Source: |
Binary string: C:\Windows\mscorlib.pdbpdblib.pdb source: LHA9oUEAwZ.exe, 00000002.00000002.3245574998.000000001BFE3000.00000004.00000020.00020000.00000000.sdmp |
Source: |
Binary string: Microsoft.VisualBasic.ni.pdb source: WER8909.tmp.dmp.12.dr |
Source: |
Binary string: System.Xml.ni.pdb source: WER8909.tmp.dmp.12.dr |
Source: |
Binary string: \??\C:\Windows\dll\mscorlib.pdb source: LHA9oUEAwZ.exe, 00000002.00000002.3245574998.000000001BFE3000.00000004.00000020.00020000.00000000.sdmp |
Source: |
Binary string: System.ni.pdbRSDS source: WER8909.tmp.dmp.12.dr |
Source: |
Binary string: System.Windows.Forms.ni.pdb source: WER8909.tmp.dmp.12.dr |
Source: |
Binary string: System.Drawing.ni.pdb source: WER8909.tmp.dmp.12.dr |
Source: |
Binary string: System.Configuration.ni.pdb source: WER8909.tmp.dmp.12.dr |
Source: |
Binary string: mscorlib.pdbcorlib.pdbpdblib.pdbC_64\mscorlib\v4.0_4.0.0.0__b77a5c561934e089\mscorlib.pdb source: LHA9oUEAwZ.exe, 00000002.00000002.3246366236.000000001C818000.00000004.00000010.00020000.00000000.sdmp |
Source: |
Binary string: mscorlib.ni.pdbRSDS7^3l source: WER8909.tmp.dmp.12.dr |
Source: |
Binary string: mscorlib.pdb0 source: WER8909.tmp.dmp.12.dr |
Source: |
Binary string: \??\C:\Windows\symbols\dll\mscorlib.pdb! source: LHA9oUEAwZ.exe, 00000002.00000002.3245967090.000000001C032000.00000004.00000020.00020000.00000000.sdmp |
Source: |
Binary string: Microsoft.VisualBasic.ni.pdbRSDS& source: WER8909.tmp.dmp.12.dr |
Source: |
Binary string: System.Configuration.pdb source: WER8909.tmp.dmp.12.dr |
Source: |
Binary string: symbols\dll\mscorlib.pdbpdb` source: LHA9oUEAwZ.exe, 00000002.00000002.3246366236.000000001C818000.00000004.00000010.00020000.00000000.sdmp |
Source: |
Binary string: System.Drawing.ni.pdbRSDS source: WER8909.tmp.dmp.12.dr |
Source: |
Binary string: \??\C:\Users\user\Desktop\LHA9oUEAwZ.PDBcesV source: LHA9oUEAwZ.exe, 00000002.00000002.3245967090.000000001C032000.00000004.00000020.00020000.00000000.sdmp |
Source: |
Binary string: System.Xml.pdb source: WER8909.tmp.dmp.12.dr |
Source: |
Binary string: System.pdb source: WER8909.tmp.dmp.12.dr |
Source: |
Binary string: 0C:\Windows\mscorlib.pdb source: LHA9oUEAwZ.exe, 00000002.00000002.3246366236.000000001C818000.00000004.00000010.00020000.00000000.sdmp |
Source: |
Binary string: System.Xml.ni.pdbRSDS# source: WER8909.tmp.dmp.12.dr |
Source: |
Binary string: Microsoft.VisualBasic.pdb source: WER8909.tmp.dmp.12.dr |
Source: |
Binary string: System.Core.ni.pdb source: WER8909.tmp.dmp.12.dr |
Source: |
Binary string: System.Windows.Forms.pdb source: WER8909.tmp.dmp.12.dr |
Source: |
Binary string: \??\C:\Windows\Microsoft.Net\assembly\GAC_64\mscorlib\v4.0_4.0.0.0__b77a5c561934e089\mscorlib.pdb source: LHA9oUEAwZ.exe, 00000002.00000002.3242499109.00000000013D6000.00000004.00000020.00020000.00000000.sdmp |
Source: |
Binary string: System.Drawing.pdbp source: WER8909.tmp.dmp.12.dr |
Source: |
Binary string: mscorlib.pdb source: LHA9oUEAwZ.exe, 00000002.00000002.3245967090.000000001C032000.00000004.00000020.00020000.00000000.sdmp, LHA9oUEAwZ.exe, 00000002.00000002.3242499109.00000000013D6000.00000004.00000020.00020000.00000000.sdmp, LHA9oUEAwZ.exe, 00000002.00000002.3245574998.000000001BFE3000.00000004.00000020.00020000.00000000.sdmp, WER8909.tmp.dmp.12.dr |
Source: |
Binary string: System.Management.ni.pdbRSDSJ< source: WER8909.tmp.dmp.12.dr |
Source: |
Binary string: System.Windows.Forms.ni.pdbRSDS source: WER8909.tmp.dmp.12.dr |
Source: |
Binary string: System.Core.pdb; source: WER8909.tmp.dmp.12.dr |
Source: |
Binary string: System.Management.pdb source: WER8909.tmp.dmp.12.dr |
Source: |
Binary string: System.Drawing.pdb source: WER8909.tmp.dmp.12.dr |
Source: |
Binary string: mscorlib.ni.pdb source: WER8909.tmp.dmp.12.dr |
Source: |
Binary string: System.Management.ni.pdb source: WER8909.tmp.dmp.12.dr |
Source: |
Binary string: \??\C:\Windows\mscorlib.pdb source: LHA9oUEAwZ.exe, 00000002.00000002.3245967090.000000001C032000.00000004.00000020.00020000.00000000.sdmp |
Source: |
Binary string: System.Core.pdb source: WER8909.tmp.dmp.12.dr |
Source: |
Binary string: System.Configuration.ni.pdbRSDScUN source: WER8909.tmp.dmp.12.dr |
Source: |
Binary string: indoC:\Windows\mscorlib.pdb source: LHA9oUEAwZ.exe, 00000002.00000002.3246366236.000000001C818000.00000004.00000010.00020000.00000000.sdmp |
Source: |
Binary string: System.ni.pdb source: WER8909.tmp.dmp.12.dr |
Source: |
Binary string: .pdbA source: LHA9oUEAwZ.exe, 00000002.00000002.3246366236.000000001C818000.00000004.00000010.00020000.00000000.sdmp |
Source: |
Binary string: System.Core.ni.pdbRSDS source: WER8909.tmp.dmp.12.dr |
Source: C:\Users\user\Desktop\LHA9oUEAwZ.exe |
Section loaded: mscoree.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LHA9oUEAwZ.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LHA9oUEAwZ.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LHA9oUEAwZ.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LHA9oUEAwZ.exe |
Section loaded: vcruntime140_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LHA9oUEAwZ.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LHA9oUEAwZ.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LHA9oUEAwZ.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LHA9oUEAwZ.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LHA9oUEAwZ.exe |
Section loaded: cryptsp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LHA9oUEAwZ.exe |
Section loaded: rsaenh.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LHA9oUEAwZ.exe |
Section loaded: cryptbase.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LHA9oUEAwZ.exe |
Section loaded: wbemcomn.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LHA9oUEAwZ.exe |
Section loaded: amsi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LHA9oUEAwZ.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LHA9oUEAwZ.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LHA9oUEAwZ.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LHA9oUEAwZ.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LHA9oUEAwZ.exe |
Section loaded: rasapi32.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LHA9oUEAwZ.exe |
Section loaded: rasman.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LHA9oUEAwZ.exe |
Section loaded: rtutils.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LHA9oUEAwZ.exe |
Section loaded: mswsock.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LHA9oUEAwZ.exe |
Section loaded: winhttp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LHA9oUEAwZ.exe |
Section loaded: ondemandconnroutehelper.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LHA9oUEAwZ.exe |
Section loaded: iphlpapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LHA9oUEAwZ.exe |
Section loaded: dhcpcsvc6.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LHA9oUEAwZ.exe |
Section loaded: dhcpcsvc.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LHA9oUEAwZ.exe |
Section loaded: dnsapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LHA9oUEAwZ.exe |
Section loaded: winnsi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LHA9oUEAwZ.exe |
Section loaded: rasadhlp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LHA9oUEAwZ.exe |
Section loaded: fwpuclnt.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LHA9oUEAwZ.exe |
Section loaded: sxs.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LHA9oUEAwZ.exe |
Section loaded: mpr.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LHA9oUEAwZ.exe |
Section loaded: scrrun.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LHA9oUEAwZ.exe |
Section loaded: propsys.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LHA9oUEAwZ.exe |
Section loaded: linkinfo.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LHA9oUEAwZ.exe |
Section loaded: ntshrui.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LHA9oUEAwZ.exe |
Section loaded: srvcli.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\LHA9oUEAwZ.exe |
Section loaded: cscapi.dll |
Jump to behavior |
Source: |
Binary string: C:\Windows\mscorlib.pdbpdblib.pdb source: LHA9oUEAwZ.exe, 00000002.00000002.3245574998.000000001BFE3000.00000004.00000020.00020000.00000000.sdmp |
Source: |
Binary string: Microsoft.VisualBasic.ni.pdb source: WER8909.tmp.dmp.12.dr |
Source: |
Binary string: System.Xml.ni.pdb source: WER8909.tmp.dmp.12.dr |
Source: |
Binary string: \??\C:\Windows\dll\mscorlib.pdb source: LHA9oUEAwZ.exe, 00000002.00000002.3245574998.000000001BFE3000.00000004.00000020.00020000.00000000.sdmp |
Source: |
Binary string: System.ni.pdbRSDS source: WER8909.tmp.dmp.12.dr |
Source: |
Binary string: System.Windows.Forms.ni.pdb source: WER8909.tmp.dmp.12.dr |
Source: |
Binary string: System.Drawing.ni.pdb source: WER8909.tmp.dmp.12.dr |
Source: |
Binary string: System.Configuration.ni.pdb source: WER8909.tmp.dmp.12.dr |
Source: |
Binary string: mscorlib.pdbcorlib.pdbpdblib.pdbC_64\mscorlib\v4.0_4.0.0.0__b77a5c561934e089\mscorlib.pdb source: LHA9oUEAwZ.exe, 00000002.00000002.3246366236.000000001C818000.00000004.00000010.00020000.00000000.sdmp |
Source: |
Binary string: mscorlib.ni.pdbRSDS7^3l source: WER8909.tmp.dmp.12.dr |
Source: |
Binary string: mscorlib.pdb0 source: WER8909.tmp.dmp.12.dr |
Source: |
Binary string: \??\C:\Windows\symbols\dll\mscorlib.pdb! source: LHA9oUEAwZ.exe, 00000002.00000002.3245967090.000000001C032000.00000004.00000020.00020000.00000000.sdmp |
Source: |
Binary string: Microsoft.VisualBasic.ni.pdbRSDS& source: WER8909.tmp.dmp.12.dr |
Source: |
Binary string: System.Configuration.pdb source: WER8909.tmp.dmp.12.dr |
Source: |
Binary string: symbols\dll\mscorlib.pdbpdb` source: LHA9oUEAwZ.exe, 00000002.00000002.3246366236.000000001C818000.00000004.00000010.00020000.00000000.sdmp |
Source: |
Binary string: System.Drawing.ni.pdbRSDS source: WER8909.tmp.dmp.12.dr |
Source: |
Binary string: \??\C:\Users\user\Desktop\LHA9oUEAwZ.PDBcesV source: LHA9oUEAwZ.exe, 00000002.00000002.3245967090.000000001C032000.00000004.00000020.00020000.00000000.sdmp |
Source: |
Binary string: System.Xml.pdb source: WER8909.tmp.dmp.12.dr |
Source: |
Binary string: System.pdb source: WER8909.tmp.dmp.12.dr |
Source: |
Binary string: 0C:\Windows\mscorlib.pdb source: LHA9oUEAwZ.exe, 00000002.00000002.3246366236.000000001C818000.00000004.00000010.00020000.00000000.sdmp |
Source: |
Binary string: System.Xml.ni.pdbRSDS# source: WER8909.tmp.dmp.12.dr |
Source: |
Binary string: Microsoft.VisualBasic.pdb source: WER8909.tmp.dmp.12.dr |
Source: |
Binary string: System.Core.ni.pdb source: WER8909.tmp.dmp.12.dr |
Source: |
Binary string: System.Windows.Forms.pdb source: WER8909.tmp.dmp.12.dr |
Source: |
Binary string: \??\C:\Windows\Microsoft.Net\assembly\GAC_64\mscorlib\v4.0_4.0.0.0__b77a5c561934e089\mscorlib.pdb source: LHA9oUEAwZ.exe, 00000002.00000002.3242499109.00000000013D6000.00000004.00000020.00020000.00000000.sdmp |
Source: |
Binary string: System.Drawing.pdbp source: WER8909.tmp.dmp.12.dr |
Source: |
Binary string: mscorlib.pdb source: LHA9oUEAwZ.exe, 00000002.00000002.3245967090.000000001C032000.00000004.00000020.00020000.00000000.sdmp, LHA9oUEAwZ.exe, 00000002.00000002.3242499109.00000000013D6000.00000004.00000020.00020000.00000000.sdmp, LHA9oUEAwZ.exe, 00000002.00000002.3245574998.000000001BFE3000.00000004.00000020.00020000.00000000.sdmp, WER8909.tmp.dmp.12.dr |
Source: |
Binary string: System.Management.ni.pdbRSDSJ< source: WER8909.tmp.dmp.12.dr |
Source: |
Binary string: System.Windows.Forms.ni.pdbRSDS source: WER8909.tmp.dmp.12.dr |
Source: |
Binary string: System.Core.pdb; source: WER8909.tmp.dmp.12.dr |
Source: |
Binary string: System.Management.pdb source: WER8909.tmp.dmp.12.dr |
Source: |
Binary string: System.Drawing.pdb source: WER8909.tmp.dmp.12.dr |
Source: |
Binary string: mscorlib.ni.pdb source: WER8909.tmp.dmp.12.dr |
Source: |
Binary string: System.Management.ni.pdb source: WER8909.tmp.dmp.12.dr |
Source: |
Binary string: \??\C:\Windows\mscorlib.pdb source: LHA9oUEAwZ.exe, 00000002.00000002.3245967090.000000001C032000.00000004.00000020.00020000.00000000.sdmp |
Source: |
Binary string: System.Core.pdb source: WER8909.tmp.dmp.12.dr |
Source: |
Binary string: System.Configuration.ni.pdbRSDScUN source: WER8909.tmp.dmp.12.dr |
Source: |
Binary string: indoC:\Windows\mscorlib.pdb source: LHA9oUEAwZ.exe, 00000002.00000002.3246366236.000000001C818000.00000004.00000010.00020000.00000000.sdmp |
Source: |
Binary string: System.ni.pdb source: WER8909.tmp.dmp.12.dr |
Source: |
Binary string: .pdbA source: LHA9oUEAwZ.exe, 00000002.00000002.3246366236.000000001C818000.00000004.00000010.00020000.00000000.sdmp |
Source: |
Binary string: System.Core.ni.pdbRSDS source: WER8909.tmp.dmp.12.dr |
Source: LHA9oUEAwZ.exe, p1IG6OHEpiNB43wrLsWuNu.cs |
.Net Code: NewLateBinding.LateCall(obj, (Type)null, "Invoke", new object[2]{null,new object[5]{gHAhN6cuIY6jdHAG5jiXIq._7djAdP40ZQYRLytyg6z4ww,gHAhN6cuIY6jdHAG5jiXIq.vNT9HESZs6wzYpQlnpv9bQ,gHAhN6cuIY6jdHAG5jiXIq.qqnQUu51giIhhiInLWaAZA,gHAhN6cuIY6jdHAG5jiXIq.ZksRuESs0HayxxFeOtjxnI,p0YNdbZlrOpuCNRE0edav2KYSP4XGWPn8wRjA9ie.bAyk0h8Ob84GvPhMEK10FPS3hfAR5zxBzUIzZuA5CHsTB1qcduUBKcsqHkHEdWXmCzAR4RLD()}}, (string[])null, (Type[])null, (bool[])null, true) |
Source: LHA9oUEAwZ.exe, p1IG6OHEpiNB43wrLsWuNu.cs |
.Net Code: NewLateBinding.LateCall(obj, (Type)null, "Invoke", new object[2]{null,new object[2]{MiSCZ88ENHevWMQO4fY1UCcrlo63AM3Btc564hZJhFUBFmH4LxXFlSQ[2],p0YNdbZlrOpuCNRE0edav2KYSP4XGWPn8wRjA9ie._9kcMNmeih7RUdhGKDbWewdtAH4wh5a4IOaa2CiNxlX4mFPxFWP7yfoUe6nikb2uyrC0NZ6N9(Convert.FromBase64String(MiSCZ88ENHevWMQO4fY1UCcrlo63AM3Btc564hZJhFUBFmH4LxXFlSQ[3]))}}, (string[])null, (Type[])null, (bool[])null, true) |
Source: LHA9oUEAwZ.exe, p1IG6OHEpiNB43wrLsWuNu.cs |
.Net Code: NewLateBinding.LateCall(obj, (Type)null, "Invoke", new object[2]{null,new object[1] { MiSCZ88ENHevWMQO4fY1UCcrlo63AM3Btc564hZJhFUBFmH4LxXFlSQ[2] }}, (string[])null, (Type[])null, (bool[])null, true) |
Source: testnt.exe.2.dr, p1IG6OHEpiNB43wrLsWuNu.cs |
.Net Code: NewLateBinding.LateCall(obj, (Type)null, "Invoke", new object[2]{null,new object[5]{gHAhN6cuIY6jdHAG5jiXIq._7djAdP40ZQYRLytyg6z4ww,gHAhN6cuIY6jdHAG5jiXIq.vNT9HESZs6wzYpQlnpv9bQ,gHAhN6cuIY6jdHAG5jiXIq.qqnQUu51giIhhiInLWaAZA,gHAhN6cuIY6jdHAG5jiXIq.ZksRuESs0HayxxFeOtjxnI,p0YNdbZlrOpuCNRE0edav2KYSP4XGWPn8wRjA9ie.bAyk0h8Ob84GvPhMEK10FPS3hfAR5zxBzUIzZuA5CHsTB1qcduUBKcsqHkHEdWXmCzAR4RLD()}}, (string[])null, (Type[])null, (bool[])null, true) |
Source: testnt.exe.2.dr, p1IG6OHEpiNB43wrLsWuNu.cs |
.Net Code: NewLateBinding.LateCall(obj, (Type)null, "Invoke", new object[2]{null,new object[2]{MiSCZ88ENHevWMQO4fY1UCcrlo63AM3Btc564hZJhFUBFmH4LxXFlSQ[2],p0YNdbZlrOpuCNRE0edav2KYSP4XGWPn8wRjA9ie._9kcMNmeih7RUdhGKDbWewdtAH4wh5a4IOaa2CiNxlX4mFPxFWP7yfoUe6nikb2uyrC0NZ6N9(Convert.FromBase64String(MiSCZ88ENHevWMQO4fY1UCcrlo63AM3Btc564hZJhFUBFmH4LxXFlSQ[3]))}}, (string[])null, (Type[])null, (bool[])null, true) |
Source: testnt.exe.2.dr, p1IG6OHEpiNB43wrLsWuNu.cs |
.Net Code: NewLateBinding.LateCall(obj, (Type)null, "Invoke", new object[2]{null,new object[1] { MiSCZ88ENHevWMQO4fY1UCcrlo63AM3Btc564hZJhFUBFmH4LxXFlSQ[2] }}, (string[])null, (Type[])null, (bool[])null, true) |
Source: LHA9oUEAwZ.exe, wbEY1BBMTLuOQnjFsb4qENNVloKJ7EbGgcClTBhaBFyHCKdc3xNJINRjl6XhJMMERGuEOGTH.cs |
High entropy of concatenated method names: 'd4RIEYOE889BObHVS9EZ3BUv0WaONwcdQqrg6M1khN8kyFgethX0kg2YmaNRARXzNc7CCKWi', 'TZtcforiMD8eG0MNVLDDyZ47lIAXs8DV3HfplJR5OmSCEMy3aTAmPgPpKaGUACq9xIkRAzyC', 'DOfcHqAO2tYhZYdneKIDsPUeGoj0vOl3gWSocNDAg9dsX67ImVAyebvif', '_5v8hJph8viLMCz9kmDSRD9SrcH6my6LQvQzx4webg5PANXahB7p971TsgK0Xe9rwGes69yYErKybrM5JiT', 'rVchSt4iuWLnfMB90MmS3WRGWMTSA5xBRzC6FkxLPDYYCKh63Ek80IpP4a0g72rgLjHcWLcQa0OZSpPiGz', 'VH9HoxrmmU2onlovjCwmP4g1cwYZkaJCXGoYJVl9rAZN2VN8faxpqT7QfLqhuPlHWkXKPVzZ128YDtZc8C', 'hag6EjJ8okvTFbLyha99y2fhg1V52cgCMXJVFY2ikzXSDUnIxouEY66Z9S6KBy7hWvXCPILu46TJqHNtCt', 'uxlb5DY1WY63r3pZrUr7XhJ19nmQsTHuut5zlhJuI0yOiEJvSXK4iwZ6wiTbEEuIcnB', '_9JhcsGoKT2OnbqCpMBgkRWF7yFEdfd5SCPMETTpsiyw7Y1PL4xsbyGsOP9YNF6SUEFE', 'xE2cjQPo0nyAYLEV1tTOAi8qMqv7zKtusaNYWkZdNoyeaIG2nylWYikfDJzQg7qJSjw' |
Source: LHA9oUEAwZ.exe, gHAhN6cuIY6jdHAG5jiXIq.cs |
High entropy of concatenated method names: 'rSjPBjbxGoRHu62t7wtWvK01R7Nt1EckwWbjTDb4AX1eirpkTjBzOLK6pgYcmV9XbUIV5qj6dKsDRcCiU0Eaik2QX5', 'uSOiBOMWi0zufTHPCsbFCNH26LlNhdPJjKiJkhS9nM38X3Er14g15PQFhz8K67aab9U7L3LFjNjQpd6Dd8DRXhGvrE', 'wXAMTbTFKSXrM0fKS4KbfOIIpEQzNOruIDqxrsDRULwrxYmCXiejRCyPQPUNsewGNCgcUjdcy1DAVx0W75DlcGCCGK', '_1gZDAoCisI1KZPD4MNWamT0vSvwkHpwz23cteXIBRDQLojFUoJYUfQ4dxt7EiWvARFAeCHGbyfQ3aXr6aQ0HpQznDk' |
Source: LHA9oUEAwZ.exe, caUeBYZfVwmeWecKlXVQ7tW3etHpDGaIrrzwqecG62TTOZYow1TXq8sSeP37gmRTdIXugIj983q5D20v.cs |
High entropy of concatenated method names: 'Equals', 'GetHashCode', 'GetType', 'ToString', 'Create__Instance__', 'Dispose__Instance__', 'kpBfQwWJ33Pg5WY5cTv1MT8QZJJeOExhDvE2MyW5vHe7htS4JqeBjo07ZEVBDSpneKdS5FUXrdm9AoupxeMVvFP4sj', 'eSf5Ji2J5t01WKHAZbTomxOLs5CfQAJGnHtPykEAdvcOW5M2KcgTe84qNBX8dsrWXgd6Gz8cWZF2tPtzIlJvtgMCuu', 'rhfua03rpysKziOJqCjWbfz0kAeLmL7kBTuHwyONb1KBKWTdmAkFaNyamnydFb1lpDl3a2VkRfG1dO3tImeGSr82oT', '_2cZOmdFrO9vD3sm3X7bn34SUBz1Gc67rNssT6yFyMzwhTb9pRKwzfqcK40inbtC0nrEsVBsBWFdU2LxJxKCs1UQcUR' |
Source: LHA9oUEAwZ.exe, bh5AgBmmct9rNksQHppG7G.cs |
High entropy of concatenated method names: 'zqn1SQUrFUMgHieXIorpxP', 'c04k38AmW1WWkBG1Xj3wvH', 'ZG8iCN2A0lEn1L6ydnzK42', 'gHmFGh8HlX6Zb4pRCESCiG', 'KHX41dZ3v4ndWAiAX7Ntew', 'gUGVVE4W2wDAXYH2i054eE', 'owXtj5QlhgpYpQdHlm58mq', 'ohfsz38hrN83Rk2XjK4n0u', 'cMTGVh7QlqnpqtS4THFPSH', 'z0AABSExIRPLOFe6d4YQGl' |
Source: LHA9oUEAwZ.exe, WIuR1rCg9OABqm2Ov6Vai2Lg9nFtnB4GBfFpoudo.cs |
High entropy of concatenated method names: 'FNHzWngLomEA2m0s7IkHnKswZPPuxbx9DqImvxXC', 'ym3amq6ICtFEpNGE25s8jQ096Z0jTdy7wWYGlWGGymDG2Zt3gT', 'zEBPDZSKVOzQ5zlq7Ri0JkZLP0DH0SROGSexfv8P1vtePgTltl', 'iNwVIlJ1tjsdxiCHWDvBpTlhvrvIlYZMw96bx0dsn1cqc8Ejzw', 'rDi3OHpasRrnDFdZG2IPJj5sBAJxI5zZjKMR8eTisj5fRHqyde' |
Source: LHA9oUEAwZ.exe, p1IG6OHEpiNB43wrLsWuNu.cs |
High entropy of concatenated method names: 'u5yD0BUm2PcSw0iB0GO3cP', 'oPAJ4NA3yjtlpSliHpVRHy', 'mDEbck9Dl7iLQmmmTiw4D5', '_7Z84Hk2AYvRgn54bPqWxxH', 'Mv3s3rXUYJDv1MlRaV5NZxp1lrZYGvPAA0ykgRtUbGEETMn7PiLRJtx', '_77YyemyOEFU7itfJCUsjpOx8gcqGs8FUQuQbA9o8ta3m6IZGpENCEdn', 'sHvtH3qz9BfXf8zkENDR7dEgvIfjGrGSPeJGEtatrfFc06ORCLo5ldj', '_0juZ9cgK4ayrYhpT7hhADZrbXqLW4FBWPOFjBSBSa4ZCUS5BFAoeDEI', 'wMVjv6gIyHStMsg1FglMtkNzcQO4BpY256l7vPnLEsfsR6NLveTsN8R', 'UIfHerstaAUFl4huhLMnguGkk7zmMhlt614liUFezUqNobGa6g6vH3x' |
Source: LHA9oUEAwZ.exe, p0YNdbZlrOpuCNRE0edav2KYSP4XGWPn8wRjA9ie.cs |
High entropy of concatenated method names: 'Wk5Rb1ThVxurWW4bR1FzYtajBSNZ3f3cYDGvN7KK', 'OE6M0rFV82DhFKGwpEZVAxuiE8p1tK1ipzXidSoY', 'Erk5rdelfOjiuryrno1aRfle7byjXfKUxM1IIYEu', 'uNO52gJl8XiflpctQQdzmbqRKQejB1mbrjnEehsD', 'c9zSsXTzShpzMwYex5arwnBbukAePQnQ4WeJe3Ax', 'zyjJyxkzs2oh0kJZ9Y4EqfRAZDI4Uwi0aea8ZOrX', 'Qavs0kE80dO9dbK005T8Q8cLCd044xtxvwy7y0mZ', 'xSogTl37TYlau03YlfU1eGjgqwst6VUgqvUruZ0E', 'UZRKZV3Dt0DNJZBzWiRF95ZUl55fQaz6d7JbqDRX', '_85FPJGNAtQhSjWYn0FzmTXtkBRhzY9oQUFKTjHdH' |
Source: LHA9oUEAwZ.exe, HSv2czNGQ5ZtVacsXcu1DvtdZfn74sbSWa0KpGeNi8UwefY4Ro8oGJD.cs |
High entropy of concatenated method names: 'rQ89f38m37zZhF5nfv6r8KS0hp8uP8FGlG9AqgdmUIkjHvZRSEBgNNI', '_3vrFleZlqfNAg5HVW', 'fkj2QBHwu6XlJY3Hj', 'QoIvAOGEAuZz19ONd', 'PabkqXCUaLQLay6wi' |
Source: LHA9oUEAwZ.exe, A6KJM5OnMj4l8Zs9YLwXRUrIXz7tx6TKgT2mMjtx.cs |
High entropy of concatenated method names: '_6b35A2axSWdonI5on3vsc92D2xbKfFvyKpIExQaY', 'pD752BHE35OB8WiKtQr0p60F3fC0avicmI5yc9k0', 'MIa5PswOlrNKDMMa2MtCLkv8JmGtgOBwVZ0JWBKg', 'WP1FEFB4Q0dzyFiN1WGA2farZLuhgXlcgyS4w0p8', 'aN8VjZcHu2u8Rmtbv', 'TJhDrOu62xHF82TLB', 's57B1kOnf10WLh9Kf', 'U2nIHzR0ooxGpXetJ', '_5uvptiCCabgcq63Ok', 'PCwTgXZAzcLFF2yAy' |
Source: LHA9oUEAwZ.exe, pWFohs8uFmHTfaAhVw9lC9.cs |
High entropy of concatenated method names: 'sIEUBVVBXhvymuoXBq3b8l', '_3a9P2xLTv2K5DSI1e6EgiN', 'x7AF0fxrGevqKUlbD2cq16', 'RookwFJp4qwU93FcPJHhs9', 'WEmXE5AIt2cD3OBQCaKM4i', 'AX0TTbOTnCbv0dJZkxNakn', '_7mSDokXU63yRJoAkHZffOf', 'xMmJ0OlkoEPrEXhP9GEKCD', 'jHFzismFBt9yWCZ9fGZjnY', '_4Oqr7SZUXA9Ugg6ixxP9AO' |
Source: LHA9oUEAwZ.exe, nAqjKWnahmZlgbIrYsgeU9lRcu9NpU73tOyeIJVmtQ5RNbG4wKEHQmh.cs |
High entropy of concatenated method names: 'ecISpUVC7UxhPRPd30VapydpSI3nLfDU5zGNeurGECmvF6f80F7gLee', 'QPr3dnXNquZaXW00q8qX0kwzlalzdv5WD40SmZ2LveeYB91exVAJO2I', 'QkVvTmVgSKYKr7VP9tcaLfRxRuOQ8TBP7XFtqGKFjWQWcXbmZXm0XvO', '_8H4z0sovpRkdAbqc3aAZFRhMun7X0O8z3K5AbYLMBgWRNF6nXHQ3gSj', 'JVlMsxOMPrYBrJus3mp3o2MoVofS3QV3NVnZ3QFFRbnZbSryG6RJJNh', 'oDJOt48iSKv0kcDhtOSbYR4rwZBi41caMtJzs2OROH0PF9xcp9uiTXK', 'X5karREfXDJrjLMfdIVTqRy4MGXUKCSlk0lA6BLH', 'O0Z7l9kZro8pyJuwJz6TQCgkkURsYV5irdxZS62c', 'JIwTQcoqzczSqlagZlMQziGeR9WoolecjR0gmTSg', 'E7GV89f8RBAgZqKGmAmkarjRsclTRcq2f5LmflzP' |
Source: testnt.exe.2.dr, wbEY1BBMTLuOQnjFsb4qENNVloKJ7EbGgcClTBhaBFyHCKdc3xNJINRjl6XhJMMERGuEOGTH.cs |
High entropy of concatenated method names: 'd4RIEYOE889BObHVS9EZ3BUv0WaONwcdQqrg6M1khN8kyFgethX0kg2YmaNRARXzNc7CCKWi', 'TZtcforiMD8eG0MNVLDDyZ47lIAXs8DV3HfplJR5OmSCEMy3aTAmPgPpKaGUACq9xIkRAzyC', 'DOfcHqAO2tYhZYdneKIDsPUeGoj0vOl3gWSocNDAg9dsX67ImVAyebvif', '_5v8hJph8viLMCz9kmDSRD9SrcH6my6LQvQzx4webg5PANXahB7p971TsgK0Xe9rwGes69yYErKybrM5JiT', 'rVchSt4iuWLnfMB90MmS3WRGWMTSA5xBRzC6FkxLPDYYCKh63Ek80IpP4a0g72rgLjHcWLcQa0OZSpPiGz', 'VH9HoxrmmU2onlovjCwmP4g1cwYZkaJCXGoYJVl9rAZN2VN8faxpqT7QfLqhuPlHWkXKPVzZ128YDtZc8C', 'hag6EjJ8okvTFbLyha99y2fhg1V52cgCMXJVFY2ikzXSDUnIxouEY66Z9S6KBy7hWvXCPILu46TJqHNtCt', 'uxlb5DY1WY63r3pZrUr7XhJ19nmQsTHuut5zlhJuI0yOiEJvSXK4iwZ6wiTbEEuIcnB', '_9JhcsGoKT2OnbqCpMBgkRWF7yFEdfd5SCPMETTpsiyw7Y1PL4xsbyGsOP9YNF6SUEFE', 'xE2cjQPo0nyAYLEV1tTOAi8qMqv7zKtusaNYWkZdNoyeaIG2nylWYikfDJzQg7qJSjw' |
Source: testnt.exe.2.dr, gHAhN6cuIY6jdHAG5jiXIq.cs |
High entropy of concatenated method names: 'rSjPBjbxGoRHu62t7wtWvK01R7Nt1EckwWbjTDb4AX1eirpkTjBzOLK6pgYcmV9XbUIV5qj6dKsDRcCiU0Eaik2QX5', 'uSOiBOMWi0zufTHPCsbFCNH26LlNhdPJjKiJkhS9nM38X3Er14g15PQFhz8K67aab9U7L3LFjNjQpd6Dd8DRXhGvrE', 'wXAMTbTFKSXrM0fKS4KbfOIIpEQzNOruIDqxrsDRULwrxYmCXiejRCyPQPUNsewGNCgcUjdcy1DAVx0W75DlcGCCGK', '_1gZDAoCisI1KZPD4MNWamT0vSvwkHpwz23cteXIBRDQLojFUoJYUfQ4dxt7EiWvARFAeCHGbyfQ3aXr6aQ0HpQznDk' |
Source: testnt.exe.2.dr, caUeBYZfVwmeWecKlXVQ7tW3etHpDGaIrrzwqecG62TTOZYow1TXq8sSeP37gmRTdIXugIj983q5D20v.cs |
High entropy of concatenated method names: 'Equals', 'GetHashCode', 'GetType', 'ToString', 'Create__Instance__', 'Dispose__Instance__', 'kpBfQwWJ33Pg5WY5cTv1MT8QZJJeOExhDvE2MyW5vHe7htS4JqeBjo07ZEVBDSpneKdS5FUXrdm9AoupxeMVvFP4sj', 'eSf5Ji2J5t01WKHAZbTomxOLs5CfQAJGnHtPykEAdvcOW5M2KcgTe84qNBX8dsrWXgd6Gz8cWZF2tPtzIlJvtgMCuu', 'rhfua03rpysKziOJqCjWbfz0kAeLmL7kBTuHwyONb1KBKWTdmAkFaNyamnydFb1lpDl3a2VkRfG1dO3tImeGSr82oT', '_2cZOmdFrO9vD3sm3X7bn34SUBz1Gc67rNssT6yFyMzwhTb9pRKwzfqcK40inbtC0nrEsVBsBWFdU2LxJxKCs1UQcUR' |
Source: testnt.exe.2.dr, bh5AgBmmct9rNksQHppG7G.cs |
High entropy of concatenated method names: 'zqn1SQUrFUMgHieXIorpxP', 'c04k38AmW1WWkBG1Xj3wvH', 'ZG8iCN2A0lEn1L6ydnzK42', 'gHmFGh8HlX6Zb4pRCESCiG', 'KHX41dZ3v4ndWAiAX7Ntew', 'gUGVVE4W2wDAXYH2i054eE', 'owXtj5QlhgpYpQdHlm58mq', 'ohfsz38hrN83Rk2XjK4n0u', 'cMTGVh7QlqnpqtS4THFPSH', 'z0AABSExIRPLOFe6d4YQGl' |
Source: testnt.exe.2.dr, WIuR1rCg9OABqm2Ov6Vai2Lg9nFtnB4GBfFpoudo.cs |
High entropy of concatenated method names: 'FNHzWngLomEA2m0s7IkHnKswZPPuxbx9DqImvxXC', 'ym3amq6ICtFEpNGE25s8jQ096Z0jTdy7wWYGlWGGymDG2Zt3gT', 'zEBPDZSKVOzQ5zlq7Ri0JkZLP0DH0SROGSexfv8P1vtePgTltl', 'iNwVIlJ1tjsdxiCHWDvBpTlhvrvIlYZMw96bx0dsn1cqc8Ejzw', 'rDi3OHpasRrnDFdZG2IPJj5sBAJxI5zZjKMR8eTisj5fRHqyde' |
Source: testnt.exe.2.dr, p1IG6OHEpiNB43wrLsWuNu.cs |
High entropy of concatenated method names: 'u5yD0BUm2PcSw0iB0GO3cP', 'oPAJ4NA3yjtlpSliHpVRHy', 'mDEbck9Dl7iLQmmmTiw4D5', '_7Z84Hk2AYvRgn54bPqWxxH', 'Mv3s3rXUYJDv1MlRaV5NZxp1lrZYGvPAA0ykgRtUbGEETMn7PiLRJtx', '_77YyemyOEFU7itfJCUsjpOx8gcqGs8FUQuQbA9o8ta3m6IZGpENCEdn', 'sHvtH3qz9BfXf8zkENDR7dEgvIfjGrGSPeJGEtatrfFc06ORCLo5ldj', '_0juZ9cgK4ayrYhpT7hhADZrbXqLW4FBWPOFjBSBSa4ZCUS5BFAoeDEI', 'wMVjv6gIyHStMsg1FglMtkNzcQO4BpY256l7vPnLEsfsR6NLveTsN8R', 'UIfHerstaAUFl4huhLMnguGkk7zmMhlt614liUFezUqNobGa6g6vH3x' |
Source: testnt.exe.2.dr, p0YNdbZlrOpuCNRE0edav2KYSP4XGWPn8wRjA9ie.cs |
High entropy of concatenated method names: 'Wk5Rb1ThVxurWW4bR1FzYtajBSNZ3f3cYDGvN7KK', 'OE6M0rFV82DhFKGwpEZVAxuiE8p1tK1ipzXidSoY', 'Erk5rdelfOjiuryrno1aRfle7byjXfKUxM1IIYEu', 'uNO52gJl8XiflpctQQdzmbqRKQejB1mbrjnEehsD', 'c9zSsXTzShpzMwYex5arwnBbukAePQnQ4WeJe3Ax', 'zyjJyxkzs2oh0kJZ9Y4EqfRAZDI4Uwi0aea8ZOrX', 'Qavs0kE80dO9dbK005T8Q8cLCd044xtxvwy7y0mZ', 'xSogTl37TYlau03YlfU1eGjgqwst6VUgqvUruZ0E', 'UZRKZV3Dt0DNJZBzWiRF95ZUl55fQaz6d7JbqDRX', '_85FPJGNAtQhSjWYn0FzmTXtkBRhzY9oQUFKTjHdH' |
Source: testnt.exe.2.dr, HSv2czNGQ5ZtVacsXcu1DvtdZfn74sbSWa0KpGeNi8UwefY4Ro8oGJD.cs |
High entropy of concatenated method names: 'rQ89f38m37zZhF5nfv6r8KS0hp8uP8FGlG9AqgdmUIkjHvZRSEBgNNI', '_3vrFleZlqfNAg5HVW', 'fkj2QBHwu6XlJY3Hj', 'QoIvAOGEAuZz19ONd', 'PabkqXCUaLQLay6wi' |
Source: testnt.exe.2.dr, A6KJM5OnMj4l8Zs9YLwXRUrIXz7tx6TKgT2mMjtx.cs |
High entropy of concatenated method names: '_6b35A2axSWdonI5on3vsc92D2xbKfFvyKpIExQaY', 'pD752BHE35OB8WiKtQr0p60F3fC0avicmI5yc9k0', 'MIa5PswOlrNKDMMa2MtCLkv8JmGtgOBwVZ0JWBKg', 'WP1FEFB4Q0dzyFiN1WGA2farZLuhgXlcgyS4w0p8', 'aN8VjZcHu2u8Rmtbv', 'TJhDrOu62xHF82TLB', 's57B1kOnf10WLh9Kf', 'U2nIHzR0ooxGpXetJ', '_5uvptiCCabgcq63Ok', 'PCwTgXZAzcLFF2yAy' |
Source: testnt.exe.2.dr, pWFohs8uFmHTfaAhVw9lC9.cs |
High entropy of concatenated method names: 'sIEUBVVBXhvymuoXBq3b8l', '_3a9P2xLTv2K5DSI1e6EgiN', 'x7AF0fxrGevqKUlbD2cq16', 'RookwFJp4qwU93FcPJHhs9', 'WEmXE5AIt2cD3OBQCaKM4i', 'AX0TTbOTnCbv0dJZkxNakn', '_7mSDokXU63yRJoAkHZffOf', 'xMmJ0OlkoEPrEXhP9GEKCD', 'jHFzismFBt9yWCZ9fGZjnY', '_4Oqr7SZUXA9Ugg6ixxP9AO' |
Source: testnt.exe.2.dr, nAqjKWnahmZlgbIrYsgeU9lRcu9NpU73tOyeIJVmtQ5RNbG4wKEHQmh.cs |
High entropy of concatenated method names: 'ecISpUVC7UxhPRPd30VapydpSI3nLfDU5zGNeurGECmvF6f80F7gLee', 'QPr3dnXNquZaXW00q8qX0kwzlalzdv5WD40SmZ2LveeYB91exVAJO2I', 'QkVvTmVgSKYKr7VP9tcaLfRxRuOQ8TBP7XFtqGKFjWQWcXbmZXm0XvO', '_8H4z0sovpRkdAbqc3aAZFRhMun7X0O8z3K5AbYLMBgWRNF6nXHQ3gSj', 'JVlMsxOMPrYBrJus3mp3o2MoVofS3QV3NVnZ3QFFRbnZbSryG6RJJNh', 'oDJOt48iSKv0kcDhtOSbYR4rwZBi41caMtJzs2OROH0PF9xcp9uiTXK', 'X5karREfXDJrjLMfdIVTqRy4MGXUKCSlk0lA6BLH', 'O0Z7l9kZro8pyJuwJz6TQCgkkURsYV5irdxZS62c', 'JIwTQcoqzczSqlagZlMQziGeR9WoolecjR0gmTSg', 'E7GV89f8RBAgZqKGmAmkarjRsclTRcq2f5LmflzP' |
Source: C:\Users\user\Desktop\LHA9oUEAwZ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LHA9oUEAwZ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LHA9oUEAwZ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LHA9oUEAwZ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LHA9oUEAwZ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LHA9oUEAwZ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LHA9oUEAwZ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LHA9oUEAwZ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LHA9oUEAwZ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LHA9oUEAwZ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LHA9oUEAwZ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LHA9oUEAwZ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LHA9oUEAwZ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LHA9oUEAwZ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LHA9oUEAwZ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LHA9oUEAwZ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LHA9oUEAwZ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LHA9oUEAwZ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LHA9oUEAwZ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LHA9oUEAwZ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LHA9oUEAwZ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LHA9oUEAwZ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LHA9oUEAwZ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LHA9oUEAwZ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LHA9oUEAwZ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LHA9oUEAwZ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LHA9oUEAwZ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LHA9oUEAwZ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LHA9oUEAwZ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LHA9oUEAwZ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LHA9oUEAwZ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LHA9oUEAwZ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LHA9oUEAwZ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LHA9oUEAwZ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LHA9oUEAwZ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LHA9oUEAwZ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LHA9oUEAwZ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LHA9oUEAwZ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LHA9oUEAwZ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LHA9oUEAwZ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LHA9oUEAwZ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LHA9oUEAwZ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LHA9oUEAwZ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LHA9oUEAwZ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LHA9oUEAwZ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LHA9oUEAwZ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LHA9oUEAwZ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LHA9oUEAwZ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LHA9oUEAwZ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LHA9oUEAwZ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LHA9oUEAwZ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\LHA9oUEAwZ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\System32\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: Amcache.hve.12.dr |
Binary or memory string: VMware |
Source: Amcache.hve.12.dr |
Binary or memory string: VMware Virtual USB Mouse |
Source: Amcache.hve.12.dr |
Binary or memory string: vmci.syshbin |
Source: Amcache.hve.12.dr |
Binary or memory string: VMware, Inc. |
Source: Amcache.hve.12.dr |
Binary or memory string: VMware20,1hbin@ |
Source: Amcache.hve.12.dr |
Binary or memory string: c:\windows\system32\driverstore\filerepository\vmci.inf_amd64_68ed49469341f563 |
Source: Amcache.hve.12.dr |
Binary or memory string: Ascsi/cdrom&ven_necvmwar&prod_vmware_sata_cd00/4&224f42ef&0&000000 |
Source: Amcache.hve.12.dr |
Binary or memory string: .Z$c:/windows/system32/drivers/vmci.sys |
Source: Amcache.hve.12.dr |
Binary or memory string: :scsi/disk&ven_vmware&prod_virtual_disk/4&1656f219&0&000000 |
Source: Amcache.hve.12.dr |
Binary or memory string: pci\ven_15ad&dev_0740&subsys_074015ad,pci\ven_15ad&dev_0740,root\vmwvmcihostdev |
Source: Amcache.hve.12.dr |
Binary or memory string: c:/windows/system32/drivers/vmci.sys |
Source: Amcache.hve.12.dr |
Binary or memory string: scsi/cdrom&ven_necvmwar&prod_vmware_sata_cd00/4&224f42ef&0&000000 |
Source: LHA9oUEAwZ.exe, 00000002.00000002.3245574998.000000001BFE3000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll |
Source: Amcache.hve.12.dr |
Binary or memory string: vmci.sys |
Source: Amcache.hve.12.dr |
Binary or memory string: vmci.syshbin` |
Source: testnt.exe.2.dr |
Binary or memory string: vmware |
Source: Amcache.hve.12.dr |
Binary or memory string: \driver\vmci,\driver\pci |
Source: Amcache.hve.12.dr |
Binary or memory string: scsi/disk&ven_vmware&prod_virtual_disk/4&1656f219&0&000000 |
Source: Amcache.hve.12.dr |
Binary or memory string: VMware20,1 |
Source: Amcache.hve.12.dr |
Binary or memory string: Microsoft Hyper-V Generation Counter |
Source: Amcache.hve.12.dr |
Binary or memory string: NECVMWar VMware SATA CD00 |
Source: Amcache.hve.12.dr |
Binary or memory string: VMware Virtual disk SCSI Disk Device |
Source: Amcache.hve.12.dr |
Binary or memory string: scsi\cdromnecvmwarvmware_sata_cd001.00,scsi\cdromnecvmwarvmware_sata_cd00,scsi\cdromnecvmwar,scsi\necvmwarvmware_sata_cd001,necvmwarvmware_sata_cd001,gencdrom |
Source: Amcache.hve.12.dr |
Binary or memory string: scsi\diskvmware__virtual_disk____2.0_,scsi\diskvmware__virtual_disk____,scsi\diskvmware__,scsi\vmware__virtual_disk____2,vmware__virtual_disk____2,gendisk |
Source: Amcache.hve.12.dr |
Binary or memory string: Microsoft Hyper-V Virtualization Infrastructure Driver |
Source: Amcache.hve.12.dr |
Binary or memory string: VMware PCI VMCI Bus Device |
Source: Amcache.hve.12.dr |
Binary or memory string: VMware VMCI Bus Device |
Source: Amcache.hve.12.dr |
Binary or memory string: VMware Virtual RAM |
Source: Amcache.hve.12.dr |
Binary or memory string: BiosVendor:VMware, Inc.,BiosVersion:VMW201.00V.20829224.B64.2211211842,BiosReleaseDate:11/21/2022,BiosMajorRelease:0xff,BiosMinorRelease:0xff,SystemManufacturer:VMware, Inc.,SystemProduct:VMware20,1,SystemFamily:,SystemSKUNumber:,BaseboardManufacturer:,BaseboardProduct:,BaseboardVersion:,EnclosureType:0x1 |
Source: Amcache.hve.12.dr |
Binary or memory string: VMware-42 27 88 19 56 cc 59 1a-97 79 fb 8c bf a1 e2 9d |
Source: Amcache.hve.12.dr |
Binary or memory string: vmci.inf_amd64_68ed49469341f563 |