Windows Analysis Report
General_Beta_VMS_Win32_V2.2.1.16.T.20230306.exe

Overview

General Information

Sample name: General_Beta_VMS_Win32_V2.2.1.16.T.20230306.exe
Analysis ID: 1431911
MD5: 02ba2c52a74c925aae66d868174e0e88
SHA1: 113a62c3c735ea6dbc66597e2db654519e545fe4
SHA256: c6541f49217a36cb3e6d5772fe1d396da56fe2d70cd2b66de5b7d9469fa453fd
Infos:

Detection

Score: 21
Range: 0 - 100
Whitelisted: false
Confidence: 40%

Signatures

Overwrites code with unconditional jumps - possibly settings hooks in foreign process
Abnormal high CPU Usage
Creates a DirectInput object (often for capturing keystrokes)
Creates a process in suspended mode (likely to inject code)
Detected TCP or UDP traffic on non-standard ports
Drops PE files
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Found dropped PE file which has not been started or loaded
JA3 SSL client fingerprint seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
PE file contains an invalid checksum
Queries the volume information (name, serial number etc) of a device
Sample execution stops while process was sleeping (likely an evasion)
Sigma detected: Classes Autorun Keys Modification
Sigma detected: Scripting/CommandLine Process Spawned Regsvr32
Sleep loop found (likely to delay execution)
Stores files to the Windows start menu directory
Uses 32bit PE files

Classification

Source: VMS.exe, 00000007.00000002.3604576816.0000000010208000.00000002.00000001.01000000.0000001A.sdmp Binary or memory string: -----BEGIN PUBLIC KEY----- memstr_57527aee-8
Source: General_Beta_VMS_Win32_V2.2.1.16.T.20230306.exe Static PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE
Source: C:\Program Files (x86)\VMS\VMS.exe File opened: C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.9672_none_d08f9da24428a513\MSVCR80.dll Jump to behavior
Source: unknown HTTPS traffic detected: 54.191.62.134:443 -> 192.168.2.4:49741 version: TLS 1.2
Source: General_Beta_VMS_Win32_V2.2.1.16.T.20230306.exe Static PE information: DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
Source: Binary string: Extract: NetSdk.pdb source: General_Beta_VMS_Win32_V2.2.1.16.T.20230306.exe, 00000000.00000003.2381467220.00000000007DB000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: e:\workspace\SNS\CMS\Trunk\VMS\Trunk\Dest\Win32\bin\Release_MultiVendor\XMCloudClientAPI.pdb source: VMS.exe, 00000007.00000002.3623190698.00000000684A2000.00000002.00000001.01000000.00000019.sdmp
Source: Binary string: C:\Users\qt\work\qt\qtsvg\plugins\imageformats\qsvg.pdb source: VMS.exe, 00000007.00000002.3613325792.00000000648A3000.00000002.00000001.01000000.00000045.sdmp
Source: Binary string: d3dx9_43.pdb source: VMS.exe, 00000007.00000002.3615414852.0000000064F71000.00000020.00000001.01000000.00000031.sdmp
Source: Binary string: \plugins\sqldriversqsqlite.dllqsqlmysql.dllqsqlodbc.dllqsqlpsql.dllpostproc.dllProcessMan.exeQt5Core.dllQt5Gui.dllQt5Multimedia.dllQt5Network.dllQt5Sql.dllQt5Svg.dllQt5Widgets.dllqwt.dllQZXing3.dllRecordPlan.exeRecordPlan.pdbRestoreData.exe source: General_Beta_VMS_Win32_V2.2.1.16.T.20230306.exe, 00000000.00000003.2514332406.0000000000761000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\projects\ffmpeg\build_out\lib\x86\avcodec.pdb source: VMS.exe, 00000007.00000002.3617232960.0000000066542000.00000002.00000001.01000000.0000002E.sdmp
Source: Binary string: D:\project\dhlog\bin\x86\release\dhlog.pdb source: VMS.exe, 00000007.00000002.3615281278.0000000064F2C000.00000002.00000001.01000000.00000033.sdmp
Source: Binary string: D:\SVN\VMS_OEM\VMS\Dest\Win32\temp\Release_MultiVendor\vc140.pdb source: General_Beta_VMS_Win32_V2.2.1.16.T.20230306.exe, 00000000.00000002.2515880950.0000000002CE9000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: D:\project\dhlog\bin\x86\release\dhlog.pdb source: VMS.exe, 00000007.00000002.3615281278.0000000064F2C000.00000002.00000001.01000000.00000033.sdmp
Source: Binary string: e:\jk_w32\workspace\CBB_DH3.RD000692_PlaySDKV3.40\Lib\Win32\vs2005shared\dhplay.pdb source: VMS.exe, 00000007.00000002.3582743236.00000000018D9000.00000002.00000001.01000000.0000001D.sdmp
Source: Binary string: C:\Users\qt\work\qt\qtbase\plugins\imageformats\qico.pdb source: VMS.exe, 00000007.00000002.3613913981.0000000064905000.00000002.00000001.01000000.00000043.sdmp
Source: Binary string: concrt140.i386.pdbGCTL source: VMS.exe, 00000007.00000002.3619266175.00000000676A1000.00000020.00000001.01000000.00000026.sdmp
Source: Binary string: lD:\SVN\VMS_OEM\VMS\Dest\Win32\bin\Release_MultiVendor\ConfigModule.pdbQQ source: VMS.exe, 00000007.00000002.3623585268.00000000684DB000.00000002.00000001.01000000.00000018.sdmp
Source: Binary string: \trunk\WindowsAudioRender\bin\AudioRender.pdb source: VMS.exe, 00000007.00000002.3616141917.0000000065261000.00000002.00000001.01000000.0000002D.sdmp
Source: Binary string: Extract: RecordPlan.pdb(7oB source: General_Beta_VMS_Win32_V2.2.1.16.T.20230306.exe, 00000000.00000003.2381467220.00000000007DB000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: Extract: H264Play.pdb source: General_Beta_VMS_Win32_V2.2.1.16.T.20230306.exe, 00000000.00000002.2515621604.00000000007C7000.00000004.00000020.00020000.00000000.sdmp, General_Beta_VMS_Win32_V2.2.1.16.T.20230306.exe, 00000000.00000003.2514016055.00000000007BF000.00000004.00000020.00020000.00000000.sdmp, General_Beta_VMS_Win32_V2.2.1.16.T.20230306.exe, 00000000.00000003.2514480181.00000000007C6000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\Users\qt\work\qt\qtbase\plugins\imageformats\qgif.pdb!! source: VMS.exe, 00000007.00000002.3614480980.0000000064925000.00000002.00000001.01000000.00000041.sdmp
Source: Binary string: C:\Users\qt\work\qt\qtsvg\lib\Qt5Svg.pdb source: VMS.exe, 00000007.00000002.3613077945.0000000064877000.00000002.00000001.01000000.00000046.sdmp
Source: Binary string: \VMS.lnkAVApis.dllavcodec.dllavdevice.dllavfilter.dllavformat.dllavnetsdk.dllavutil.dllCloudClientAPI.dllCMSClient.dllCMSClient.pdbconfig.iniconcrt140.dllConfigModule.dllConfigModule.pdbd3dx9_24.dllD3DX9_43.dllDhDecode.dlldhlog.dlldhnetsdk.dlldhplay.dlldhplay.pdbDllDeinterlace.dllErrorReport.exefisheye.dllgdiplus.dllglew32.dllH264Play.dllH264Play.pdbh264_enc.dllHCCore.dllHCNetSDK.dll source: General_Beta_VMS_Win32_V2.2.1.16.T.20230306.exe, 00000000.00000003.2514332406.0000000000761000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: vcruntime140.i386.pdbGCTL source: VMS.exe, 00000007.00000002.3624932255.0000000068991000.00000020.00000001.01000000.00000016.sdmp
Source: Binary string: Extract: CMSClient.pdb source: General_Beta_VMS_Win32_V2.2.1.16.T.20230306.exe, 00000000.00000002.2515621604.00000000007C7000.00000004.00000020.00020000.00000000.sdmp, General_Beta_VMS_Win32_V2.2.1.16.T.20230306.exe, 00000000.00000003.2514016055.00000000007BF000.00000004.00000020.00020000.00000000.sdmp, General_Beta_VMS_Win32_V2.2.1.16.T.20230306.exe, 00000000.00000003.2514480181.00000000007C6000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\Users\qt\work\qt\qtimageformats\plugins\imageformats\qwebp.pdb source: VMS.exe, 00000007.00000002.3611885650.00000000647B0000.00000002.00000001.01000000.0000004A.sdmp
Source: Binary string: y:\StreamMedia\StreamSvr_Third\Lib\Release\Win32\vs2005\StreamSvr.pdb source: VMS.exe, 00000007.00000002.3591298660.0000000005F8F000.00000002.00000001.01000000.00000038.sdmp
Source: Binary string: \streamParser\bin\Release\StreamReader.pdb source: VMS.exe, 00000007.00000002.3581948713.000000000159A000.00000002.00000001.01000000.0000001C.sdmp
Source: Binary string: G:\subversion\vrsoft\Source\Windows_SupportWin64\VRSoftDll\VRSoft\Release\VRSoft.pdb source: General_Beta_VMS_Win32_V2.2.1.16.T.20230306.exe, 00000000.00000002.2515880950.00000000027A9000.00000004.00000020.00020000.00000000.sdmp, VMS.exe, 00000007.00000002.3622223790.00000000683EE000.00000002.00000001.01000000.0000001F.sdmp
Source: Binary string: D:\Programming\My Projects\CodeProject\HowToBuildLibiconv\LibIconv_Build_1_14\Release_Win32\libiconv.pdb@W source: VMS.exe, 00000007.00000002.3621017751.000000006813A000.00000002.00000001.01000000.00000022.sdmp
Source: Binary string: D:\Workplace\QRCodeRecognition\QRCodeRecognition\bin\QZXing3.pdb source: VMS.exe, 00000007.00000002.3625277789.0000000068C35000.00000002.00000001.01000000.00000015.sdmp
Source: Binary string: c:\users\xmuser\documents\visual studio 2005\projects\multilendlltest\release\XMDrift.pdb` source: General_Beta_VMS_Win32_V2.2.1.16.T.20230306.exe, 00000000.00000002.2515880950.0000000002CE9000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: Extract: dhplay.pdbQ" source: General_Beta_VMS_Win32_V2.2.1.16.T.20230306.exe, 00000000.00000002.2515621604.00000000007C7000.00000004.00000020.00020000.00000000.sdmp, General_Beta_VMS_Win32_V2.2.1.16.T.20230306.exe, 00000000.00000003.2514016055.00000000007BF000.00000004.00000020.00020000.00000000.sdmp, General_Beta_VMS_Win32_V2.2.1.16.T.20230306.exe, 00000000.00000003.2514480181.00000000007C6000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: Extract: StreamReader.pdb\ source: General_Beta_VMS_Win32_V2.2.1.16.T.20230306.exe, 00000000.00000003.2340704802.0000000003B31000.00000004.00000020.00020000.00000000.sdmp, General_Beta_VMS_Win32_V2.2.1.16.T.20230306.exe, 00000000.00000003.2381417690.0000000003B32000.00000004.00000020.00020000.00000000.sdmp, General_Beta_VMS_Win32_V2.2.1.16.T.20230306.exe, 00000000.00000002.2516791909.0000000003B32000.00000004.00000020.00020000.00000000.sdmp, General_Beta_VMS_Win32_V2.2.1.16.T.20230306.exe, 00000000.00000003.2513496848.0000000003B32000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\Users\qt\work\qt\qtbase\plugins\sqldrivers\qsqlite.pdb source: VMS.exe, 00000007.00000002.3614710395.0000000064AA9000.00000002.00000001.01000000.0000004B.sdmp
Source: Binary string: d:\workspace\NetFramework\Trunk\Lib\Win32\d_r_mt\NetFramework.pdb source: VMS.exe, 00000007.00000002.3590932119.0000000005EAF000.00000002.00000001.01000000.00000037.sdmp
Source: Binary string: \bin\netsdk\x86\release\NetSdk.pdb source: VMS.exe, 00000007.00000002.3604576816.0000000010208000.00000002.00000001.01000000.0000001A.sdmp
Source: Binary string: C:\Users\qt\work\qt\qtbase\plugins\sqldrivers\qsqlite.pdb!! source: VMS.exe, 00000007.00000002.3614710395.0000000064AA9000.00000002.00000001.01000000.0000004B.sdmp
Source: Binary string: vcomp140.i386.pdb source: VMS.exe, 00000007.00000002.3615730948.0000000065171000.00000020.00000001.01000000.00000030.sdmp
Source: Binary string: <glob pattern="*.pdb"/> source: VMS.exe, 00000007.00000003.2384526690.00000000069E2000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\projects\ffmpeg\build_out\lib\x86\swresample.pdb source: VMS.exe, 00000007.00000002.3615955851.00000000651D6000.00000002.00000001.01000000.0000002F.sdmp
Source: Binary string: \translations\RecoveryDataRussian.qmSimpChinese_Qt.qmvccorlib140.dllvcomp140.dllvcruntime140.dllvcruntime140d.dllvcruntime140_1.dllversion.txtVMS.pdbVMS source: General_Beta_VMS_Win32_V2.2.1.16.T.20230306.exe, 00000000.00000003.2514332406.0000000000761000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: e:\SuperRender\2015\7\7.16-Ex\bin\SuperRender_privite.pdb source: VMS.exe, 00000007.00000002.3588000071.0000000003FFE000.00000002.00000001.01000000.0000002C.sdmp
Source: Binary string: e:\Project\MediaPlayControl\mpCtrl_win32_Base\Dll_OUT\win32\PDB\PlayCtrl.pdb source: VMS.exe, 00000007.00000002.3587543708.0000000003EB1000.00000002.00000001.01000000.00000029.sdmp
Source: Binary string: C:\Users\qt\work\qt\qtimageformats\plugins\imageformats\qtiff.pdbBB source: VMS.exe, 00000007.00000002.3612469905.000000006480C000.00000002.00000001.01000000.00000048.sdmp
Source: Binary string: C:\Users\qt\work\qt\qtbase\lib\Qt5Core.pdb9 source: VMS.exe, 00000007.00000002.3624108546.00000000688CC000.00000002.00000001.01000000.00000017.sdmp
Source: Binary string: Extract: VMS.pdb source: General_Beta_VMS_Win32_V2.2.1.16.T.20230306.exe, 00000000.00000003.2341120922.00000000007FD000.00000004.00000020.00020000.00000000.sdmp, General_Beta_VMS_Win32_V2.2.1.16.T.20230306.exe, 00000000.00000003.2341081966.00000000007F5000.00000004.00000020.00020000.00000000.sdmp, General_Beta_VMS_Win32_V2.2.1.16.T.20230306.exe, 00000000.00000003.2381359571.0000000000801000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: D:\jenkins\workspace\APP_Package_SDK_Windows32\common\HCNetSDK\VS2013\lib\win32\HCCore.pdb source: VMS.exe, 00000007.00000002.3619714056.0000000067D80000.00000002.00000001.01000000.00000025.sdmp
Source: Binary string: D:\SVN\VMS_OEM\VMS\Dest\Win32\bin\Release_MultiVendor\VMS.pdb source: VMS.exe, 00000007.00000000.2380249721.0000000000B8A000.00000002.00000001.01000000.0000000C.sdmp
Source: Binary string: C:\Users\qt\work\qt\qtbase\lib\Qt5Core.pdb source: VMS.exe, 00000007.00000002.3624108546.00000000688CC000.00000002.00000001.01000000.00000017.sdmp
Source: Binary string: C:\Users\qt\work\qt\qtimageformats\plugins\imageformats\qtiff.pdb source: VMS.exe, 00000007.00000002.3612469905.000000006480C000.00000002.00000001.01000000.00000048.sdmp
Source: Binary string: C:\Users\qt\work\qt\qtbase\plugins\imageformats\qgif.pdb source: VMS.exe, 00000007.00000002.3614480980.0000000064925000.00000002.00000001.01000000.00000041.sdmp
Source: Binary string: *.pdb source: VMS.exe, 00000007.00000002.3593071572.0000000006C10000.00000004.00000020.00020000.00000000.sdmp, VMS.exe, 00000007.00000002.3593258932.0000000006D7E000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: c:\users\xmuser\documents\visual studio 2005\projects\multilendlltest\release\XMDrift.pdb source: General_Beta_VMS_Win32_V2.2.1.16.T.20230306.exe, 00000000.00000002.2515880950.0000000002CE9000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\Users\qt\work\qt\qtimageformats\plugins\imageformats\qtga.pdb source: VMS.exe, 00000007.00000002.3612771939.0000000064843000.00000002.00000001.01000000.00000047.sdmp
Source: Binary string: m)D:\SVN\VMS_OEM\VMS\Dest\Win32\bin\Release_MultiVendor\VMS.pdb source: VMS.exe, 00000007.00000000.2380249721.0000000000B8A000.00000002.00000001.01000000.0000000C.sdmp
Source: Binary string: D:\Programming\My Projects\CodeProject\HowToBuildLibiconv\LibIconv_Build_1_14\Release_Win32\libiconv.pdb source: VMS.exe, 00000007.00000002.3621017751.000000006813A000.00000002.00000001.01000000.00000022.sdmp
Source: Binary string: C:\Users\qt\work\qt\qtimageformats\plugins\imageformats\qicns.pdb source: VMS.exe, 00000007.00000002.3614193607.0000000064915000.00000002.00000001.01000000.00000042.sdmp
Source: Binary string: vcruntime140.i386.pdb source: VMS.exe, 00000007.00000002.3624932255.0000000068991000.00000020.00000001.01000000.00000016.sdmp
Source: Binary string: D:\jenkins\workspace\APP_Package_SDK_Windows32\common\HCNetSDK\VS2013\lib\win32\HCNetSDK.pdb source: VMS.exe, 00000007.00000002.3621567654.0000000068398000.00000002.00000001.01000000.00000021.sdmp
Source: Binary string: \Release\H264Play.pdb source: VMS.exe, 00000007.00000002.3581441637.0000000001519000.00000002.00000001.01000000.0000001B.sdmp
Source: Binary string: \bin\netsdk\x86\release\NetSdk.pdb\m( source: VMS.exe, 00000007.00000002.3604576816.0000000010208000.00000002.00000001.01000000.0000001A.sdmp
Source: Binary string: \modeldetect.caffemodeldetect.prototxtsr.caffemodelsr.prototxtMP_Render.dllMP_VIE.dllmsvcm80.dllmsvcm90.dllmsvcp80.dllmsvcp90.dllmsvcp140.dllmsvcr120.dllmsvcr80.dllNetFramework.dllNetSdk.dllNetSdk.pdbopencv_img_hash460.dllopencv_videoio_ffmpeg460.dllopencv_world460.dllPeerSDK.dll source: General_Beta_VMS_Win32_V2.2.1.16.T.20230306.exe, 00000000.00000003.2514332406.0000000000761000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\projects\ffmpeg\build_out\lib\x86\avutil.pdb source: VMS.exe, 00000007.00000002.3618992177.00000000670B3000.00000002.00000001.01000000.0000002A.sdmp
Source: Binary string: C:\Users\qt\work\qt\qtbase\plugins\imageformats\qico.pdb"" source: VMS.exe, 00000007.00000002.3613913981.0000000064905000.00000002.00000001.01000000.00000043.sdmp
Source: Binary string: msvcr120.i386.pdb source: VMS.exe, 00000007.00000002.3620370718.0000000068031000.00000020.00000001.01000000.00000023.sdmp
Source: Binary string: vcomp140.i386.pdbGCTL source: VMS.exe, 00000007.00000002.3615730948.0000000065171000.00000020.00000001.01000000.00000030.sdmp
Source: Binary string: \sound\TradChinesessleay32.dllStream.dllStreamReader.pdbStreamSvr.dllSuperRender.dllswresample.dllswscale.dll source: General_Beta_VMS_Win32_V2.2.1.16.T.20230306.exe, 00000000.00000003.2514332406.0000000000761000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: d:\SVN\Sofia\NetIP\Trunk\Onvif_client1\Onvif_client\release\libonvifclient.pdb source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp
Source: Binary string: C:\Users\qt\work\qt\qtbase\plugins\imageformats\qjpeg.pdbPP source: VMS.exe, 00000007.00000002.3613627894.00000000648E6000.00000002.00000001.01000000.00000044.sdmp
Source: Binary string: D:\SVN\VMS_OEM\VMS\Dest\Win32\bin\Release_MultiVendor\ConfigModule.pdb source: VMS.exe, 00000007.00000002.3623585268.00000000684DB000.00000002.00000001.01000000.00000018.sdmp
Source: Binary string: concrt140.i386.pdb source: VMS.exe, 00000007.00000002.3619266175.00000000676A1000.00000020.00000001.01000000.00000026.sdmp
Source: Binary string: e:\SuperRender\2015\7\7.16-Ex\bin\SuperRender_privite.pdb8 source: VMS.exe, 00000007.00000002.3588000071.0000000003FFE000.00000002.00000001.01000000.0000002C.sdmp
Source: Binary string: C:\Users\qt\work\qt\qtsvg\lib\Qt5Svg.pdb,, source: VMS.exe, 00000007.00000002.3613077945.0000000064877000.00000002.00000001.01000000.00000046.sdmp
Source: Binary string: C:\Users\qt\work\qt\qtbase\plugins\platforms\qwindows.pdb source: VMS.exe, 00000007.00000002.3614954025.0000000064BA2000.00000002.00000001.01000000.0000003D.sdmp
Source: Binary string: C:\Users\qt\work\qt\qtbase\plugins\imageformats\qjpeg.pdb source: VMS.exe, 00000007.00000002.3613627894.00000000648E6000.00000002.00000001.01000000.00000044.sdmp
Source: Binary string: C:\Users\qt\work\qt\qtimageformats\plugins\imageformats\qwbmp.pdb source: VMS.exe, 00000007.00000002.3612170234.00000000647D3000.00000002.00000001.01000000.00000049.sdmp
Source: global traffic UDP traffic: 192.168.2.4:54566 -> 54.176.110.240:7999
Source: global traffic UDP traffic: 192.168.2.4:54567 -> 50.18.10.59:8765
Source: global traffic UDP traffic: 192.168.2.4:54568 -> 152.32.200.49:8765
Source: global traffic UDP traffic: 192.168.2.4:54568 -> 152.32.197.61:8765
Source: Joe Sandbox View JA3 fingerprint: 1aee0238942d453d679fc1e37a303387
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 152.32.200.49
Source: unknown UDP traffic detected without corresponding DNS query: 152.32.197.61
Source: unknown UDP traffic detected without corresponding DNS query: 152.32.200.49
Source: unknown UDP traffic detected without corresponding DNS query: 152.32.197.61
Source: global traffic DNS traffic detected: DNS query: secu100.net
Source: global traffic DNS traffic detected: DNS query: rs.xmeye.net
Source: unknown HTTP traffic detected: POST /faceCheckocx/v1/00000015449906/dece7107f0f523761c67edecec030240.rs HTTP/1.1Host: rs.xmeye.netAccept: */*Accept-Charset: utf-8Content-Type: application/x-www-form-urlencodeduuid: e0534f3240274897821a126be19b6d46appKey: 4a6cfc1d0038b61eb6e75f659c1c528eUser-Agent: NetSDK
Source: General_Beta_VMS_Win32_V2.2.1.16.T.20230306.exe, 00000000.00000002.2515880950.00000000027A9000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://10.6.3.200/svn/Release/Dev/DVR/General/)
Source: VMS.exe, 00000007.00000002.3582743236.00000000018D9000.00000002.00000001.01000000.0000001D.sdmp String found in binary or memory: http://10.6.5.2/svnpl/CODEC/PC/DEC_AAC/Trunk
Source: VMS.exe, 00000007.00000002.3582743236.00000000018D9000.00000002.00000001.01000000.0000001D.sdmp String found in binary or memory: http://10.6.5.2/svnpl/CODEC/PC/DEC_AAC/Trunke
Source: VMS.exe, 00000007.00000002.3582743236.00000000018D9000.00000002.00000001.01000000.0000001D.sdmp String found in binary or memory: http://10.6.5.2/svnpl/CODEC/PC/DEC_H26L/Trunk/H26L_Decoder_PC
Source: VMS.exe, 00000007.00000002.3582743236.00000000018D9000.00000002.00000001.01000000.0000001D.sdmp String found in binary or memory: http://10.6.5.2/svnpl/CODEC/PC/DEC_H26L/Trunk/H26L_Decoder_PCInput
Source: General_Beta_VMS_Win32_V2.2.1.16.T.20230306.exe, 00000000.00000003.2381553988.0000000000560000.00000004.00000800.00020000.00000000.sdmp, VMS.exe, 00000007.00000002.3580659593.0000000001221000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://103.43.18.73:8086/NAS/
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://docs.oasis-open.org/wsn/b-2
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://docs.oasis-open.org/wsn/bw-2/CreatePullPoint/CreatePullPointRequest
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://docs.oasis-open.org/wsn/bw-2/NotificationConsumer/Notify
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://docs.oasis-open.org/wsn/bw-2/NotificationProducer/GetCurrentMessageRequest
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://docs.oasis-open.org/wsn/bw-2/NotificationProducer/SubscribeRequest
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://docs.oasis-open.org/wsn/bw-2/NotificationProducer/SubscribeRequest-denf:Subscribe-denf:Subscr
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://docs.oasis-open.org/wsn/bw-2/PausableSubscriptionManager/PauseSubscriptionRequest
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://docs.oasis-open.org/wsn/bw-2/PausableSubscriptionManager/RenewRequest
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://docs.oasis-open.org/wsn/bw-2/PausableSubscriptionManager/ResumeSubscriptionRequest
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://docs.oasis-open.org/wsn/bw-2/PausableSubscriptionManager/UnsubscribeRequest
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://docs.oasis-open.org/wsn/bw-2/PullPoint/DestroyPullPointRequest
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://docs.oasis-open.org/wsn/bw-2/PullPoint/GetMessagesRequest
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://docs.oasis-open.org/wsn/bw-2/PullPoint/Notify
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://docs.oasis-open.org/wsn/bw-2/SubscriptionManager/RenewRequest
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://docs.oasis-open.org/wsn/bw-2/SubscriptionManager/UnsubscribeRequest
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://docs.oasis-open.org/wsn/t-1
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://docs.oasis-open.org/wsrf/bf-2
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-soap-message-security-1.0#Base64Binary
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-username-token-profile-1.0#PasswordDigest
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-username-token-profile-1.0#PasswordText
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-secext-1.0.xsd
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-utility-1.0.xsd
Source: General_Beta_VMS_Win32_V2.2.1.16.T.20230306.exe String found in binary or memory: http://nsis.sf.net/NSIS_ErrorError
Source: VMS.exe, 00000007.00000003.2384526690.00000000069E2000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://schema.omg.org/spec/XMI/2.0
Source: VMS.exe, 00000007.00000003.2384526690.00000000069E2000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://schema.omg.org/spec/XMI/2.1
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://schemas.xmlsoap.org/soap/actor/next
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://schemas.xmlsoap.org/soap/actor/nextrefSOAP-ENC:refSOAP-ENC:itemTypeSOAP-ENC:arraySizeSOAP-ENV
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://schemas.xmlsoap.org/soap/encoding/
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://schemas.xmlsoap.org/soap/envelope/
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://schemas.xmlsoap.org/ws/2004/08/addressing
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/04/discovery
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/04/discovery/Probe
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/04/discovery/Probehttp://schemas.xmlsoap.org/ws/2005/04/discovery
Source: VMS.exe, 00000007.00000003.2384526690.00000000069E2000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.abisource.com/awml.dtd
Source: VMS.exe, 00000007.00000002.3586789771.00000000037C5000.00000004.00000001.01000000.00000027.sdmp String found in binary or memory: http://www.audiocoding.com/)
Source: VMS.exe, 00000007.00000003.2384526690.00000000069E2000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.daa.com.au/~james/dia-shape-ns
Source: VMS.exe, 00000007.00000003.2384526690.00000000069E2000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.freedesktop.org/standards/shared-mime-info
Source: VMS.exe, 00000007.00000003.2384526690.00000000069E2000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.gribuser.ru/xml/fictionbook/2.0
Source: VMS.exe, 00000007.00000003.2384526690.00000000069E2000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.lysator.liu.se/~alla/dia/
Source: VMS.exe, 00000007.00000003.2384526690.00000000069E2000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.metalinker.org/
Source: VMS.exe, 00000007.00000003.2384526690.00000000069E2000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.mozilla.org/keymaster/gatekeeper/there.is.only.xul
Source: VMS.exe, 00000007.00000002.3594127304.00000000070EC000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.mozilla.org2
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/analyticsdevice/wsdl/CreateAnalyticsEngineControl
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/analyticsdevice/wsdl/CreateAnalyticsEngineInputs
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/analyticsdevice/wsdl/DeleteAnalyticsEngineControl
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/analyticsdevice/wsdl/DeleteAnalyticsEngineInputs
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/analyticsdevice/wsdl/GetAnalyticsDeviceStreamUri
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/analyticsdevice/wsdl/GetAnalyticsEngine
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/analyticsdevice/wsdl/GetAnalyticsEngineControl
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/analyticsdevice/wsdl/GetAnalyticsEngineControls
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/analyticsdevice/wsdl/GetAnalyticsEngineInput
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/analyticsdevice/wsdl/GetAnalyticsEngineInputs
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/analyticsdevice/wsdl/GetAnalyticsEngines
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/analyticsdevice/wsdl/GetAnalyticsState
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/analyticsdevice/wsdl/GetServiceCapabilities
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/analyticsdevice/wsdl/GetVideoAnalyticsConfiguration
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/analyticsdevice/wsdl/SetAnalyticsEngineControl
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/analyticsdevice/wsdl/SetAnalyticsEngineInput
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/analyticsdevice/wsdl/SetVideoAnalyticsConfiguration
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/device/wsdl
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/device/wsdl/AddIPAddressFilter
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/device/wsdl/AddScopes
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/device/wsdl/CreateCertificate
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/device/wsdl/CreateDot1XConfiguration
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/device/wsdl/CreateUsers
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/device/wsdl/DeleteCertificates
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/device/wsdl/DeleteDot1XConfiguration
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/device/wsdl/DeleteUsers
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/device/wsdl/GetAccessPolicy
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/device/wsdl/GetCACertificates
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/device/wsdl/GetCapabilities
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/device/wsdl/GetCertificateInformation
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/device/wsdl/GetCertificates
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/device/wsdl/GetCertificatesStatus
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/device/wsdl/GetClientCertificateMode
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/device/wsdl/GetDNS
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/device/wsdl/GetDPAddresses
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/device/wsdl/GetDeviceInformation
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/device/wsdl/GetDiscoveryMode
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/device/wsdl/GetDot11Capabilities
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/device/wsdl/GetDot11Status
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/device/wsdl/GetDot1XConfiguration
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/device/wsdl/GetDot1XConfigurations
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/device/wsdl/GetDynamicDNS
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/device/wsdl/GetEndpointReference
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/device/wsdl/GetHostname
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/device/wsdl/GetIPAddressFilter
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/device/wsdl/GetNTP
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/device/wsdl/GetNetworkDefaultGateway
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/device/wsdl/GetNetworkInterfaces
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/device/wsdl/GetNetworkProtocols
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/device/wsdl/GetPkcs10Request
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/device/wsdl/GetRelayOutputs
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/device/wsdl/GetRemoteDiscoveryMode
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/device/wsdl/GetRemoteUser
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/device/wsdl/GetScopes
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/device/wsdl/GetServiceCapabilities
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/device/wsdl/GetServices
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/device/wsdl/GetSystemBackup
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/device/wsdl/GetSystemDateAndTime
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/device/wsdl/GetSystemLog
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/device/wsdl/GetSystemSupportInformation
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/device/wsdl/GetSystemUris
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/device/wsdl/GetUsers
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/device/wsdl/GetWsdlUrl
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/device/wsdl/GetZeroConfiguration
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/device/wsdl/LoadCACertificates
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/device/wsdl/LoadCertificateWithPrivateKey
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/device/wsdl/LoadCertificates
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/device/wsdl/RemoveIPAddressFilter
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/device/wsdl/RemoveScopes
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/device/wsdl/RestoreSystem
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/device/wsdl/ScanAvailableDot11Networks
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/device/wsdl/SendAuxiliaryCommand
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/device/wsdl/SetAccessPolicy
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/device/wsdl/SetCertificatesStatus
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/device/wsdl/SetClientCertificateMode
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/device/wsdl/SetDNS
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/device/wsdl/SetDPAddresses
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/device/wsdl/SetDiscoveryMode
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/device/wsdl/SetDot1XConfiguration
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/device/wsdl/SetDynamicDNS
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/device/wsdl/SetHostname
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/device/wsdl/SetHostnameFromDHCP
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/device/wsdl/SetIPAddressFilter
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/device/wsdl/SetNTP
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/device/wsdl/SetNetworkDefaultGateway
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/device/wsdl/SetNetworkInterfaces
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/device/wsdl/SetNetworkProtocols
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/device/wsdl/SetRelayOutputSettings
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/device/wsdl/SetRelayOutputState
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/device/wsdl/SetRemoteDiscoveryMode
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/device/wsdl/SetRemoteUser
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/device/wsdl/SetScopes
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/device/wsdl/SetSystemDateAndTime
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/device/wsdl/SetSystemFactoryDefault
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/device/wsdl/SetUser
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/device/wsdl/SetZeroConfiguration
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/device/wsdl/StartFirmwareUpgrade
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/device/wsdl/StartSystemRestore
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/device/wsdl/SystemReboot
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/device/wsdl/UpgradeSystemFirmware
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/display/wsdl/CreatePaneConfiguration
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/display/wsdl/DeletePaneConfiguration
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/display/wsdl/GetDisplayOptions
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/display/wsdl/GetLayout
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/display/wsdl/GetPaneConfiguration
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/display/wsdl/GetPaneConfigurations
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/display/wsdl/GetServiceCapabilities
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/display/wsdl/SetLayout
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/display/wsdl/SetPaneConfiguration
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/display/wsdl/SetPaneConfigurations
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/error
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/events/wsdl
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/events/wsdl/EventPortType/CreatePullPointSubscriptionRequest
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/events/wsdl/EventPortType/GetEventPropertiesRequest
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/events/wsdl/EventPortType/GetServiceCapabilities
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/events/wsdl/PullPointSubscription/PullMessagesRequest
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/events/wsdl/PullPointSubscription/SetSynchronizationPointRequest
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/media/wsdl
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/media/wsdl/
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/media/wsdl/AddAudioDecoderConfiguration
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/media/wsdl/AddAudioEncoderConfiguration
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/media/wsdl/AddAudioOutputConfiguration
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/media/wsdl/AddAudioSourceConfiguration
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/media/wsdl/AddMetadataConfiguration
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/media/wsdl/AddPTZConfiguration
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/media/wsdl/AddVideoAnalyticsConfiguration
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/media/wsdl/AddVideoEncoderConfiguration
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/media/wsdl/AddVideoSourceConfiguration
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/media/wsdl/CreateOSD
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/media/wsdl/CreateProfile
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/media/wsdl/DeleteOSD
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/media/wsdl/DeleteProfile
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/media/wsdl/GetAudioDecoderConfiguration
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/media/wsdl/GetAudioDecoderConfigurationOptions
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/media/wsdl/GetAudioDecoderConfigurations
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/media/wsdl/GetAudioEncoderConfiguration
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/media/wsdl/GetAudioEncoderConfigurationOptions
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/media/wsdl/GetAudioEncoderConfigurations
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/media/wsdl/GetAudioOutputConfiguration
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/media/wsdl/GetAudioOutputConfigurationOptions
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/media/wsdl/GetAudioOutputConfigurations
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/media/wsdl/GetAudioOutputs
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/media/wsdl/GetAudioSourceConfiguration
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/media/wsdl/GetAudioSourceConfigurationOptions
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/media/wsdl/GetAudioSources
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/media/wsdl/GetCompatibleAudioDecoderConfigurations
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/media/wsdl/GetCompatibleAudioEncoderConfigurations
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/media/wsdl/GetCompatibleAudioOutputConfigurations
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/media/wsdl/GetCompatibleAudioSourceConfigurations
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/media/wsdl/GetCompatibleMetadataConfigurations
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/media/wsdl/GetCompatibleVideoAnalyticsConfigurations
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/media/wsdl/GetCompatibleVideoEncoderConfigurations
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/media/wsdl/GetCompatibleVideoSourceConfigurations
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/media/wsdl/GetMetadataConfiguration
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/media/wsdl/GetMetadataConfigurationOptions
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/media/wsdl/GetMetadataConfigurations
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/media/wsdl/GetOSD
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/media/wsdl/GetOSDOptions
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/media/wsdl/GetOSDs
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/media/wsdl/GetProfiles
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/media/wsdl/GetServiceCapabilities
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/media/wsdl/GetSnapshotUri
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/media/wsdl/GetStreamUri
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/media/wsdl/GetVideoAnalyticsConfiguration
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/media/wsdl/GetVideoAnalyticsConfigurations
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/media/wsdl/GetVideoEncoderConfiguration
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/media/wsdl/GetVideoEncoderConfigurationOptions
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/media/wsdl/GetVideoEncoderConfigurations
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/media/wsdl/GetVideoSourceConfiguration
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/media/wsdl/GetVideoSourceConfigurations
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/media/wsdl/RemoveAudioDecoderConfiguration
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/media/wsdl/RemoveAudioEncoderConfiguration
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/media/wsdl/RemoveAudioOutputConfiguration
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/media/wsdl/RemoveAudioSourceConfiguration
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/media/wsdl/RemoveMetadataConfiguration
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/media/wsdl/RemovePTZConfiguration
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/media/wsdl/RemoveVideoAnalyticsConfiguration
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/media/wsdl/RemoveVideoEncoderConfiguration
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/media/wsdl/RemoveVideoSourceConfiguration
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/media/wsdl/SetAudioDecoderConfiguration
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/media/wsdl/SetAudioEncoderConfiguration
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/media/wsdl/SetAudioOutputConfiguration
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/media/wsdl/SetAudioSourceConfiguration
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/media/wsdl/SetMetadataConfiguration
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/media/wsdl/SetOSD
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/media/wsdl/SetSynchronizationPoint
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/media/wsdl/SetVideoAnalyticsConfiguration
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/media/wsdl/SetVideoEncoderConfiguration
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/media/wsdl/SetVideoSourceConfiguration
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/media/wsdl/StartMulticastStreaming
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/media/wsdl/StopMulticastStreaming
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/media/wsdlGetAudioSourceConfigurations/
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/media/wsdlGetProfile/
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/media/wsdlGetVideoSourceConfigurationOptions/
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/media/wsdlGetVideoSources/
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/network/wsdl
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/network/wsdl/Bye
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/network/wsdl/Hello
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/receiver/wsdl/ConfigureReceiver
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/receiver/wsdl/CreateReceiver
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/receiver/wsdl/DeleteReceiver
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/receiver/wsdl/GetReceiver
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/receiver/wsdl/GetReceiverState
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/receiver/wsdl/GetReceivers
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/receiver/wsdl/GetServiceCapabilities
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/receiver/wsdl/SetReceiverMode
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/recording/wsdl/CreateRecording
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/recording/wsdl/CreateRecordingJob
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/recording/wsdl/CreateTrack
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/recording/wsdl/DeleteRecording
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/recording/wsdl/DeleteRecordingJob
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/recording/wsdl/DeleteTrack
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/recording/wsdl/GetRecordingConfiguration
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/recording/wsdl/GetRecordingJobConfiguration
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/recording/wsdl/GetRecordingJobState
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/recording/wsdl/GetRecordingJobs
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/recording/wsdl/GetRecordings
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/recording/wsdl/GetServiceCapabilities
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/recording/wsdl/GetTrackConfiguration
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/recording/wsdl/SetRecordingConfiguration
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/recording/wsdl/SetRecordingJobConfiguration
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/recording/wsdl/SetRecordingJobMode
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/recording/wsdl/SetTrackConfiguration
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/replay/wsdl/GetReplayConfiguration
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/replay/wsdl/GetReplayUri
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/replay/wsdl/GetServiceCapabilities
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/replay/wsdl/SetReplayConfiguration
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/schema
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/schema/Receiver
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/search/wsdl/EndSearch
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/search/wsdl/FindEvents
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/search/wsdl/FindMetadata
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/search/wsdl/FindPTZPosition
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/search/wsdl/FindRecordings
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/search/wsdl/GetEventSearchResults
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/search/wsdl/GetMediaAttributes
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/search/wsdl/GetMetadataSearchResults
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/search/wsdl/GetPTZPositionSearchResults
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/search/wsdl/GetRecordingInformation
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/search/wsdl/GetRecordingSearchResults
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/search/wsdl/GetRecordingSummary
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/search/wsdl/GetSearchState
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/search/wsdl/GetServiceCapabilities
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver10/topics
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver20/analytics/wsdl/CreateAnalyticsModules
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver20/analytics/wsdl/CreateRules
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver20/analytics/wsdl/DeleteAnalyticsModules
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver20/analytics/wsdl/DeleteRules
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver20/analytics/wsdl/GetAnalyticsModules
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver20/analytics/wsdl/GetRules
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver20/analytics/wsdl/GetServiceCapabilities
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver20/analytics/wsdl/GetSupportedAnalyticsModules
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver20/analytics/wsdl/GetSupportedRules
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver20/analytics/wsdl/ModifyAnalyticsModules
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver20/analytics/wsdl/ModifyRules
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver20/imaging/wsdl
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver20/imaging/wsdl/FocusStop
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver20/imaging/wsdl/GetImagingSettings
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver20/imaging/wsdl/GetMoveOptions
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver20/imaging/wsdl/GetOptions
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver20/imaging/wsdl/GetServiceCapabilities
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver20/imaging/wsdl/GetStatus
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver20/imaging/wsdl/Move
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver20/imaging/wsdl/SetImagingSettings
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver20/ptz/wsdl
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver20/ptz/wsdl/AbsoluteMove
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver20/ptz/wsdl/ContinuousMove
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver20/ptz/wsdl/GetConfiguration
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver20/ptz/wsdl/GetConfigurationOptions
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver20/ptz/wsdl/GetConfigurations
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver20/ptz/wsdl/GetNode
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver20/ptz/wsdl/GetNodes
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver20/ptz/wsdl/GetPresets
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver20/ptz/wsdl/GetServiceCapabilities
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver20/ptz/wsdl/GetStatus
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver20/ptz/wsdl/GotoHomePosition
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver20/ptz/wsdl/GotoPreset
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver20/ptz/wsdl/RelativeMove
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver20/ptz/wsdl/RemovePreset
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver20/ptz/wsdl/SendAuxiliaryCommand
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver20/ptz/wsdl/SetConfiguration
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver20/ptz/wsdl/SetHomePosition
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver20/ptz/wsdl/SetPreset
Source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp String found in binary or memory: http://www.onvif.org/ver20/ptz/wsdl/Stop
Source: VMS.exe, 00000007.00000003.2384526690.00000000069E2000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.opengis.net/gml/3.2
Source: VMS.exe, 00000007.00000003.2384526690.00000000069E2000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.opengis.net/kml/2.2
Source: VMS.exe, 00000007.00000003.2384526690.00000000069E2000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.topografix.com/GPX/1/0
Source: VMS.exe, 00000007.00000003.2384526690.00000000069E2000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.topografix.com/GPX/1/1
Source: VMS.exe, 00000007.00000002.3617232960.0000000066390000.00000002.00000001.01000000.0000002E.sdmp String found in binary or memory: http://www.videolan.org/x264.html
Source: VMS.exe, 00000007.00000002.3580659593.0000000001221000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.zhongyicts.com.cn
Source: VMS.exe, 00000007.00000002.3617232960.0000000066390000.00000002.00000001.01000000.0000002E.sdmp String found in binary or memory: http://x265.org
Source: VMS.exe, 00000007.00000003.2384526690.00000000069E2000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://xspf.org/ns/0/
Source: VMS.exe, 00000007.00000002.3604576816.0000000010208000.00000002.00000001.01000000.0000001A.sdmp String found in binary or memory: https://%s/%s/%s/%s/%s.rs
Source: VMS.exe, 00000007.00000002.3604576816.0000000010208000.00000002.00000001.01000000.0000001A.sdmp String found in binary or memory: https://%s/%s/%s/%s/%s.rsWarnning
Source: VMS.exe, 00000007.00000002.3578680843.0000000000AB5000.00000002.00000001.01000000.0000000C.sdmp String found in binary or memory: https://app.xmeye.net/apps/latest/%1?type=windows
Source: VMS.exe, 00000007.00000000.2380249721.0000000000AB5000.00000002.00000001.01000000.0000000C.sdmp, VMS.exe, 00000007.00000002.3578680843.0000000000AB5000.00000002.00000001.01000000.0000000C.sdmp String found in binary or memory: https://app.xmeye.net/apps/latest/VMSProWIN32?type=windows
Source: VMS.exe, 00000007.00000000.2380249721.0000000000AB5000.00000002.00000001.01000000.0000000C.sdmp, VMS.exe, 00000007.00000002.3578680843.0000000000AB5000.00000002.00000001.01000000.0000000C.sdmp String found in binary or memory: https://app.xmeye.net/apps/latest/VMSProWIN32?type=windowsGet
Source: VMS.exe, 00000007.00000002.3604576816.0000000010208000.00000002.00000001.01000000.0000001A.sdmp String found in binary or memory: https://curl.se/docs/alt-svc.html
Source: VMS.exe, 00000007.00000002.3604576816.0000000010208000.00000002.00000001.01000000.0000001A.sdmp String found in binary or memory: https://curl.se/docs/http-cookies.html
Source: VMS.exe, 00000007.00000000.2380249721.0000000000AB5000.00000002.00000001.01000000.0000000C.sdmp, VMS.exe, 00000007.00000002.3578680843.0000000000AB5000.00000002.00000001.01000000.0000000C.sdmp String found in binary or memory: https://d.xmeye.net/
Source: VMS.exe, 00000007.00000000.2380249721.0000000000AB5000.00000002.00000001.01000000.0000000C.sdmp, VMS.exe, 00000007.00000002.3578680843.0000000000AB5000.00000002.00000001.01000000.0000000C.sdmp String found in binary or memory: https://d.xmeye.net/?shareInfo=?shareInfo=devIdloginNamepwdd:
Source: VMS.exe, 00000007.00000002.3588188088.0000000004225000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://rs.xmeye.net/faceCheckocx/v1/00000015449906/dece7107f0f523761c67edecec030240.rs
Source: VMS.exe, 00000007.00000002.3588188088.0000000004225000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://rs.xmeye.net/faceCheckocx/v1/00000015449906/dece7107f0f523761c67edecec030240.rs5449906/dece7
Source: VMS.exe, 00000007.00000002.3604576816.0000000010208000.00000002.00000001.01000000.0000001A.sdmp String found in binary or memory: https://www.openssl.org/docs/faq.html
Source: VMS.exe, 00000007.00000002.3604576816.0000000010208000.00000002.00000001.01000000.0000001A.sdmp String found in binary or memory: https://www.openssl.org/docs/faq.html....................crypto
Source: VMS.exe, 00000007.00000002.3580659593.0000000001221000.00000004.00000020.00020000.00000000.sdmp, VMS.exe, 00000007.00000002.3596963866.0000000008B23000.00000004.00000020.00020000.00000000.sdmp, VMS.exe, 00000007.00000000.2380249721.0000000000B8A000.00000002.00000001.01000000.0000000C.sdmp String found in binary or memory: https://www.xmeye.net/cloud_register_register_member
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49741
Source: unknown Network traffic detected: HTTP traffic on port 49741 -> 443
Source: unknown HTTPS traffic detected: 54.191.62.134:443 -> 192.168.2.4:49741 version: TLS 1.2
Source: VMS.exe, 00000007.00000002.3582743236.00000000018D9000.00000002.00000001.01000000.0000001D.sdmp Binary or memory string: DirectDrawCreateEx memstr_c4bcbefb-e
Source: C:\Program Files (x86)\VMS\VMS.exe Process Stats: CPU usage > 49%
Source: General_Beta_VMS_Win32_V2.2.1.16.T.20230306.exe Static PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE
Source: VMS.exe, 00000007.00000002.3624108546.0000000068797000.00000002.00000001.01000000.00000017.sdmp Binary or memory string: com.slnishinomiya.hyogo.jpkustanai.rucom.snpassenger-association.aerocom.sotsushima.nagasaki.jpcom.stuy.comx.seisa-geek.comcom.sv
Source: classification engine Classification label: sus21.winEXE@11/1028@2/6
Source: C:\Users\user\Desktop\General_Beta_VMS_Win32_V2.2.1.16.T.20230306.exe File created: C:\Program Files (x86)\VMS Jump to behavior
Source: C:\Users\user\Desktop\General_Beta_VMS_Win32_V2.2.1.16.T.20230306.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VMS Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Mutant created: NULL
Source: C:\Windows\System32\conhost.exe Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6372:120:WilError_03
Source: C:\Users\user\Desktop\General_Beta_VMS_Win32_V2.2.1.16.T.20230306.exe File created: C:\Users\user\AppData\Local\Temp\nsc258A.tmp Jump to behavior
Source: C:\Users\user\Desktop\General_Beta_VMS_Win32_V2.2.1.16.T.20230306.exe Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c ""C:\Program Files (x86)\VMS\MediaPlayer\register.bat""
Source: General_Beta_VMS_Win32_V2.2.1.16.T.20230306.exe Static PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: C:\Users\user\Desktop\General_Beta_VMS_Win32_V2.2.1.16.T.20230306.exe File read: C:\Users\desktop.ini Jump to behavior
Source: C:\Users\user\Desktop\General_Beta_VMS_Win32_V2.2.1.16.T.20230306.exe Key opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers Jump to behavior
Source: VMS.exe, 00000007.00000002.3614710395.0000000064AA9000.00000002.00000001.01000000.0000004B.sdmp Binary or memory string: INSERT INTO %Q.%s VALUES('index',%Q,%Q,#%d,%Q);
Source: VMS.exe, 00000007.00000002.3614710395.0000000064AA9000.00000002.00000001.01000000.0000004B.sdmp Binary or memory string: CREATE TABLE %Q.'%q_docsize'(docid INTEGER PRIMARY KEY, size BLOB);
Source: VMS.exe, 00000007.00000002.3614710395.0000000064AA9000.00000002.00000001.01000000.0000004B.sdmp Binary or memory string: CREATE TABLE IF NOT EXISTS %Q.'%q_stat'(id INTEGER PRIMARY KEY, value BLOB);
Source: VMS.exe, 00000007.00000002.3614710395.0000000064AA9000.00000002.00000001.01000000.0000004B.sdmp Binary or memory string: CREATE TABLE %Q.'%q_segdir'(level INTEGER,idx INTEGER,start_block INTEGER,leaves_end_block INTEGER,end_block INTEGER,root BLOB,PRIMARY KEY(level, idx));
Source: VMS.exe, 00000007.00000002.3614710395.0000000064AA9000.00000002.00000001.01000000.0000004B.sdmp Binary or memory string: UPDATE "%w".%s SET sql = sqlite_rename_parent(sql, %Q, %Q) WHERE %s;
Source: VMS.exe, 00000007.00000002.3614710395.0000000064AA9000.00000002.00000001.01000000.0000004B.sdmp Binary or memory string: UPDATE sqlite_temp_master SET sql = sqlite_rename_trigger(sql, %Q), tbl_name = %Q WHERE %s;
Source: VMS.exe, 00000007.00000002.3614710395.0000000064AA9000.00000002.00000001.01000000.0000004B.sdmp Binary or memory string: CREATE TABLE %Q.'%q_segments'(blockid INTEGER PRIMARY KEY, block BLOB);
Source: VMS.exe, 00000007.00000002.3614710395.0000000064AA9000.00000002.00000001.01000000.0000004B.sdmp Binary or memory string: UPDATE %Q.%s SET sql = CASE WHEN type = 'trigger' THEN sqlite_rename_trigger(sql, %Q)ELSE sqlite_rename_table(sql, %Q) END, tbl_name = %Q, name = CASE WHEN type='table' THEN %Q WHEN name LIKE 'sqlite_autoindex%%' AND type='index' THEN 'sqlite_autoindex_' || %Q || substr(name,%d+18) ELSE name END WHERE tbl_name=%Q COLLATE nocase AND (type='table' OR type='index' OR type='trigger');
Source: VMS.exe, 00000007.00000002.3614710395.0000000064AA9000.00000002.00000001.01000000.0000004B.sdmp Binary or memory string: CREATE TABLE "%w"."%w_parent"(nodeno INTEGER PRIMARY KEY,parentnode);
Source: C:\Users\user\Desktop\General_Beta_VMS_Win32_V2.2.1.16.T.20230306.exe File read: C:\Users\user\Desktop\General_Beta_VMS_Win32_V2.2.1.16.T.20230306.exe Jump to behavior
Source: unknown Process created: C:\Users\user\Desktop\General_Beta_VMS_Win32_V2.2.1.16.T.20230306.exe "C:\Users\user\Desktop\General_Beta_VMS_Win32_V2.2.1.16.T.20230306.exe"
Source: C:\Users\user\Desktop\General_Beta_VMS_Win32_V2.2.1.16.T.20230306.exe Process created: C:\Program Files (x86)\VMS\VMS.exe "C:\Program Files (x86)\VMS\VMS.exe"
Source: C:\Users\user\Desktop\General_Beta_VMS_Win32_V2.2.1.16.T.20230306.exe Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c ""C:\Program Files (x86)\VMS\MediaPlayer\register.bat""
Source: C:\Windows\SysWOW64\cmd.exe Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Windows\SysWOW64\cmd.exe Process created: C:\Windows\SysWOW64\regsvr32.exe regsvr32 /u -s "C:\Program Files (x86)\VMS\MediaPlayer\MediaDecFilter.ax"
Source: C:\Windows\SysWOW64\cmd.exe Process created: C:\Windows\SysWOW64\regsvr32.exe regsvr32 -s "C:\Program Files (x86)\VMS\MediaPlayer\MediaDecFilter.ax"
Source: C:\Users\user\Desktop\General_Beta_VMS_Win32_V2.2.1.16.T.20230306.exe Process created: C:\Program Files (x86)\VMS\VMS.exe "C:\Program Files (x86)\VMS\VMS.exe" Jump to behavior
Source: C:\Users\user\Desktop\General_Beta_VMS_Win32_V2.2.1.16.T.20230306.exe Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c ""C:\Program Files (x86)\VMS\MediaPlayer\register.bat"" Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exe Process created: C:\Windows\SysWOW64\regsvr32.exe regsvr32 /u -s "C:\Program Files (x86)\VMS\MediaPlayer\MediaDecFilter.ax" Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exe Process created: C:\Windows\SysWOW64\regsvr32.exe regsvr32 -s "C:\Program Files (x86)\VMS\MediaPlayer\MediaDecFilter.ax" Jump to behavior
Source: C:\Users\user\Desktop\General_Beta_VMS_Win32_V2.2.1.16.T.20230306.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Users\user\Desktop\General_Beta_VMS_Win32_V2.2.1.16.T.20230306.exe Section loaded: userenv.dll Jump to behavior
Source: C:\Users\user\Desktop\General_Beta_VMS_Win32_V2.2.1.16.T.20230306.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Users\user\Desktop\General_Beta_VMS_Win32_V2.2.1.16.T.20230306.exe Section loaded: propsys.dll Jump to behavior
Source: C:\Users\user\Desktop\General_Beta_VMS_Win32_V2.2.1.16.T.20230306.exe Section loaded: dwmapi.dll Jump to behavior
Source: C:\Users\user\Desktop\General_Beta_VMS_Win32_V2.2.1.16.T.20230306.exe Section loaded: cryptbase.dll Jump to behavior
Source: C:\Users\user\Desktop\General_Beta_VMS_Win32_V2.2.1.16.T.20230306.exe Section loaded: oleacc.dll Jump to behavior
Source: C:\Users\user\Desktop\General_Beta_VMS_Win32_V2.2.1.16.T.20230306.exe Section loaded: ntmarta.dll Jump to behavior
Source: C:\Users\user\Desktop\General_Beta_VMS_Win32_V2.2.1.16.T.20230306.exe Section loaded: version.dll Jump to behavior
Source: C:\Users\user\Desktop\General_Beta_VMS_Win32_V2.2.1.16.T.20230306.exe Section loaded: shfolder.dll Jump to behavior
Source: C:\Users\user\Desktop\General_Beta_VMS_Win32_V2.2.1.16.T.20230306.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Users\user\Desktop\General_Beta_VMS_Win32_V2.2.1.16.T.20230306.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Users\user\Desktop\General_Beta_VMS_Win32_V2.2.1.16.T.20230306.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Users\user\Desktop\General_Beta_VMS_Win32_V2.2.1.16.T.20230306.exe Section loaded: textinputframework.dll Jump to behavior
Source: C:\Users\user\Desktop\General_Beta_VMS_Win32_V2.2.1.16.T.20230306.exe Section loaded: coreuicomponents.dll Jump to behavior
Source: C:\Users\user\Desktop\General_Beta_VMS_Win32_V2.2.1.16.T.20230306.exe Section loaded: coremessaging.dll Jump to behavior
Source: C:\Users\user\Desktop\General_Beta_VMS_Win32_V2.2.1.16.T.20230306.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\Desktop\General_Beta_VMS_Win32_V2.2.1.16.T.20230306.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\Desktop\General_Beta_VMS_Win32_V2.2.1.16.T.20230306.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\Desktop\General_Beta_VMS_Win32_V2.2.1.16.T.20230306.exe Section loaded: textshaping.dll Jump to behavior
Source: C:\Users\user\Desktop\General_Beta_VMS_Win32_V2.2.1.16.T.20230306.exe Section loaded: riched20.dll Jump to behavior
Source: C:\Users\user\Desktop\General_Beta_VMS_Win32_V2.2.1.16.T.20230306.exe Section loaded: usp10.dll Jump to behavior
Source: C:\Users\user\Desktop\General_Beta_VMS_Win32_V2.2.1.16.T.20230306.exe Section loaded: msls31.dll Jump to behavior
Source: C:\Users\user\Desktop\General_Beta_VMS_Win32_V2.2.1.16.T.20230306.exe Section loaded: profapi.dll Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Section loaded: qt5core.dll Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Section loaded: qt5gui.dll Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Section loaded: qt5widgets.dll Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Section loaded: qt5network.dll Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Section loaded: qt5sql.dll Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Section loaded: cmsclient.dll Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Section loaded: qt5multimedia.dll Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Section loaded: msvcp140.dll Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Section loaded: opencv_world460.dll Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Section loaded: libzbar-0.dll Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Section loaded: qzxing3.dll Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Section loaded: dbghelp.dll Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Section loaded: vcruntime140.dll Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Section loaded: qt5core.dll Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Section loaded: msvcp140.dll Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Section loaded: vcruntime140.dll Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Section loaded: qt5core.dll Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Section loaded: dwmapi.dll Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Section loaded: msvcp140.dll Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Section loaded: vcruntime140.dll Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Section loaded: qt5core.dll Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Section loaded: vcruntime140.dll Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Section loaded: qt5core.dll Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Section loaded: dnsapi.dll Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Section loaded: iphlpapi.dll Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Section loaded: qt5core.dll Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Section loaded: qt5multimedia.dll Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Section loaded: configmodule.dll Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Section loaded: cloudclientapi.dll Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Section loaded: netsdk.dll Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Section loaded: h264play.dll Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Section loaded: streamreader.dll Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Section loaded: msvcp140.dll Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Section loaded: opengl32.dll Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Section loaded: glew32.dll Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Section loaded: vrsoft.dll Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Section loaded: dhplay.dll Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Section loaded: playctrl.dll Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Section loaded: dhnetsdk.dll Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Section loaded: hcnetsdk.dll Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Section loaded: libonvifclient.dll Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Section loaded: vcruntime140.dll Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Section loaded: msvcp140.dll Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Section loaded: vcruntime140.dll Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Section loaded: vcruntime140.dll Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Section loaded: qt5core.dll Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Section loaded: vcruntime140.dll Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Section loaded: winmm.dll Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Section loaded: libiconv.dll Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Section loaded: msvcr120.dll Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Section loaded: qt5core.dll Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Section loaded: vcruntime140.dll Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Section loaded: mpr.dll Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Section loaded: version.dll Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Section loaded: winmm.dll Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Section loaded: streamreader.dll Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Section loaded: winmm.dll Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Section loaded: wsock32.dll Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Section loaded: opengl32.dll Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Section loaded: opengl32.dll Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Section loaded: hccore.dll Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Section loaded: glu32.dll Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Section loaded: mfplat.dll Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Section loaded: mf.dll Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Section loaded: mfreadwrite.dll Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Section loaded: dxgi.dll Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Section loaded: d3d11.dll Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Section loaded: concrt140.dll Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Section loaded: mswsock.dll Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Section loaded: mfcore.dll Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Section loaded: powrprof.dll Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Section loaded: ksuser.dll Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Section loaded: mfperfhelper.dll Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Section loaded: cryptbase.dll Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Section loaded: ddraw.dll Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Section loaded: avcodec.dll Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Section loaded: avutil.dll Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Section loaded: streamreader.dll Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Section loaded: openal32.dll Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Section loaded: dsound.dll Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Section loaded: ddraw.dll Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Section loaded: dciman32.dll Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Section loaded: superrender.dll Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Section loaded: audiorender.dll Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Section loaded: dbgcore.dll Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Section loaded: winmmbase.dll Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Section loaded: swresample.dll Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Section loaded: vcomp140.dll Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Section loaded: d3dx9_43.dll Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Section loaded: umpdc.dll Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Section loaded: opencl.dll Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Section loaded: avnetsdk.dll Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Section loaded: infra.dll Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Section loaded: stream.dll Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Section loaded: netframework.dll Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Section loaded: streamsvr.dll Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Section loaded: json.dll Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Section loaded: infra.dll Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Section loaded: json.dll Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Section loaded: dhconfigsdk.dll Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Section loaded: rtworkq.dll Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Section loaded: wintab32.dll Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Section loaded: profapi.dll Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Section loaded: qt5svg.dll Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Section loaded: rasadhlp.dll Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Section loaded: fwpuclnt.dll Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Section loaded: cryptsp.dll Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Section loaded: rsaenh.dll Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Section loaded: dhcpcsvc.dll Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Section loaded: dwrite.dll Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Section loaded: dataexchange.dll Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Section loaded: dcomp.dll Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Section loaded: twinapi.appcore.dll Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Section loaded: textinputframework.dll Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Section loaded: coreuicomponents.dll Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Section loaded: coremessaging.dll Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Section loaded: ntmarta.dll Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Section loaded: coremessaging.dll Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exe Section loaded: cmdext.dll Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Windows\SysWOW64\regsvr32.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Windows\SysWOW64\regsvr32.exe Section loaded: aclayers.dll Jump to behavior
Source: C:\Windows\SysWOW64\regsvr32.exe Section loaded: mpr.dll Jump to behavior
Source: C:\Windows\SysWOW64\regsvr32.exe Section loaded: sfc.dll Jump to behavior
Source: C:\Windows\SysWOW64\regsvr32.exe Section loaded: sfc_os.dll Jump to behavior
Source: C:\Windows\SysWOW64\regsvr32.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Windows\SysWOW64\regsvr32.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Windows\SysWOW64\regsvr32.exe Section loaded: winmm.dll Jump to behavior
Source: C:\Windows\SysWOW64\regsvr32.exe Section loaded: h264play.dll Jump to behavior
Source: C:\Windows\SysWOW64\regsvr32.exe Section loaded: ddraw.dll Jump to behavior
Source: C:\Windows\SysWOW64\regsvr32.exe Section loaded: streamreader.dll Jump to behavior
Source: C:\Windows\SysWOW64\regsvr32.exe Section loaded: dxgi.dll Jump to behavior
Source: C:\Windows\SysWOW64\regsvr32.exe Section loaded: dciman32.dll Jump to behavior
Source: C:\Windows\SysWOW64\regsvr32.exe Section loaded: quartz.dll Jump to behavior
Source: C:\Windows\SysWOW64\regsvr32.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Windows\SysWOW64\regsvr32.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Windows\SysWOW64\regsvr32.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Windows\SysWOW64\regsvr32.exe Section loaded: aclayers.dll Jump to behavior
Source: C:\Windows\SysWOW64\regsvr32.exe Section loaded: mpr.dll Jump to behavior
Source: C:\Windows\SysWOW64\regsvr32.exe Section loaded: sfc.dll Jump to behavior
Source: C:\Windows\SysWOW64\regsvr32.exe Section loaded: sfc_os.dll Jump to behavior
Source: C:\Windows\SysWOW64\regsvr32.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Windows\SysWOW64\regsvr32.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Windows\SysWOW64\regsvr32.exe Section loaded: winmm.dll Jump to behavior
Source: C:\Windows\SysWOW64\regsvr32.exe Section loaded: h264play.dll Jump to behavior
Source: C:\Windows\SysWOW64\regsvr32.exe Section loaded: ddraw.dll Jump to behavior
Source: C:\Windows\SysWOW64\regsvr32.exe Section loaded: streamreader.dll Jump to behavior
Source: C:\Windows\SysWOW64\regsvr32.exe Section loaded: dxgi.dll Jump to behavior
Source: C:\Windows\SysWOW64\regsvr32.exe Section loaded: dciman32.dll Jump to behavior
Source: C:\Windows\SysWOW64\regsvr32.exe Section loaded: quartz.dll Jump to behavior
Source: C:\Windows\SysWOW64\regsvr32.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Windows\SysWOW64\regsvr32.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Windows\SysWOW64\regsvr32.exe Section loaded: devenum.dll Jump to behavior
Source: C:\Users\user\Desktop\General_Beta_VMS_Win32_V2.2.1.16.T.20230306.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}\InProcServer32 Jump to behavior
Source: C:\Users\user\Desktop\General_Beta_VMS_Win32_V2.2.1.16.T.20230306.exe File written: C:\Users\user\AppData\Local\Temp\nsx26F3.tmp\ioSpecial.ini Jump to behavior
Source: C:\Users\user\Desktop\General_Beta_VMS_Win32_V2.2.1.16.T.20230306.exe Automated click: OK
Source: C:\Users\user\Desktop\General_Beta_VMS_Win32_V2.2.1.16.T.20230306.exe Automated click: Next >
Source: C:\Users\user\Desktop\General_Beta_VMS_Win32_V2.2.1.16.T.20230306.exe Automated click: Install
Source: Window Recorder Window detected: More than 3 window changes detected
Source: General_Beta_VMS_Win32_V2.2.1.16.T.20230306.exe Static file information: File size 90115974 > 1048576
Source: C:\Program Files (x86)\VMS\VMS.exe File opened: C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.9672_none_d08f9da24428a513\MSVCR80.dll Jump to behavior
Source: General_Beta_VMS_Win32_V2.2.1.16.T.20230306.exe Static PE information: DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
Source: Binary string: Extract: NetSdk.pdb source: General_Beta_VMS_Win32_V2.2.1.16.T.20230306.exe, 00000000.00000003.2381467220.00000000007DB000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: e:\workspace\SNS\CMS\Trunk\VMS\Trunk\Dest\Win32\bin\Release_MultiVendor\XMCloudClientAPI.pdb source: VMS.exe, 00000007.00000002.3623190698.00000000684A2000.00000002.00000001.01000000.00000019.sdmp
Source: Binary string: C:\Users\qt\work\qt\qtsvg\plugins\imageformats\qsvg.pdb source: VMS.exe, 00000007.00000002.3613325792.00000000648A3000.00000002.00000001.01000000.00000045.sdmp
Source: Binary string: d3dx9_43.pdb source: VMS.exe, 00000007.00000002.3615414852.0000000064F71000.00000020.00000001.01000000.00000031.sdmp
Source: Binary string: \plugins\sqldriversqsqlite.dllqsqlmysql.dllqsqlodbc.dllqsqlpsql.dllpostproc.dllProcessMan.exeQt5Core.dllQt5Gui.dllQt5Multimedia.dllQt5Network.dllQt5Sql.dllQt5Svg.dllQt5Widgets.dllqwt.dllQZXing3.dllRecordPlan.exeRecordPlan.pdbRestoreData.exe source: General_Beta_VMS_Win32_V2.2.1.16.T.20230306.exe, 00000000.00000003.2514332406.0000000000761000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\projects\ffmpeg\build_out\lib\x86\avcodec.pdb source: VMS.exe, 00000007.00000002.3617232960.0000000066542000.00000002.00000001.01000000.0000002E.sdmp
Source: Binary string: D:\project\dhlog\bin\x86\release\dhlog.pdb source: VMS.exe, 00000007.00000002.3615281278.0000000064F2C000.00000002.00000001.01000000.00000033.sdmp
Source: Binary string: D:\SVN\VMS_OEM\VMS\Dest\Win32\temp\Release_MultiVendor\vc140.pdb source: General_Beta_VMS_Win32_V2.2.1.16.T.20230306.exe, 00000000.00000002.2515880950.0000000002CE9000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: D:\project\dhlog\bin\x86\release\dhlog.pdb source: VMS.exe, 00000007.00000002.3615281278.0000000064F2C000.00000002.00000001.01000000.00000033.sdmp
Source: Binary string: e:\jk_w32\workspace\CBB_DH3.RD000692_PlaySDKV3.40\Lib\Win32\vs2005shared\dhplay.pdb source: VMS.exe, 00000007.00000002.3582743236.00000000018D9000.00000002.00000001.01000000.0000001D.sdmp
Source: Binary string: C:\Users\qt\work\qt\qtbase\plugins\imageformats\qico.pdb source: VMS.exe, 00000007.00000002.3613913981.0000000064905000.00000002.00000001.01000000.00000043.sdmp
Source: Binary string: concrt140.i386.pdbGCTL source: VMS.exe, 00000007.00000002.3619266175.00000000676A1000.00000020.00000001.01000000.00000026.sdmp
Source: Binary string: lD:\SVN\VMS_OEM\VMS\Dest\Win32\bin\Release_MultiVendor\ConfigModule.pdbQQ source: VMS.exe, 00000007.00000002.3623585268.00000000684DB000.00000002.00000001.01000000.00000018.sdmp
Source: Binary string: \trunk\WindowsAudioRender\bin\AudioRender.pdb source: VMS.exe, 00000007.00000002.3616141917.0000000065261000.00000002.00000001.01000000.0000002D.sdmp
Source: Binary string: Extract: RecordPlan.pdb(7oB source: General_Beta_VMS_Win32_V2.2.1.16.T.20230306.exe, 00000000.00000003.2381467220.00000000007DB000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: Extract: H264Play.pdb source: General_Beta_VMS_Win32_V2.2.1.16.T.20230306.exe, 00000000.00000002.2515621604.00000000007C7000.00000004.00000020.00020000.00000000.sdmp, General_Beta_VMS_Win32_V2.2.1.16.T.20230306.exe, 00000000.00000003.2514016055.00000000007BF000.00000004.00000020.00020000.00000000.sdmp, General_Beta_VMS_Win32_V2.2.1.16.T.20230306.exe, 00000000.00000003.2514480181.00000000007C6000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\Users\qt\work\qt\qtbase\plugins\imageformats\qgif.pdb!! source: VMS.exe, 00000007.00000002.3614480980.0000000064925000.00000002.00000001.01000000.00000041.sdmp
Source: Binary string: C:\Users\qt\work\qt\qtsvg\lib\Qt5Svg.pdb source: VMS.exe, 00000007.00000002.3613077945.0000000064877000.00000002.00000001.01000000.00000046.sdmp
Source: Binary string: \VMS.lnkAVApis.dllavcodec.dllavdevice.dllavfilter.dllavformat.dllavnetsdk.dllavutil.dllCloudClientAPI.dllCMSClient.dllCMSClient.pdbconfig.iniconcrt140.dllConfigModule.dllConfigModule.pdbd3dx9_24.dllD3DX9_43.dllDhDecode.dlldhlog.dlldhnetsdk.dlldhplay.dlldhplay.pdbDllDeinterlace.dllErrorReport.exefisheye.dllgdiplus.dllglew32.dllH264Play.dllH264Play.pdbh264_enc.dllHCCore.dllHCNetSDK.dll source: General_Beta_VMS_Win32_V2.2.1.16.T.20230306.exe, 00000000.00000003.2514332406.0000000000761000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: vcruntime140.i386.pdbGCTL source: VMS.exe, 00000007.00000002.3624932255.0000000068991000.00000020.00000001.01000000.00000016.sdmp
Source: Binary string: Extract: CMSClient.pdb source: General_Beta_VMS_Win32_V2.2.1.16.T.20230306.exe, 00000000.00000002.2515621604.00000000007C7000.00000004.00000020.00020000.00000000.sdmp, General_Beta_VMS_Win32_V2.2.1.16.T.20230306.exe, 00000000.00000003.2514016055.00000000007BF000.00000004.00000020.00020000.00000000.sdmp, General_Beta_VMS_Win32_V2.2.1.16.T.20230306.exe, 00000000.00000003.2514480181.00000000007C6000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\Users\qt\work\qt\qtimageformats\plugins\imageformats\qwebp.pdb source: VMS.exe, 00000007.00000002.3611885650.00000000647B0000.00000002.00000001.01000000.0000004A.sdmp
Source: Binary string: y:\StreamMedia\StreamSvr_Third\Lib\Release\Win32\vs2005\StreamSvr.pdb source: VMS.exe, 00000007.00000002.3591298660.0000000005F8F000.00000002.00000001.01000000.00000038.sdmp
Source: Binary string: \streamParser\bin\Release\StreamReader.pdb source: VMS.exe, 00000007.00000002.3581948713.000000000159A000.00000002.00000001.01000000.0000001C.sdmp
Source: Binary string: G:\subversion\vrsoft\Source\Windows_SupportWin64\VRSoftDll\VRSoft\Release\VRSoft.pdb source: General_Beta_VMS_Win32_V2.2.1.16.T.20230306.exe, 00000000.00000002.2515880950.00000000027A9000.00000004.00000020.00020000.00000000.sdmp, VMS.exe, 00000007.00000002.3622223790.00000000683EE000.00000002.00000001.01000000.0000001F.sdmp
Source: Binary string: D:\Programming\My Projects\CodeProject\HowToBuildLibiconv\LibIconv_Build_1_14\Release_Win32\libiconv.pdb@W source: VMS.exe, 00000007.00000002.3621017751.000000006813A000.00000002.00000001.01000000.00000022.sdmp
Source: Binary string: D:\Workplace\QRCodeRecognition\QRCodeRecognition\bin\QZXing3.pdb source: VMS.exe, 00000007.00000002.3625277789.0000000068C35000.00000002.00000001.01000000.00000015.sdmp
Source: Binary string: c:\users\xmuser\documents\visual studio 2005\projects\multilendlltest\release\XMDrift.pdb` source: General_Beta_VMS_Win32_V2.2.1.16.T.20230306.exe, 00000000.00000002.2515880950.0000000002CE9000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: Extract: dhplay.pdbQ" source: General_Beta_VMS_Win32_V2.2.1.16.T.20230306.exe, 00000000.00000002.2515621604.00000000007C7000.00000004.00000020.00020000.00000000.sdmp, General_Beta_VMS_Win32_V2.2.1.16.T.20230306.exe, 00000000.00000003.2514016055.00000000007BF000.00000004.00000020.00020000.00000000.sdmp, General_Beta_VMS_Win32_V2.2.1.16.T.20230306.exe, 00000000.00000003.2514480181.00000000007C6000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: Extract: StreamReader.pdb\ source: General_Beta_VMS_Win32_V2.2.1.16.T.20230306.exe, 00000000.00000003.2340704802.0000000003B31000.00000004.00000020.00020000.00000000.sdmp, General_Beta_VMS_Win32_V2.2.1.16.T.20230306.exe, 00000000.00000003.2381417690.0000000003B32000.00000004.00000020.00020000.00000000.sdmp, General_Beta_VMS_Win32_V2.2.1.16.T.20230306.exe, 00000000.00000002.2516791909.0000000003B32000.00000004.00000020.00020000.00000000.sdmp, General_Beta_VMS_Win32_V2.2.1.16.T.20230306.exe, 00000000.00000003.2513496848.0000000003B32000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\Users\qt\work\qt\qtbase\plugins\sqldrivers\qsqlite.pdb source: VMS.exe, 00000007.00000002.3614710395.0000000064AA9000.00000002.00000001.01000000.0000004B.sdmp
Source: Binary string: d:\workspace\NetFramework\Trunk\Lib\Win32\d_r_mt\NetFramework.pdb source: VMS.exe, 00000007.00000002.3590932119.0000000005EAF000.00000002.00000001.01000000.00000037.sdmp
Source: Binary string: \bin\netsdk\x86\release\NetSdk.pdb source: VMS.exe, 00000007.00000002.3604576816.0000000010208000.00000002.00000001.01000000.0000001A.sdmp
Source: Binary string: C:\Users\qt\work\qt\qtbase\plugins\sqldrivers\qsqlite.pdb!! source: VMS.exe, 00000007.00000002.3614710395.0000000064AA9000.00000002.00000001.01000000.0000004B.sdmp
Source: Binary string: vcomp140.i386.pdb source: VMS.exe, 00000007.00000002.3615730948.0000000065171000.00000020.00000001.01000000.00000030.sdmp
Source: Binary string: <glob pattern="*.pdb"/> source: VMS.exe, 00000007.00000003.2384526690.00000000069E2000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\projects\ffmpeg\build_out\lib\x86\swresample.pdb source: VMS.exe, 00000007.00000002.3615955851.00000000651D6000.00000002.00000001.01000000.0000002F.sdmp
Source: Binary string: \translations\RecoveryDataRussian.qmSimpChinese_Qt.qmvccorlib140.dllvcomp140.dllvcruntime140.dllvcruntime140d.dllvcruntime140_1.dllversion.txtVMS.pdbVMS source: General_Beta_VMS_Win32_V2.2.1.16.T.20230306.exe, 00000000.00000003.2514332406.0000000000761000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: e:\SuperRender\2015\7\7.16-Ex\bin\SuperRender_privite.pdb source: VMS.exe, 00000007.00000002.3588000071.0000000003FFE000.00000002.00000001.01000000.0000002C.sdmp
Source: Binary string: e:\Project\MediaPlayControl\mpCtrl_win32_Base\Dll_OUT\win32\PDB\PlayCtrl.pdb source: VMS.exe, 00000007.00000002.3587543708.0000000003EB1000.00000002.00000001.01000000.00000029.sdmp
Source: Binary string: C:\Users\qt\work\qt\qtimageformats\plugins\imageformats\qtiff.pdbBB source: VMS.exe, 00000007.00000002.3612469905.000000006480C000.00000002.00000001.01000000.00000048.sdmp
Source: Binary string: C:\Users\qt\work\qt\qtbase\lib\Qt5Core.pdb9 source: VMS.exe, 00000007.00000002.3624108546.00000000688CC000.00000002.00000001.01000000.00000017.sdmp
Source: Binary string: Extract: VMS.pdb source: General_Beta_VMS_Win32_V2.2.1.16.T.20230306.exe, 00000000.00000003.2341120922.00000000007FD000.00000004.00000020.00020000.00000000.sdmp, General_Beta_VMS_Win32_V2.2.1.16.T.20230306.exe, 00000000.00000003.2341081966.00000000007F5000.00000004.00000020.00020000.00000000.sdmp, General_Beta_VMS_Win32_V2.2.1.16.T.20230306.exe, 00000000.00000003.2381359571.0000000000801000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: D:\jenkins\workspace\APP_Package_SDK_Windows32\common\HCNetSDK\VS2013\lib\win32\HCCore.pdb source: VMS.exe, 00000007.00000002.3619714056.0000000067D80000.00000002.00000001.01000000.00000025.sdmp
Source: Binary string: D:\SVN\VMS_OEM\VMS\Dest\Win32\bin\Release_MultiVendor\VMS.pdb source: VMS.exe, 00000007.00000000.2380249721.0000000000B8A000.00000002.00000001.01000000.0000000C.sdmp
Source: Binary string: C:\Users\qt\work\qt\qtbase\lib\Qt5Core.pdb source: VMS.exe, 00000007.00000002.3624108546.00000000688CC000.00000002.00000001.01000000.00000017.sdmp
Source: Binary string: C:\Users\qt\work\qt\qtimageformats\plugins\imageformats\qtiff.pdb source: VMS.exe, 00000007.00000002.3612469905.000000006480C000.00000002.00000001.01000000.00000048.sdmp
Source: Binary string: C:\Users\qt\work\qt\qtbase\plugins\imageformats\qgif.pdb source: VMS.exe, 00000007.00000002.3614480980.0000000064925000.00000002.00000001.01000000.00000041.sdmp
Source: Binary string: *.pdb source: VMS.exe, 00000007.00000002.3593071572.0000000006C10000.00000004.00000020.00020000.00000000.sdmp, VMS.exe, 00000007.00000002.3593258932.0000000006D7E000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: c:\users\xmuser\documents\visual studio 2005\projects\multilendlltest\release\XMDrift.pdb source: General_Beta_VMS_Win32_V2.2.1.16.T.20230306.exe, 00000000.00000002.2515880950.0000000002CE9000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\Users\qt\work\qt\qtimageformats\plugins\imageformats\qtga.pdb source: VMS.exe, 00000007.00000002.3612771939.0000000064843000.00000002.00000001.01000000.00000047.sdmp
Source: Binary string: m)D:\SVN\VMS_OEM\VMS\Dest\Win32\bin\Release_MultiVendor\VMS.pdb source: VMS.exe, 00000007.00000000.2380249721.0000000000B8A000.00000002.00000001.01000000.0000000C.sdmp
Source: Binary string: D:\Programming\My Projects\CodeProject\HowToBuildLibiconv\LibIconv_Build_1_14\Release_Win32\libiconv.pdb source: VMS.exe, 00000007.00000002.3621017751.000000006813A000.00000002.00000001.01000000.00000022.sdmp
Source: Binary string: C:\Users\qt\work\qt\qtimageformats\plugins\imageformats\qicns.pdb source: VMS.exe, 00000007.00000002.3614193607.0000000064915000.00000002.00000001.01000000.00000042.sdmp
Source: Binary string: vcruntime140.i386.pdb source: VMS.exe, 00000007.00000002.3624932255.0000000068991000.00000020.00000001.01000000.00000016.sdmp
Source: Binary string: D:\jenkins\workspace\APP_Package_SDK_Windows32\common\HCNetSDK\VS2013\lib\win32\HCNetSDK.pdb source: VMS.exe, 00000007.00000002.3621567654.0000000068398000.00000002.00000001.01000000.00000021.sdmp
Source: Binary string: \Release\H264Play.pdb source: VMS.exe, 00000007.00000002.3581441637.0000000001519000.00000002.00000001.01000000.0000001B.sdmp
Source: Binary string: \bin\netsdk\x86\release\NetSdk.pdb\m( source: VMS.exe, 00000007.00000002.3604576816.0000000010208000.00000002.00000001.01000000.0000001A.sdmp
Source: Binary string: \modeldetect.caffemodeldetect.prototxtsr.caffemodelsr.prototxtMP_Render.dllMP_VIE.dllmsvcm80.dllmsvcm90.dllmsvcp80.dllmsvcp90.dllmsvcp140.dllmsvcr120.dllmsvcr80.dllNetFramework.dllNetSdk.dllNetSdk.pdbopencv_img_hash460.dllopencv_videoio_ffmpeg460.dllopencv_world460.dllPeerSDK.dll source: General_Beta_VMS_Win32_V2.2.1.16.T.20230306.exe, 00000000.00000003.2514332406.0000000000761000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\projects\ffmpeg\build_out\lib\x86\avutil.pdb source: VMS.exe, 00000007.00000002.3618992177.00000000670B3000.00000002.00000001.01000000.0000002A.sdmp
Source: Binary string: C:\Users\qt\work\qt\qtbase\plugins\imageformats\qico.pdb"" source: VMS.exe, 00000007.00000002.3613913981.0000000064905000.00000002.00000001.01000000.00000043.sdmp
Source: Binary string: msvcr120.i386.pdb source: VMS.exe, 00000007.00000002.3620370718.0000000068031000.00000020.00000001.01000000.00000023.sdmp
Source: Binary string: vcomp140.i386.pdbGCTL source: VMS.exe, 00000007.00000002.3615730948.0000000065171000.00000020.00000001.01000000.00000030.sdmp
Source: Binary string: \sound\TradChinesessleay32.dllStream.dllStreamReader.pdbStreamSvr.dllSuperRender.dllswresample.dllswscale.dll source: General_Beta_VMS_Win32_V2.2.1.16.T.20230306.exe, 00000000.00000003.2514332406.0000000000761000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: d:\SVN\Sofia\NetIP\Trunk\Onvif_client1\Onvif_client\release\libonvifclient.pdb source: VMS.exe, 00000007.00000002.3587107914.0000000003998000.00000002.00000001.01000000.00000028.sdmp
Source: Binary string: C:\Users\qt\work\qt\qtbase\plugins\imageformats\qjpeg.pdbPP source: VMS.exe, 00000007.00000002.3613627894.00000000648E6000.00000002.00000001.01000000.00000044.sdmp
Source: Binary string: D:\SVN\VMS_OEM\VMS\Dest\Win32\bin\Release_MultiVendor\ConfigModule.pdb source: VMS.exe, 00000007.00000002.3623585268.00000000684DB000.00000002.00000001.01000000.00000018.sdmp
Source: Binary string: concrt140.i386.pdb source: VMS.exe, 00000007.00000002.3619266175.00000000676A1000.00000020.00000001.01000000.00000026.sdmp
Source: Binary string: e:\SuperRender\2015\7\7.16-Ex\bin\SuperRender_privite.pdb8 source: VMS.exe, 00000007.00000002.3588000071.0000000003FFE000.00000002.00000001.01000000.0000002C.sdmp
Source: Binary string: C:\Users\qt\work\qt\qtsvg\lib\Qt5Svg.pdb,, source: VMS.exe, 00000007.00000002.3613077945.0000000064877000.00000002.00000001.01000000.00000046.sdmp
Source: Binary string: C:\Users\qt\work\qt\qtbase\plugins\platforms\qwindows.pdb source: VMS.exe, 00000007.00000002.3614954025.0000000064BA2000.00000002.00000001.01000000.0000003D.sdmp
Source: Binary string: C:\Users\qt\work\qt\qtbase\plugins\imageformats\qjpeg.pdb source: VMS.exe, 00000007.00000002.3613627894.00000000648E6000.00000002.00000001.01000000.00000044.sdmp
Source: Binary string: C:\Users\qt\work\qt\qtimageformats\plugins\imageformats\qwbmp.pdb source: VMS.exe, 00000007.00000002.3612170234.00000000647D3000.00000002.00000001.01000000.00000049.sdmp
Source: nsProcess.dll.0.dr Static PE information: real checksum: 0x0 should be: 0x10849
Source: LangDLL.dll.0.dr Static PE information: real checksum: 0x0 should be: 0x104fe
Source: AudioRender.dll.0.dr Static PE information: real checksum: 0x383fc should be: 0x1fe1a
Source: InstallOptions.dll.0.dr Static PE information: real checksum: 0x0 should be: 0xf13f
Source: C:\Users\user\Desktop\General_Beta_VMS_Win32_V2.2.1.16.T.20230306.exe File created: C:\Users\user\AppData\Local\Temp\nsx26F3.tmp\nsProcess.dll Jump to dropped file
Source: C:\Users\user\Desktop\General_Beta_VMS_Win32_V2.2.1.16.T.20230306.exe File created: C:\Program Files (x86)\VMS\AudioRender.dll Jump to dropped file
Source: C:\Users\user\Desktop\General_Beta_VMS_Win32_V2.2.1.16.T.20230306.exe File created: C:\Users\user\AppData\Local\Temp\nsx26F3.tmp\LangDLL.dll Jump to dropped file
Source: C:\Users\user\Desktop\General_Beta_VMS_Win32_V2.2.1.16.T.20230306.exe File created: C:\Users\user\AppData\Local\Temp\nsx26F3.tmp\InstallOptions.dll Jump to dropped file
Source: C:\Users\user\Desktop\General_Beta_VMS_Win32_V2.2.1.16.T.20230306.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VMS Jump to behavior
Source: C:\Users\user\Desktop\General_Beta_VMS_Win32_V2.2.1.16.T.20230306.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VMS\VMS.lnk Jump to behavior
Source: C:\Users\user\Desktop\General_Beta_VMS_Win32_V2.2.1.16.T.20230306.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VMS\Uninstall.lnk Jump to behavior

Hooking and other Techniques for Hiding and Protection

barindex
Source: C:\Program Files (x86)\VMS\VMS.exe Memory written: PID: 1344 base: 74DF1720 value: E9 DB 11 BD 8B Jump to behavior
Source: C:\Users\user\Desktop\General_Beta_VMS_Win32_V2.2.1.16.T.20230306.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\General_Beta_VMS_Win32_V2.2.1.16.T.20230306.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\General_Beta_VMS_Win32_V2.2.1.16.T.20230306.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\conhost.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\regsvr32.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\regsvr32.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Window / User API: threadDelayed 3327 Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Window / User API: threadDelayed 1648 Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Window / User API: threadDelayed 1981 Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Window / User API: threadDelayed 1843 Jump to behavior
Source: C:\Users\user\Desktop\General_Beta_VMS_Win32_V2.2.1.16.T.20230306.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\nsx26F3.tmp\nsProcess.dll Jump to dropped file
Source: C:\Users\user\Desktop\General_Beta_VMS_Win32_V2.2.1.16.T.20230306.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\nsx26F3.tmp\LangDLL.dll Jump to dropped file
Source: C:\Users\user\Desktop\General_Beta_VMS_Win32_V2.2.1.16.T.20230306.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\nsx26F3.tmp\InstallOptions.dll Jump to dropped file
Source: C:\Program Files (x86)\VMS\VMS.exe TID: 3484 Thread sleep time: -33270s >= -30000s Jump to behavior
Source: C:\Windows\System32\conhost.exe Last function: Thread delayed
Source: C:\Program Files (x86)\VMS\VMS.exe Thread sleep count: Count: 3327 delay: -10 Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Thread sleep count: Count: 1648 delay: -10 Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Thread sleep count: Count: 1981 delay: -10 Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Thread sleep count: Count: 1843 delay: -10 Jump to behavior
Source: C:\Users\user\Desktop\General_Beta_VMS_Win32_V2.2.1.16.T.20230306.exe File Volume queried: C:\Program Files (x86) FullSizeInformation Jump to behavior
Source: C:\Users\user\Desktop\General_Beta_VMS_Win32_V2.2.1.16.T.20230306.exe File Volume queried: C:\Program Files (x86) FullSizeInformation Jump to behavior
Source: VMS.exe, 00000007.00000002.3583582900.00000000019AE000.00000008.00000001.01000000.0000001D.sdmp Binary or memory string: yuv420pyuyv422rgb24bgr24yuv422pyuv444pyuv410pyuv411pgraygray8,y8monowmonobpal8yuvj420pyuvj422pyuvj444pxvmcmcxvmcidctuyvy422uyyvyy411bgr8bgr4bgr4_bytergb8rgb4rgb4_bytenv12nv21argbrgbaabgrbgragray16bey16begray16ley16leyuv440pyuvj440pyuva420pvdpau_h264vdpau_mpeg1vdpau_mpeg2vdpau_wmv3vdpau_vc1rgb48bergb48lergb565bergb565lergb555bergb555lebgr565bebgr565lebgr555bebgr555levaapi_mocovaapi_idctvaapi_vldyuv420p16leyuv420p16beyuv422p16leyuv422p16beyuv444p16leyuv444p16bevdpau_mpeg4dxva2_vldrgb444lergb444bebgr444lebgr444beya8gray8abgr48bebgr48leyuv420p9beyuv420p9leyuv420p10beyuv420p10leyuv422p10beyuv422p10leyuv444p9beyuv444p9leyuv444p10beyuv444p10leyuv422p9beyuv422p9levda_vldgbrpgbrp9begbrp9legbrp10begbrp10legbrp16begbrp16leyuva420p9beyuva420p9leyuva422p9beyuva422p9leyuva444p9beyuva444p9leyuva420p10beyuva420p10leyuva422p10beyuva422p10le
Source: VMS.exe, 00000007.00000002.3582743236.00000000018D9000.00000002.00000001.01000000.0000001D.sdmp Binary or memory string: YCgCosmpte240msmpte170mbt470bgfccbt709GBRvdpauyuva444p16leyuva444p16beyuva422p16leyuva422p16beyuva420p16leyuva420p16beyuva444p10leyuva444p10beyuva422p10leyuva422p10beyuva420p10leyuva420p10beyuva444p9leyuva444p9beyuva422p9leyuva422p9beyuva420p9leyuva420p9begbrp16legbrp16begbrp10legbrp10begbrp9legbrp9begbrpvda_vldyuv422p9leyuv422p9beyuv444p10leyuv444p10beyuv444p9leyuv444p9beyuv422p10leyuv422p10beyuv420p10leyuv420p10beyuv420p9leyuv420p9bebgr48lebgr48begray8abgr444bebgr444lergb444bergb444ledxva2_vldvdpau_mpeg4yuv444p16beyuv444p16leyuv422p16beyuv422p16leyuv420p16beyuv420p16levaapi_vldvaapi_idctvaapi_mocobgr555lebgr555bebgr565lebgr565bergb555lergb555bergb565lergb565bergb48lergb48bevdpau_vc1vdpau_wmv3vdpau_mpeg2vdpau_mpeg1vdpau_h264yuvj440pabgrrgbargb4_bytebgr4_bytexvmcidctxvmcmcpal8monobmonowH
Source: VMS.exe, 00000007.00000002.3583582900.00000000019AE000.00000008.00000001.01000000.0000001D.sdmp Binary or memory string: xvmcidct
Source: VMS.exe, 00000007.00000002.3580659593.00000000011EE000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dllj
Source: VMS.exe, 00000007.00000002.3617232960.0000000066110000.00000002.00000001.01000000.0000002E.sdmp Binary or memory string: VMware Screen Codec / VMware Video
Source: C:\Users\user\Desktop\General_Beta_VMS_Win32_V2.2.1.16.T.20230306.exe Process information queried: ProcessInformation Jump to behavior
Source: C:\Users\user\Desktop\General_Beta_VMS_Win32_V2.2.1.16.T.20230306.exe Process created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c ""C:\Program Files (x86)\VMS\MediaPlayer\register.bat"" Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exe Process created: C:\Windows\SysWOW64\regsvr32.exe regsvr32 /u -s "C:\Program Files (x86)\VMS\MediaPlayer\MediaDecFilter.ax" Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exe Process created: C:\Windows\SysWOW64\regsvr32.exe regsvr32 -s "C:\Program Files (x86)\VMS\MediaPlayer\MediaDecFilter.ax" Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Queries volume information: C:\Program Files (x86)\VMS\platforms\qminimal.dll VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Queries volume information: C:\Program Files (x86)\VMS\platforms\qoffscreen.dll VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Queries volume information: C:\Program Files (x86)\VMS\config.ini VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Queries volume information: C:\Program Files (x86)\VMS\translations\English.qm VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Queries volume information: C:\Program Files (x86)\VMS\translations\English.qm VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Queries volume information: C:\Program Files (x86)\VMS\plugins\platforms\qminimal.dll VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Queries volume information: C:\Program Files (x86)\VMS\plugins\platforms\qoffscreen.dll VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Queries volume information: C:\Program Files (x86)\VMS\plugins\platforms\qwindows.dll VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Queries volume information: C:\Program Files (x86)\VMS\plugins\iconengines\qsvgicon.dll VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Queries volume information: C:\Program Files (x86)\VMS\plugins\imageformats\qgif.dll VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Queries volume information: C:\Program Files (x86)\VMS\plugins\imageformats\qicns.dll VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Queries volume information: C:\Program Files (x86)\VMS\plugins\imageformats\qico.dll VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Queries volume information: C:\Program Files (x86)\VMS\plugins\imageformats\qjpeg.dll VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Queries volume information: C:\Program Files (x86)\VMS\plugins\imageformats\qsvg.dll VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Queries volume information: C:\Program Files (x86)\VMS\plugins\imageformats\qwbmp.dll VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Queries volume information: C:\Program Files (x86)\VMS\skin\default\icons\vms.png VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Queries volume information: C:\Program Files (x86)\VMS\skin\default\icons\vms.png VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Queries volume information: C:\Program Files (x86)\VMS\skin\default\style.ss VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Queries volume information: C:\Program Files (x86)\VMS\plugins\sqldrivers\qsqlite.dll VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Queries volume information: C:\Program Files (x86)\VMS\plugins\sqldrivers\qsqlmysql.dll VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Queries volume information: C:\Program Files (x86)\VMS\plugins\sqldrivers\qsqlodbc.dll VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Queries volume information: C:\Program Files (x86)\VMS\plugins\sqldrivers\qsqlpsql.dll VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Queries volume information: C:\Program Files (x86)\VMS\ErrorLog\VMS_Error_Log_2024_04_26_00_41_05.txt VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Queries volume information: C:\Program Files (x86)\VMS\ErrorLog\VMS_Error_Log_2024_04_26_00_41_05.txt VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Queries volume information: C:\Windows\Fonts\msyh.ttc VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Queries volume information: C:\Program Files (x86)\VMS\skin\default\logos\logo_top_login.png VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Queries volume information: C:\Program Files (x86)\VMS\skin\default\logos\logo_top_login.png VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Queries volume information: C:\Program Files (x86)\VMS\skin\default\buttons\check.png VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Queries volume information: C:\Program Files (x86)\VMS\skin\default\buttons\check.png VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Queries volume information: C:\Program Files (x86)\VMS\skin\default\buttons\Checked_hover.png VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Queries volume information: C:\Program Files (x86)\VMS\skin\default\buttons\Checked_hover.png VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\VMS\VMS.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuid Jump to behavior
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs