9dp.exe, 00000000.00000003.2148970965.000000000149B000.00000004.00000020.00020000.00000000.sdmp, 7bXVSwc9dp.exe, 00000000.00000002.2150867701.000000000149C000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: FILE//C:USERSuserAPPDATAROAMINGMICROSOFTWINDOWSSTART%20MENUPROGRAMSSTARTUPQEMU-GA.EXESN |
Source: qemu-ga.exe, 00000003.00000002.3223012208.0000000000DC5000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: QEMU-GA.EXEJ |
Source: 7bXVSwc9dp.exe, 00000000.00000003.2148970965.000000000149B000.00000004.00000020.00020000.00000000.sdmp, 7bXVSwc9dp.exe, 00000000.00000002.2150867701.000000000149C000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: LNAMEQEMU-GA.EXEH |
Source: qemu-ga.exe, 00000005.00000002.3223167225.00000000004EB000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: FQC:/USERS/user/APPDATA/ROAMING/MICROSOFT/WINDOWS/START MENU/PROGRAMS/STARTUP/QEMU-GA.EXE.CONFIGG& |
Source: qemu-ga.exe, 00000003.00000002.3223012208.0000000000DC5000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: QEMU-GA.EXEE |
Source: qemu-ga.exe, 00000005.00000002.3223167225.0000000000489000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: /HC:\USERS\user\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\STARTUP\QEMU-GA.EXE |
Source: qemu-ga.exe, 00000003.00000002.3223012208.0000000000D5C000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\USERS\user\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\STARTUP\QEMU-GA.EXE8 |
Source: qemu-ga.exe, 00000003.00000002.3223012208.0000000000DC5000.00000004.00000020.00020000.00000000.sdmp, qemu-ga.exe, 00000005.00000002.3223167225.00000000004EB000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\USERS\user\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\STARTUP\QEMU-GA.EXE.CONFIGG |
Source: 7bXVSwc9dp.exe, 00000000.00000003.2148970965.000000000149B000.00000004.00000020.00020000.00000000.sdmp, 7bXVSwc9dp.exe, 00000000.00000002.2150867701.000000000149C000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\USERS\user\APPDATA\ROAMING\MICROSOFT\WINDOWS\START%20MENU\PROGRAMS\STARTUP\QEMU-GA.EXE^J7~ |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2160002093.00000000059F0000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\USERS\user\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\STARTUP\QEMU-GA.EXE35/T |
Source: qemu-ga.exe, 00000005.00000002.3223167225.0000000000489000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: FIC:\USERS\user\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\STARTUP\QEMU-GA.EXE |
Source: qemu-ga.exe, 00000005.00000002.3223167225.0000000000489000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: QEMU-GA.EXENALFO0 |
Source: 7bXVSwc9dp.exe, 00000000.00000003.2148970965.000000000149B000.00000004.00000020.00020000.00000000.sdmp, 7bXVSwc9dp.exe, 00000000.00000002.2150867701.000000000149C000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: NALFILENAMEQEMU-GA.EXE0 |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2150906526.00000000014DB000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: FILE:///C:/USERS/user/APPDATA/ROAMING/MICROSOFT/WINDOWS/START%20MENU/PROGRAMS/STARTUP/QEMU-GA.EXE{ |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2160807057.0000000005ACE000.00000004.00000020.00020000.00000000.sdmp, 7bXVSwc9dp.exe, 00000000.00000003.2149088208.0000000005ACD000.00000004.00000020.00020000.00000000.sdmp, 7bXVSwc9dp.exe, 00000000.00000003.2148749486.0000000005AA1000.00000004.00000020.00020000.00000000.sdmp, 7bXVSwc9dp.exe, 00000000.00000002.2164115712.00000000072B8000.00000004.00000020.00020000.00000000.sdmp, 7bXVSwc9dp.exe, 00000000.00000003.2149036097.00000000072B7000.00000004.00000020.00020000.00000000.sdmp, 7bXVSwc9dp.exe, 00000000.00000002.2150906526.00000000014CB000.00000004.00000020.00020000.00000000.sdmp, 7bXVSwc9dp.exe, 00000000.00000002.2160159846.0000000005A76000.00000004.00000020.00020000.00000000.sdmp, 7bXVSwc9dp.exe, 00000000.00000003.2148475586.00000000072AA000.00000004.00000020.00020000.00000000.sdmp, 7bXVSwc9dp.exe, 00000000.00000002.2160584253.0000000005AA1000.00000004.00000020.00020000.00000000.sdmp, 7bXVSwc9dp.exe, 00000000.00000002.2152685133.0000000003877000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: QEMU-GA.EXE |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2160159846.0000000005A76000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: \??\C:\USERS\user\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\STARTUP\QEMU-GA.EXE:ZONE.IDENTIFIER |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2150906526.00000000014CB000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: /C:/USERS/user/APPDATA/ROAMING/MICROSOFT/WINDOWS/START%20MENU/PROGRAMS/STARTUP/QEMU-GA.EXE |
Source: qemu-ga.exe, 00000005.00000002.3223167225.00000000004B2000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: P,KC:\USERS\user\APPDATA\LOCALC:\USERS\user\APPDATA\LOCAL\MICROSOFT\CLR_V4.0\USAGELOGS\QEMU-GA.EXE.LOGP |
Source: 7bXVSwc9dp.exe, 00000000.00000003.2148970965.000000000149B000.00000004.00000020.00020000.00000000.sdmp, 7bXVSwc9dp.exe, 00000000.00000002.2150867701.000000000149C000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\USERS\user\APPDATA\LOCAL\TEMPMINGMICROSOFTWINDOWSSTART%20MENUPROGRAMSSTARTUPQEMU-GA.EXE |
Source: qemu-ga.exe, 00000003.00000002.3223012208.0000000000DC5000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: FILE:///C:/USERS/user/APPDATA/ROAMING/MICROSOFT/WINDOWS/START MENU/PROGRAMS/STARTUP/QEMU-GA.EXE |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2160807057.0000000005ACE000.00000004.00000020.00020000.00000000.sdmp, 7bXVSwc9dp.exe, 00000000.00000003.2149088208.0000000005ACD000.00000004.00000020.00020000.00000000.sdmp, 7bXVSwc9dp.exe, 00000000.00000003.2148749486.0000000005AA1000.00000004.00000020.00020000.00000000.sdmp, 7bXVSwc9dp.exe, 00000000.00000002.2164115712.00000000072B8000.00000004.00000020.00020000.00000000.sdmp, 7bXVSwc9dp.exe, 00000000.00000003.2149036097.00000000072B7000.00000004.00000020.00020000.00000000.sdmp, 7bXVSwc9dp.exe, 00000000.00000002.2160159846.0000000005A76000.00000004.00000020.00020000.00000000.sdmp, 7bXVSwc9dp.exe, 00000000.00000003.2148475586.00000000072AA000.00000004.00000020.00020000.00000000.sdmp, 7bXVSwc9dp.exe, 00000000.00000002.2160584253.0000000005AA1000.00000004.00000020.00020000.00000000.sdmp, 7bXVSwc9dp.exe, 00000000.00000003.2148923577.0000000005AC1000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: QEMU-GA.EXEH |
Source: qemu-ga.exe, 00000005.00000002.3223167225.00000000004EB000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: FILE:///C:/USERS/user/APPDATA/ROAMING/MICROSOFT/WINDOWS/START MENU/PROGRAMS/STARTUP/QEMU-GA.EXEIG |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2152685133.0000000003877000.00000004.00000800.00020000.00000000.sdmp, qemu-ga.exe, 00000003.00000000.2148231933.0000000000964000.00000002.00000001.01000000.00000007.sdmp, qemu-ga.exe.0.dr | Binary or memory string: ORIGINALFILENAMEQEMU-GA.EXE0 |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2160159846.0000000005A76000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: \\?\C:\USERS\user\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\STARTUP\QEMU-GA.EXE:ZONE.IDENTIFIER?J |
Source: qemu-ga.exe, 00000003.00000002.3223012208.0000000000DC5000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:USERSuserAPPDATAROAMINGMICROSOFTWINDOWSSTART%20MENUPROGRAMSSTARTUPQEMU-GA.EXE.CONFIG! |
Source: qemu-ga.exe, 00000005.00000002.3223981771.0000000000780000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: XC:\USERS\user\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\STARTUP\QEMU-GA.EXE]V |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2150191036.0000000001190000.00000004.00000020.00040000.00000000.sdmp | Binary or memory string: C:\USERS\user\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\STARTUP\QEMU-GA.EXE\??\C:\USERS\user\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\STARTUP\QEMU-GA.EXEEN-GBENEN-USMYAPPLICATION.APPBB. |
Source: qemu-ga.exe, 00000003.00000002.3223012208.0000000000D5C000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\USERS\user\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\STARTUP\QEMU-GA.EXE.WSF |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2152685133.0000000003877000.00000004.00000800.00020000.00000000.sdmp, qemu-ga.exe, 00000003.00000000.2148231933.0000000000964000.00000002.00000001.01000000.00000007.sdmp, qemu-ga.exe.0.dr | Binary or memory string: INTERNALNAMEQEMU-GA.EXEH |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2164115712.00000000072B8000.00000004.00000020.00020000.00000000.sdmp, 7bXVSwc9dp.exe, 00000000.00000003.2149036097.00000000072B7000.00000004.00000020.00020000.00000000.sdmp, 7bXVSwc9dp.exe, 00000000.00000003.2148475586.00000000072AA000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: SERS\user\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\STARTUP\QEMU-GA.EXEE |
Source: qemu-ga.exe, 00000003.00000002.3223012208.0000000000D5C000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: \??\C:\USERS\user\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\STARTUP\QEMU-GA.EXE.CONFIG |
Source: qemu-ga.exe, 00000005.00000002.3223167225.0000000000480000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\USERS\user\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\STARTUP\C:\USERS\user\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\STARTUP\QEMU-GA.EXE"C:\USERS\user\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\STARTUP\QEMU-GA.EXE" C:\USERS\user\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\STARTUP\QEMU-GA.EXEWINSTA0\DEFAULT |
Source: qemu-ga.exe, 00000003.00000002.3224563673.0000000002E31000.00000004.00000800.00020000.00000000.sdmp, qemu-ga.exe, 00000005.00000002.3224439455.0000000002271000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: QEMU-GA.EXE.CONFIG |
Source: qemu-ga.exe, 00000003.00000002.3223012208.0000000000D50000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\WINDOWS\TEMP\ASLLOG_APPHELPDEBUG_QEMU-GA.EXE_2828.TXT P |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2160002093.00000000059F0000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: \REGISTRY\MACHINE\SOFTWARE\CLASSES\APPLICATIONS\QEMU-GA.EXEOWS\START MENU\PROGRAMS\STARTUP\QEMU-GA.EXEZL |
Source: qemu-ga.exe, 00000005.00000002.3223167225.00000000004EB000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: PQEMU-GA.EXE |
Source: qemu-ga.exe, 00000003.00000002.3223012208.0000000000D50000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\WINDOWS\TEMP\ASLLOG_SHIMDEBUGLOG_QEMU-GA.EXE_2828.TXT L |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2150388965.0000000001305000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\USERS\user\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\STARTUP\QEMU-GA.EXEWINSTA0\DEFAULT |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2150906526.00000000014CB000.00000004.00000020.00020000.00000000.sdmp, 7bXVSwc9dp.exe, 00000000.00000002.2160002093.00000000059F0000.00000004.00000020.00020000.00000000.sdmp, qemu-ga.exe, 00000003.00000002.3222786269.0000000000D20000.00000004.00000020.00020000.00000000.sdmp, qemu-ga.exe, 00000003.00000002.3223012208.0000000000D5C000.00000004.00000020.00020000.00000000.sdmp, qemu-ga.exe, 00000003.00000002.3222653528.0000000000CFA000.00000004.00000010.00020000.00000000.sdmp, qemu-ga.exe, 00000003.00000002.3223012208.0000000000D50000.00000004.00000020.00020000.00000000.sdmp, qemu-ga.exe, 00000005.00000002.3223167225.0000000000489000.00000004.00000020.00020000.00000000.sdmp, qemu-ga.exe, 00000005.00000002.3222573802.000000000015A000.00000004.00000010.00020000.00000000.sdmp, qemu-ga.exe, 00000005.00000002.3223167225.0000000000480000.00000004.00000020.00020000.00000000.sdmp, qemu-ga.exe, 00000005.00000002.3223167225.00000000004EB000.00000004.00000020.00020000.00000000.sdmp, qemu-ga.exe, 00000005.00000002.3223981771.0000000000780000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\USERS\user\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\STARTUP\QEMU-GA.EXE |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2150906526.00000000014CB000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: /C:/USERS/user/APPDATA/ROAMING/MICROSOFT/WINDOWS/START%20MENU/PROGRAMS/STARTUP/QEMU-GA.EXE4 |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2150906526.00000000014DB000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: FILE:///C:/USERS/user/APPDATA/ROAMING/MICROSOFT/WINDOWS/START%20MENU/PROGRAMS/STARTUP/QEMU-GA.EXE |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2150906526.00000000014CB000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: \??\C:\USERS\user\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\STARTUP\QEMU-GA.EXEY |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2150906526.00000000014CB000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: /C:/USERS/user/APPDATA/ROAMING/MICROSOFT/WINDOWS/START%20MENU/PROGRAMS/STARTUP/QEMU-GA.EXE: |
Source: qemu-ga.exe, 00000005.00000002.3223167225.0000000000480000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: QHC:\USERS\user\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\STARTUP\QEMU-GA.EXE |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2150906526.00000000014CB000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: \??\C:\USERS\user\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\STARTUP\QEMU-GA.EXE |
Source: 7bXVSwc9dp.exe, 00000000.00000003.2148970965.000000000149B000.00000004.00000020.00020000.00000000.sdmp, 7bXVSwc9dp.exe, 00000000.00000002.2150867701.000000000149C000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: FILE//C:USERSuserAPPDATAROAMINGMICROSOFTWINDOWSSTART%20MENUPROGRAMSSTARTUPQEMU-GA.EXE{HTX |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2152685133.0000000003877000.00000004.00000800.00020000.00000000.sdmp, qemu-ga.exe, 00000003.00000000.2148201842.0000000000962000.00000002.00000001.01000000.00000007.sdmp, qemu-ga.exe.0.dr | Binary or memory string: <MODULE>QEMU-GAMSCORLIBTHREADCONSOLEREADLINEDEBUGGABLEATTRIBUTECOMVISIBLEATTRIBUTEASSEMBLYTITLEATTRIBUTEASSEMBLYTRADEMARKATTRIBUTETARGETFRAMEWORKATTRIBUTEASSEMBLYFILEVERSIONATTRIBUTEASSEMBLYCONFIGURATIONATTRIBUTEASSEMBLYDESCRIPTIONATTRIBUTECOMPILATIONRELAXATIONSATTRIBUTEASSEMBLYPRODUCTATTRIBUTEASSEMBLYCOPYRIGHTATTRIBUTEASSEMBLYCOMPANYATTRIBUTERUNTIMECOMPATIBILITYATTRIBUTEQEMU-GA.EXESYSTEM.THREADINGSYSTEM.RUNTIME.VERSIONINGPROGRAMSYSTEMMAINSYSTEM.REFLECTIONSLEEP.CTORSYSTEM.DIAGNOSTICSSYSTEM.RUNTIME.INTEROPSERVICESSYSTEM.RUNTIME.COMPILERSERVICESDEBUGGINGMODESARGSOBJECT |
Source: qemu-ga.exe, 00000003.00000002.3223012208.0000000000DC5000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: \user\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\STARTUP\QEMU-GA.EXE.CONFIG |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2160002093.00000000059F0000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\USERS\user\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\STARTUP\QEMU-GA.EXEWU |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2160002093.00000000059F0000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\USERS\user\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\STARTUP\QEMU-GA.EXEWT |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2155160486.00000000044BB000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: Interactive Brokers - EU WestVMware20,11696428655n |
Source: qemu-ga.exe, 00000003.00000002.3223012208.0000000000DC5000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:/Users/user/AppData/Roaming/Microsoft/Windows/Start Menu/Programs/Startup/qemu-ga.exe.configg |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2160002093.00000000059F0000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exewt |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2160002093.00000000059F0000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: \Registry\Machine\Software\Classes\Applications\qemu-ga.exeows\Start Menu\Programs\Startup\qemu-ga.exeZl |
Source: qemu-ga.exe, 00000003.00000002.3223012208.0000000000D50000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\Windows\Temp\AslLog_ShimDebugLog_qemu-ga.exe_2828.txt l |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2155160486.00000000044BB000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: ms.portal.azure.comVMware20,11696428655 |
Source: qemu-ga.exe, 00000005.00000002.3223167225.00000000004EB000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: FQC:UsersuserAppDataRoamingMicrosoftWindowsStart%20MenuProgramsStartupqemu-ga.exe.config! |
Source: qemu-ga.exe, 00000005.00000002.3223167225.00000000004EB000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exeNh |
Source: 7bXVSwc9dp.exe, 00000000.00000003.2148475586.00000000072AA000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: \??\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\Device\CdRom0\??\Volume{a33c736e-61ca-11ee-8c18-806e6f6e6963}\DosDevices\D:n |
Source: qemu-ga.exe, 00000003.00000002.3223012208.0000000000DC5000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: file:///C:/Users/user/AppData/Roaming/Microsoft/Windows/Start Menu/Programs/Startup/qemu-ga.exe |
Source: 7bXVSwc9dp.exe, 00000000.00000003.2148970965.000000000149B000.00000004.00000020.00020000.00000000.sdmp, 7bXVSwc9dp.exe, 00000000.00000002.2150867701.000000000149C000.00000004.00000020.00020000.00000000.sdmp, 7bXVSwc9dp.exe, 00000000.00000002.2152685133.0000000003877000.00000004.00000800.00020000.00000000.sdmp, qemu-ga.exe, 00000003.00000000.2148231933.0000000000964000.00000002.00000001.01000000.00000007.sdmp, qemu-ga.exe.0.dr | Binary or memory string: ProductNameqemu-ga4 |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2150906526.00000000014CB000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: /C:/Users/user/AppData/Roaming/Microsoft/Windows/Start%20Menu/Programs/Startup/qemu-ga.exe4 |
Source: qemu-ga.exe, 00000003.00000002.3223012208.0000000000D5C000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exe0\Modules;C:\Program Files (x86)\AutoIt3\AutoItXPUBLIC=C:\Users\PublicSESSIONNAME=ConsoleSystemDrive=C:SystemRoot=C:\WindowsTEMP=C:\Users\user\AppData\Local\TempT |
Source: qemu-ga.exe, 00000005.00000002.3223167225.00000000004B2000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: p,KC:\Users\user\AppData\LocalC:\Users\user\AppData\Local\Microsoft\CLR_v4.0\UsageLogs\qemu-ga.exe.logP |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2155160486.00000000044BB000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: global block list test formVMware20,11696428655 |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2155160486.00000000044BB000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: Test URL for global passwords blocklistVMware20,11696428655 |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2150906526.00000000014CB000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: /C:/Users/user/AppData/Roaming/Microsoft/Windows/Start%20Menu/Programs/Startup/qemu-ga.exe: |
Source: qemu-ga.exe, 00000003.00000002.3223012208.0000000000DC5000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: \user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exe.config |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2155160486.00000000044BB000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: microsoft.visualstudio.comVMware20,11696428655x |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2150906526.00000000014CB000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: \??\C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exeY |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2160002093.00000000059F0000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exeWu |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2155160486.00000000045AB000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: AMC password management pageVMware20,11696428655 |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2150906526.00000000014CB000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: \??\C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exe |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2155160486.00000000045AB000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: tasks.office.comVMware20,11696428655o |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2155160486.00000000045AB000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: interactivebrokers.comVMware20,11696428655 |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2150906526.00000000014DB000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: file:///C:/Users/user/AppData/Roaming/Microsoft/Windows/Start%20Menu/Programs/Startup/qemu-ga.exe |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2155160486.00000000044BB000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: Interactive Brokers - EU East & CentralVMware20,11696428655 |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2150137777.00000000010EE000.00000004.00000010.00020000.00000000.sdmp, 7bXVSwc9dp.exe, 00000000.00000002.2150298072.0000000001282000.00000020.00001000.00020000.00000000.sdmp | Binary or memory string: \qemu-ga.exe |
Source: qemu-ga.exe, 00000005.00000002.3223167225.0000000000489000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: FIC:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exe |
Source: qemu-ga.exe, 00000005.00000002.3223167225.0000000000480000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exe"C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exe" C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exeWinsta0\Default |
Source: qemu-ga.exe, 00000003.00000002.3223012208.0000000000D50000.00000004.00000020.00020000.00000000.sdmp, qemu-ga.exe, 00000005.00000002.3223167225.0000000000480000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: "C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exe" |
Source: qemu-ga.exe, 00000003.00000002.3223012208.0000000000D5C000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: \??\C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exe.config |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2150388965.0000000001305000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exeWinsta0\Default |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2155160486.00000000045AB000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: bankofamerica.comVMware20,11696428655x |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2160159846.0000000005A76000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: \??\C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exe:Zone.Identifier |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2150906526.00000000014DB000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: file:///C:/Users/user/AppData/Roaming/Microsoft/Windows/Start%20Menu/Programs/Startup/qemu-ga.exe1 |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2152685133.0000000003877000.00000004.00000800.00020000.00000000.sdmp, qemu-ga.exe, 00000003.00000000.2148231933.0000000000964000.00000002.00000001.01000000.00000007.sdmp, qemu-ga.exe.0.dr | Binary or memory string: InternalNameqemu-ga.exeH |
Source: qemu-ga.exe, 00000003.00000002.3223012208.0000000000DBF000.00000004.00000020.00020000.00000000.sdmp, qemu-ga.exe, 00000005.00000002.3223167225.00000000004EB000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: \??\C:\Windows\assembly\NativeImages_v4.0.30319_64\qemu-ga\* |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2150388965.0000000001305000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\Users\user\Desktop\C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exe"C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exe" |
Source: qemu-ga.exe, 00000005.00000002.3225241930.00007FF848E34000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: Iqemu-ga |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2155160486.00000000045AB000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: discord.comVMware20,11696428655f |
Source: qemu-ga.exe, 00000005.00000002.3223167225.0000000000489000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: /HC:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exe |
Source: 7bXVSwc9dp.exe, 00000000.00000003.2148970965.000000000149B000.00000004.00000020.00020000.00000000.sdmp, 7bXVSwc9dp.exe, 00000000.00000002.2150867701.000000000149C000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\Users\user\AppData\Local\TempmingMicrosoftWindowsStart%20MenuProgramsStartupqemu-ga.exe |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2155160486.00000000044BB000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: turbotax.intuit.comVMware20,11696428655t |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2155160486.00000000044BB000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: dev.azure.comVMware20,11696428655j |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2155160486.00000000044BB000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: www.interactivebrokers.comVMware20,11696428655} |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2160807057.0000000005ACE000.00000004.00000020.00020000.00000000.sdmp, 7bXVSwc9dp.exe, 00000000.00000003.2149088208.0000000005ACD000.00000004.00000020.00020000.00000000.sdmp, 7bXVSwc9dp.exe, 00000000.00000003.2148749486.0000000005AA1000.00000004.00000020.00020000.00000000.sdmp, 7bXVSwc9dp.exe, 00000000.00000002.2164115712.00000000072B8000.00000004.00000020.00020000.00000000.sdmp, 7bXVSwc9dp.exe, 00000000.00000003.2149036097.00000000072B7000.00000004.00000020.00020000.00000000.sdmp, 7bXVSwc9dp.exe, 00000000.00000002.2160159846.0000000005A76000.00000004.00000020.00020000.00000000.sdmp, 7bXVSwc9dp.exe, 00000000.00000003.2148475586.00000000072AA000.00000004.00000020.00020000.00000000.sdmp, 7bXVSwc9dp.exe, 00000000.00000002.2160584253.0000000005AA1000.00000004.00000020.00020000.00000000.sdmp, 7bXVSwc9dp.exe, 00000000.00000003.2148923577.0000000005AC1000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: :qemu-ga.exe |
Source: qemu-ga.exe, 00000003.00000002.3224563673.0000000002E31000.00000004.00000800.00020000.00000000.sdmp, qemu-ga.exe, 00000005.00000002.3224439455.0000000002271000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: YC:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exe |
Source: qemu-ga.exe, 00000003.00000002.3223012208.0000000000DC5000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: qemu@S |
Source: 7bXVSwc9dp.exe, 00000000.00000003.2148970965.000000000149B000.00000004.00000020.00020000.00000000.sdmp, 7bXVSwc9dp.exe, 00000000.00000002.2150867701.000000000149C000.00000004.00000020.00020000.00000000.sdmp, 7bXVSwc9dp.exe, 00000000.00000002.2152685133.0000000003877000.00000004.00000800.00020000.00000000.sdmp, qemu-ga.exe, 00000003.00000000.2148231933.0000000000964000.00000002.00000001.01000000.00000007.sdmp, qemu-ga.exe.0.dr | Binary or memory string: FileDescriptionqemu-ga0 |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2155160486.00000000045AB000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: secure.bankofamerica.comVMware20,11696428655|UE |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2155160486.00000000045AB000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: Interactive Brokers - EU WestVMware20,11696428655n |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2155160486.00000000045AB000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: outlook.office365.comVMware20,11696428655t |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2155160486.00000000045AB000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: Canara Change Transaction PasswordVMware20,11696428655 |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2155160486.00000000045AB000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: outlook.office.comVMware20,11696428655s |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2155160486.00000000044BB000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: discord.comVMware20,11696428655f |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2155160486.00000000045AB000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: www.interactivebrokers.co.inVMware20,11696428655~ |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2155160486.00000000045AB000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: ms.portal.azure.comVMware20,11696428655 |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2152685133.0000000003877000.00000004.00000800.00020000.00000000.sdmp, qemu-ga.exe, 00000003.00000000.2148231933.0000000000964000.00000002.00000001.01000000.00000007.sdmp, qemu-ga.exe.0.dr | Binary or memory string: OriginalFilenameqemu-ga.exe0 |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2155160486.00000000045AB000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: Interactive Brokers - NDCDYNVMware20,11696428655z |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2155160486.00000000045AB000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: dev.azure.comVMware20,11696428655j |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2155160486.00000000045AB000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: netportal.hdfcbank.comVMware20,11696428655 |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2155160486.00000000044BB000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: Canara Change Transaction PasswordVMware20,11696428655^ |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2155160486.00000000044BB000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: AMC password management pageVMware20,11696428655 |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2155160486.00000000044BB000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: interactivebrokers.comVMware20,11696428655 |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2155160486.00000000044BB000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: www.interactivebrokers.co.inVMware20,11696428655~ |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2160159846.0000000005A76000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: \\?\C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exe:Zone.Identifier?j |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2150906526.00000000014DB000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: file:///C:/Users/user/AppData/Roaming/Microsoft/Windows/Start%20Menu/Programs/Startup/qemu-ga.exe{ |
Source: qemu-ga.exe, 00000003.00000002.3223012208.0000000000DC5000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:UsersuserAppDataRoamingMicrosoftWindowsStart%20MenuProgramsStartupqemu-ga.exe.config! |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2155160486.00000000044BB000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: Interactive Brokers - NDCDYNVMware20,11696428655z |
Source: qemu-ga.exe, 00000003.00000002.3223012208.0000000000D50000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: \user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exC:P |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2155160486.00000000045AB000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: trackpan.utiitsl.comVMware20,11696428655h |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2155160486.00000000044BB000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: Interactive Brokers - HKVMware20,11696428655] |
Source: qemu-ga.exe, 00000003.00000002.3223012208.0000000000D5C000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exe.WSF |
Source: qemu-ga.exe, 00000005.00000002.3223167225.00000000004EB000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: qemu-ga.exep |
Source: 7bXVSwc9dp.exe, 00000000.00000003.2148970965.000000000149B000.00000004.00000020.00020000.00000000.sdmp, 7bXVSwc9dp.exe, 00000000.00000002.2150867701.000000000149C000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: ilenameqemu-ga.exe0 |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2152685133.0000000003877000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: \qemu-ga.exe0 |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2155160486.00000000045AB000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: interactivebrokers.co.inVMware20,11696428655d |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2155160486.00000000045AB000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: Interactive Brokers - COM.HKVMware20,11696428655 |
Source: qemu-ga.exe, 00000003.00000002.3224563673.0000000002E31000.00000004.00000800.00020000.00000000.sdmp, qemu-ga.exe, 00000005.00000002.3224439455.0000000002271000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: qemu-ga.exe.config |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2155160486.00000000045AB000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: global block list test formVMware20,11696428655 |
Source: qemu-ga.exe, 00000003.00000002.3223012208.0000000000DC5000.00000004.00000020.00020000.00000000.sdmp, qemu-ga.exe, 00000005.00000002.3223167225.00000000004EB000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exe.config |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2160807057.0000000005ACE000.00000004.00000020.00020000.00000000.sdmp, 7bXVSwc9dp.exe, 00000000.00000003.2149088208.0000000005ACD000.00000004.00000020.00020000.00000000.sdmp, 7bXVSwc9dp.exe, 00000000.00000003.2148749486.0000000005AA1000.00000004.00000020.00020000.00000000.sdmp, 7bXVSwc9dp.exe, 00000000.00000002.2164115712.00000000072B8000.00000004.00000020.00020000.00000000.sdmp, 7bXVSwc9dp.exe, 00000000.00000003.2149036097.00000000072B7000.00000004.00000020.00020000.00000000.sdmp, 7bXVSwc9dp.exe, 00000000.00000002.2150906526.00000000014CB000.00000004.00000020.00020000.00000000.sdmp, 7bXVSwc9dp.exe, 00000000.00000002.2160159846.0000000005A76000.00000004.00000020.00020000.00000000.sdmp, 7bXVSwc9dp.exe, 00000000.00000003.2148475586.00000000072AA000.00000004.00000020.00020000.00000000.sdmp, 7bXVSwc9dp.exe, 00000000.00000002.2160584253.0000000005AA1000.00000004.00000020.00020000.00000000.sdmp, 7bXVSwc9dp.exe, 00000000.00000002.2152685133.0000000003877000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: qemu-ga.exe |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2155160486.00000000045AB000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: account.microsoft.com/profileVMware20,11696428655u |
Source: 7bXVSwc9dp.exe, 00000000.00000003.2148970965.000000000149B000.00000004.00000020.00020000.00000000.sdmp, 7bXVSwc9dp.exe, 00000000.00000002.2150867701.000000000149C000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: lNameqemu-ga.exeH |
Source: qemu-ga.exe, 00000005.00000002.3223167225.0000000000480000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: H`4H\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exC:P |
Source: 7bXVSwc9dp.exe, 00000000.00000003.2148970965.000000000149B000.00000004.00000020.00020000.00000000.sdmp, 7bXVSwc9dp.exe, 00000000.00000002.2150867701.000000000149C000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: ernalNameqemu-ga.exeH |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2155160486.00000000045AB000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: Interactive Brokers - GDCDYNVMware20,11696428655p |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2150906526.00000000014CB000.00000004.00000020.00020000.00000000.sdmp, 7bXVSwc9dp.exe, 00000000.00000002.2160002093.00000000059F0000.00000004.00000020.00020000.00000000.sdmp, qemu-ga.exe, 00000003.00000002.3222786269.0000000000D20000.00000004.00000020.00020000.00000000.sdmp, qemu-ga.exe, 00000003.00000002.3223012208.0000000000D5C000.00000004.00000020.00020000.00000000.sdmp, qemu-ga.exe, 00000003.00000002.3222653528.0000000000CFA000.00000004.00000010.00020000.00000000.sdmp, qemu-ga.exe, 00000003.00000002.3223012208.0000000000D50000.00000004.00000020.00020000.00000000.sdmp, qemu-ga.exe, 00000005.00000002.3223167225.0000000000489000.00000004.00000020.00020000.00000000.sdmp, qemu-ga.exe, 00000005.00000002.3222573802.000000000015A000.00000004.00000010.00020000.00000000.sdmp, qemu-ga.exe, 00000005.00000002.3223167225.0000000000480000.00000004.00000020.00020000.00000000.sdmp, qemu-ga.exe, 00000005.00000002.3223167225.00000000004EB000.00000004.00000020.00020000.00000000.sdmp, qemu-ga.exe, 00000005.00000002.3223981771.0000000000780000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exe |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2155160486.00000000044BB000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: secure.bankofamerica.comVMware20,11696428655|UE |
Source: qemu-ga.exe, 00000003.00000002.3224563673.0000000002E31000.00000004.00000800.00020000.00000000.sdmp, qemu-ga.exe, 00000005.00000002.3224439455.0000000002271000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: qemu-ga.exe2! |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2160159846.0000000005A76000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: \??\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\yj |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2164115712.00000000072B8000.00000004.00000020.00020000.00000000.sdmp, 7bXVSwc9dp.exe, 00000000.00000003.2149036097.00000000072B7000.00000004.00000020.00020000.00000000.sdmp, 7bXVSwc9dp.exe, 00000000.00000003.2148475586.00000000072AA000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: sers\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exee |
Source: qemu-ga.exe, 00000005.00000002.3223167225.00000000004EB000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: FQC:/Users/user/AppData/Roaming/Microsoft/Windows/Start Menu/Programs/Startup/qemu-ga.exe.configg& |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2152685133.0000000003877000.00000004.00000800.00020000.00000000.sdmp, qemu-ga.exe, 00000003.00000002.3225201926.00007FF848E14000.00000004.00000800.00020000.00000000.sdmp, qemu-ga.exe, 00000003.00000000.2148201842.0000000000962000.00000002.00000001.01000000.00000007.sdmp, qemu-ga.exe, 00000005.00000002.3225241930.00007FF848E34000.00000004.00000800.00020000.00000000.sdmp, qemu-ga.exe, 00000005.00000002.3223167225.00000000004EB000.00000004.00000020.00020000.00000000.sdmp, qemu-ga.exe.0.dr | Binary or memory string: qemu-ga |
Source: qemu-ga.exe, 00000003.00000002.3223012208.0000000000D5C000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\Users\user\AppData\Local\Microsoft\CLR_v4.0\UsageLogs\qemu-ga.exe.log |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2150191036.0000000001190000.00000004.00000020.00040000.00000000.sdmp | Binary or memory string: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exe\??\C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exeen-GBenen-USMyApplication.appbb. |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2155160486.00000000045AB000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: turbotax.intuit.comVMware20,11696428655t |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2160807057.0000000005ACE000.00000004.00000020.00020000.00000000.sdmp, 7bXVSwc9dp.exe, 00000000.00000003.2149088208.0000000005ACD000.00000004.00000020.00020000.00000000.sdmp, 7bXVSwc9dp.exe, 00000000.00000003.2148749486.0000000005AA1000.00000004.00000020.00020000.00000000.sdmp, 7bXVSwc9dp.exe, 00000000.00000002.2164115712.00000000072B8000.00000004.00000020.00020000.00000000.sdmp, 7bXVSwc9dp.exe, 00000000.00000003.2149036097.00000000072B7000.00000004.00000020.00020000.00000000.sdmp, 7bXVSwc9dp.exe, 00000000.00000002.2160159846.0000000005A76000.00000004.00000020.00020000.00000000.sdmp, 7bXVSwc9dp.exe, 00000000.00000003.2148475586.00000000072AA000.00000004.00000020.00020000.00000000.sdmp, 7bXVSwc9dp.exe, 00000000.00000002.2160584253.0000000005AA1000.00000004.00000020.00020000.00000000.sdmp, 7bXVSwc9dp.exe, 00000000.00000003.2148923577.0000000005AC1000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: qemu-ga.exeH |
Source: qemu-ga.exe, 00000003.00000002.3223012208.0000000000DC5000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:/Users/user/AppData/Roaming/Microsoft/Windows/Start%20Menu/Programs/Startup/qemu-ga.exe.configl |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2155160486.00000000045AB000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: Interactive Brokers - non-EU EuropeVMware20,11696428655 |
Source: qemu-ga.exe, 00000003.00000002.3223012208.0000000000DC5000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exen |
Source: qemu-ga.exe, 00000005.00000002.3223167225.00000000004EB000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: FQ\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exe.configL |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2160002093.00000000059F0000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: \Registry\Machine\Software\Classes\Applications\qemu-ga.exe |
Source: qemu-ga.exe, 00000003.00000002.3223012208.0000000000D5C000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exeh |
Source: 7bXVSwc9dp.exe, 00000000.00000003.2148970965.000000000149B000.00000004.00000020.00020000.00000000.sdmp, 7bXVSwc9dp.exe, 00000000.00000002.2150867701.000000000149C000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exee |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2155160486.00000000045AB000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: Interactive Brokers - HKVMware20,11696428655] |
Source: 7bXVSwc9dp.exe, 00000000.00000003.2148970965.000000000149B000.00000004.00000020.00020000.00000000.sdmp, 7bXVSwc9dp.exe, 00000000.00000002.2150867701.000000000149C000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: file//C:UsersuserAppDataRoamingMicrosoftWindowsStart%20MenuProgramsStartupqemu-ga.exe{HTx |
Source: qemu-ga.exe, 00000003.00000002.3223012208.0000000000DC5000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: qemu-ga.exee |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2155160486.00000000044BB000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: Interactive Brokers - COM.HKVMware20,11696428655 |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2155160486.00000000044BB000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: interactivebrokers.co.inVMware20,11696428655d |
Source: qemu-ga.exe, 00000003.00000002.3223012208.0000000000D5C000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exei |
Source: qemu-ga.exe, 00000003.00000002.3223012208.0000000000DBF000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: qemu-ga.exen |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2155160486.00000000044BB000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: netportal.hdfcbank.comVMware20,11696428655 |
Source: qemu-ga.exe, 00000003.00000002.3223012208.0000000000DC5000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: qemu-ga.exej |
Source: 7bXVSwc9dp.exe, 00000000.00000003.2148970965.000000000149B000.00000004.00000020.00020000.00000000.sdmp, 7bXVSwc9dp.exe, 00000000.00000002.2150867701.000000000149C000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start%20Menu\Programs\Startup\qemu-ga.exe^J7~ |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2155160486.00000000045AB000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: Test URL for global passwords blocklistVMware20,11696428655 |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2155160486.00000000045AB000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: Canara Transaction PasswordVMware20,11696428655x |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2155160486.00000000044BB000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: Canara Change Transaction PasswordVMware20,11696428655 |
Source: qemu-ga.exe, 00000003.00000002.3224563673.0000000002E31000.00000004.00000800.00020000.00000000.sdmp, qemu-ga.exe, 00000005.00000002.3224439455.0000000002271000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: `C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exe.config`_! |
Source: 7bXVSwc9dp.exe, 00000000.00000003.2148970965.000000000149B000.00000004.00000020.00020000.00000000.sdmp, 7bXVSwc9dp.exe, 00000000.00000002.2150867701.000000000149C000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: file//C:UsersuserAppDataRoamingMicrosoftWindowsStart%20MenuProgramsStartupqemu-ga.exeSN |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2150906526.00000000014CB000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: /C:/Users/user/AppData/Roaming/Microsoft/Windows/Start%20Menu/Programs/Startup/qemu-ga.exe |
Source: qemu-ga.exe, 00000003.00000002.3223012208.0000000000DC5000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: qemu-ga6 |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2150906526.00000000014CB000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: /C:/Users/user/AppData/Roaming/Microsoft/Windows/Start%20Menu/Programs/Startup/qemu-ga.exel |
Source: qemu-ga.exe, 00000003.00000002.3223012208.0000000000D50000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\Users\user\Desktop\C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exe"C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exe" C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exeWinsta0\Default |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2155160486.00000000044BB000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: outlook.office365.comVMware20,11696428655t |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2155160486.00000000045AB000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: Canara Transaction PasswordVMware20,11696428655} |
Source: qemu-ga.exe, 00000003.00000002.3223012208.0000000000D50000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\Windows\Temp\AslLog_shimengstate_qemu-ga.exe_2828.txt |
Source: qemu-ga.exe, 00000005.00000002.3223167225.00000000004EB000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: file:///C:/Users/user/AppData/Roaming/Microsoft/Windows/Start Menu/Programs/Startup/qemu-ga.exeig |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2155160486.00000000044BB000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: account.microsoft.com/profileVMware20,11696428655u |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2155160486.00000000044BB000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: Canara Transaction PasswordVMware20,11696428655} |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2150906526.00000000014CB000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: /C:/Users/user/AppData/Roaming/Microsoft/Windows/Start%20Menu/Programs/Startup/qemu-ga.exer |
Source: qemu-ga.exe, 00000005.00000002.3223981771.0000000000780000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: xC:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exe]v |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2155160486.00000000045AB000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: Interactive Brokers - EU East & CentralVMware20,11696428655 |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2150906526.00000000014CB000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exeF |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2155160486.00000000045AB000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: Canara Change Transaction PasswordVMware20,11696428655^ |
Source: qemu-ga.exe, 00000005.00000002.3223167225.0000000000480000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: QHC:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exe |
Source: qemu-ga.exe, 00000005.00000002.3223167225.0000000000489000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exeJ |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2160002093.00000000059F0000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exe@ |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2155160486.00000000045AB000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: www.interactivebrokers.comVMware20,11696428655} |
Source: qemu-ga.exe, 00000003.00000002.3223012208.0000000000D50000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\Windows\Temp\AslLog_ApphelpDebug_qemu-ga.exe_2828.txt P |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2155160486.00000000045AB000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: microsoft.visualstudio.comVMware20,11696428655x |
Source: qemu-ga.exe, 00000003.00000002.3223012208.0000000000D5C000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: \??\C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exe.config2.dll |
Source: 7bXVSwc9dp.exe, 00000000.00000003.2080444288.00000000014D6000.00000004.00000020.00020000.00000000.sdmp, 7bXVSwc9dp.exe, 00000000.00000003.2079482540.00000000014B7000.00000004.00000020.00020000.00000000.sdmp, 7bXVSwc9dp.exe, 00000000.00000002.2150906526.00000000014DB000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2155160486.00000000044BB000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: Canara Transaction PasswordVMware20,11696428655x |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2155160486.00000000044BB000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: outlook.office.comVMware20,11696428655s |
Source: qemu-ga.exe, 00000003.00000002.3223012208.0000000000D5C000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exe8 |
Source: qemu-ga.exe, 00000005.00000002.3223167225.00000000004EB000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: FQC:/Users/user/AppData/Roaming/Microsoft/Windows/Start%20Menu/Programs/Startup/qemu-ga.exe.config |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2152685133.0000000003877000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: $]qYC:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exe |
Source: qemu-ga.exe, 00000005.00000002.3223167225.0000000000489000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: Isers\user\AppData\Local\Microsoft\CLR_v4.0\UsageLogs\qemu- |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2155160486.00000000044BB000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: tasks.office.comVMware20,11696428655o |
Source: 7bXVSwc9dp.exe, 00000000.00000003.2148970965.000000000149B000.00000004.00000020.00020000.00000000.sdmp, 7bXVSwc9dp.exe, 00000000.00000002.2150867701.000000000149C000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: nalFilenameqemu-ga.exe0 |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2152685133.0000000003877000.00000004.00000800.00020000.00000000.sdmp, qemu-ga.exe, 00000003.00000000.2148201842.0000000000962000.00000002.00000001.01000000.00000007.sdmp, qemu-ga.exe.0.dr | Binary or memory string: <Module>qemu-gamscorlibThreadConsoleReadLineDebuggableAttributeComVisibleAttributeAssemblyTitleAttributeAssemblyTrademarkAttributeTargetFrameworkAttributeAssemblyFileVersionAttributeAssemblyConfigurationAttributeAssemblyDescriptionAttributeCompilationRelaxationsAttributeAssemblyProductAttributeAssemblyCopyrightAttributeAssemblyCompanyAttributeRuntimeCompatibilityAttributeqemu-ga.exeSystem.ThreadingSystem.Runtime.VersioningProgramSystemMainSystem.ReflectionSleep.ctorSystem.DiagnosticsSystem.Runtime.InteropServicesSystem.Runtime.CompilerServicesDebuggingModesargsObject |
Source: qemu-ga.exe, 00000005.00000002.3223167225.0000000000489000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exe2 |
Source: qemu-ga.exe, 00000005.00000002.3223167225.0000000000489000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: qemu-ga.exenalfo0 |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2155160486.00000000044BB000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: Interactive Brokers - GDCDYNVMware20,11696428655p |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2155160486.00000000044BB000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: Interactive Brokers - non-EU EuropeVMware20,11696428655 |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2150906526.00000000014CB000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: /C:/Users/user/AppData/Roaming/Microsoft/Windows/Start%20Menu/Programs/Startup/qemu-ga.exeS |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2160002093.00000000059F0000.00000004.00000020.00020000.00000000.sdmp, qemu-ga.exe, 00000003.00000002.3223012208.0000000000D5C000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exe, |
Source: qemu-ga.exe, 00000003.00000002.3223012208.0000000000DC5000.00000004.00000020.00020000.00000000.sdmp, qemu-ga.exe, 00000005.00000002.3223167225.00000000004EB000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exe.configg |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2155160486.00000000044BB000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: trackpan.utiitsl.comVMware20,11696428655h |
Source: qemu-ga.exe, 00000003.00000002.3223012208.0000000000DC5000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exe* |
Source: qemu-ga.exe, 00000005.00000002.3223167225.00000000004EB000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: Pqemu-ga.exe |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2155160486.00000000044BB000.00000004.00000800.00020000.00000000.sdmp | Binary or memory string: bankofamerica.comVMware20,11696428655x |
Source: 7bXVSwc9dp.exe, 00000000.00000002.2160002093.00000000059F0000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\qemu-ga.exe35/t |