Source: |
Binary string: C:\Windows\mscorlib.pdbpdblib.pdb source: InstallUtil.exe, 00000001.00000002.2946020220.0000000000A10000.00000004.00000020.00020000.00000000.sdmp |
Source: |
Binary string: \??\C:\Windows\symbols\dll\System.pdbxP source: InstallUtil.exe, 00000001.00000002.2946020220.0000000000A10000.00000004.00000020.00020000.00000000.sdmp |
Source: |
Binary string: C:\Windows\System.pdbpdbtem.pdb source: InstallUtil.exe, 00000001.00000002.2946020220.0000000000A10000.00000004.00000020.00020000.00000000.sdmp |
Source: |
Binary string: \??\C:\Windows\dll\mscorlib.pdb source: InstallUtil.exe, 00000001.00000002.2946020220.0000000000A10000.00000004.00000020.00020000.00000000.sdmp |
Source: |
Binary string: \??\C:\Windows\mscorlib.pdbqQ, source: InstallUtil.exe, 00000001.00000002.2946020220.0000000000A10000.00000004.00000020.00020000.00000000.sdmp |
Source: |
Binary string: C:\Users\dahall\Documents\GitHubRepos\TaskScheduler\TaskService\obj\Release\net40\Microsoft.Win32.TaskScheduler.pdbSHA256e source: u5GtsPYWPJ.exe, 00000000.00000002.1727434169.0000000005EB0000.00000004.08000000.00040000.00000000.sdmp, u5GtsPYWPJ.exe, 00000000.00000002.1721268265.00000000038DD000.00000004.00000800.00020000.00000000.sdmp |
Source: |
Binary string: ((.pdb source: InstallUtil.exe, 00000001.00000002.2944881169.00000000003E8000.00000004.00000010.00020000.00000000.sdmp |
Source: |
Binary string: \??\C:\Windows\symbols\exe\InstallUtil.pdb source: InstallUtil.exe, 00000001.00000002.2946020220.00000000009CA000.00000004.00000020.00020000.00000000.sdmp |
Source: |
Binary string: \??\C:\Windows\dll\mscorlib.pdb3 source: InstallUtil.exe, 00000001.00000002.2946020220.0000000000A10000.00000004.00000020.00020000.00000000.sdmp |
Source: |
Binary string: \??\C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System\v4.0_4.0.0.0__b77a5c561934e089\System.pdbR source: InstallUtil.exe, 00000001.00000002.2946020220.00000000009CA000.00000004.00000020.00020000.00000000.sdmp |
Source: |
Binary string: C:\Users\dahall\Documents\GitHubRepos\TaskScheduler\TaskService\obj\Release\net40\Microsoft.Win32.TaskScheduler.pdb source: u5GtsPYWPJ.exe, 00000000.00000002.1727434169.0000000005EB0000.00000004.08000000.00040000.00000000.sdmp, u5GtsPYWPJ.exe, 00000000.00000002.1721268265.00000000038DD000.00000004.00000800.00020000.00000000.sdmp |
Source: |
Binary string: protobuf-net.pdbSHA256}Lq source: u5GtsPYWPJ.exe, 00000000.00000002.1726586989.0000000005370000.00000004.08000000.00040000.00000000.sdmp |
Source: |
Binary string: \??\C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.pdb source: InstallUtil.exe, 00000001.00000002.2946020220.0000000000988000.00000004.00000020.00020000.00000000.sdmp |
Source: |
Binary string: protobuf-net.pdb source: u5GtsPYWPJ.exe, 00000000.00000002.1726586989.0000000005370000.00000004.08000000.00040000.00000000.sdmp |
Source: |
Binary string: \??\C:\Windows\System.pdb source: InstallUtil.exe, 00000001.00000002.2946020220.0000000000A10000.00000004.00000020.00020000.00000000.sdmp |
Source: |
Binary string: InstallUtil.pdb source: InstallUtil.exe, 00000001.00000002.2946020220.0000000000A10000.00000004.00000020.00020000.00000000.sdmp |
Source: |
Binary string: \??\C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.pdbl source: InstallUtil.exe, 00000001.00000002.2946020220.0000000000988000.00000004.00000020.00020000.00000000.sdmp |
Source: |
Binary string: o.pdb source: InstallUtil.exe, 00000001.00000002.2944881169.00000000003E8000.00000004.00000010.00020000.00000000.sdmp |
Source: |
Binary string: >symbols\exe\InstallUtil.pdb source: InstallUtil.exe, 00000001.00000002.2944881169.00000000003E8000.00000004.00000010.00020000.00000000.sdmp |
Source: |
Binary string: \??\C:\Windows\symbols\dll\mscorlib.pdbR[ source: InstallUtil.exe, 00000001.00000002.2946020220.0000000000A10000.00000004.00000020.00020000.00000000.sdmp |
Source: |
Binary string: C:\Windows\InstallUtil.pdbpdbtil.pdb source: InstallUtil.exe, 00000001.00000002.2946020220.0000000000A10000.00000004.00000020.00020000.00000000.sdmp |
Source: |
Binary string: \??\C:\Windows\dll\System.pdb8 source: InstallUtil.exe, 00000001.00000002.2946020220.0000000000A10000.00000004.00000020.00020000.00000000.sdmp |
Source: |
Binary string: \??\C:\Windows\exe\InstallUtil.pdb source: InstallUtil.exe, 00000001.00000002.2946020220.0000000000A10000.00000004.00000020.00020000.00000000.sdmp |
Source: |
Binary string: \??\C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.PDBpwT source: InstallUtil.exe, 00000001.00000002.2946020220.0000000000988000.00000004.00000020.00020000.00000000.sdmp |
Source: |
Binary string: \??\C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System\v4.0_4.0.0.0__b77a5c561934e089\System.pdb source: InstallUtil.exe, 00000001.00000002.2946020220.00000000009CA000.00000004.00000020.00020000.00000000.sdmp |
Source: |
Binary string: InstallUtil.pdbllUtil.pdbpdbtil.pdb.30319\InstallUtil.pdbh source: InstallUtil.exe, 00000001.00000002.2944881169.00000000003E8000.00000004.00000010.00020000.00000000.sdmp |
Source: |
Binary string: \??\C:\Windows\mscorlib.pdb source: InstallUtil.exe, 00000001.00000002.2946020220.0000000000A10000.00000004.00000020.00020000.00000000.sdmp |
Source: |
Binary string: oC:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.pdb( source: InstallUtil.exe, 00000001.00000002.2944881169.00000000003E8000.00000004.00000010.00020000.00000000.sdmp |
Source: |
Binary string: \??\C:\Windows\InstallUtil.pdb source: InstallUtil.exe, 00000001.00000002.2946020220.0000000000A10000.00000004.00000020.00020000.00000000.sdmp |
Source: |
Binary string: n8C:\Windows\InstallUtil.pdbA source: InstallUtil.exe, 00000001.00000002.2944881169.00000000003E8000.00000004.00000010.00020000.00000000.sdmp |
Source: u5GtsPYWPJ.exe, 00000000.00000002.1707958881.0000000002692000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name |
Source: u5GtsPYWPJ.exe, 00000000.00000002.1726586989.0000000005370000.00000004.08000000.00040000.00000000.sdmp |
String found in binary or memory: https://github.com/mgravell/protobuf-net |
Source: u5GtsPYWPJ.exe, 00000000.00000002.1726586989.0000000005370000.00000004.08000000.00040000.00000000.sdmp, u5GtsPYWPJ.exe, 00000000.00000002.1721268265.00000000038DD000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://github.com/mgravell/protobuf-netJ |
Source: u5GtsPYWPJ.exe, 00000000.00000002.1726586989.0000000005370000.00000004.08000000.00040000.00000000.sdmp |
String found in binary or memory: https://github.com/mgravell/protobuf-neti |
Source: u5GtsPYWPJ.exe, 00000000.00000002.1726586989.0000000005370000.00000004.08000000.00040000.00000000.sdmp |
String found in binary or memory: https://stackoverflow.com/q/11564914/23354; |
Source: u5GtsPYWPJ.exe, 00000000.00000002.1707958881.0000000002692000.00000004.00000800.00020000.00000000.sdmp, u5GtsPYWPJ.exe, 00000000.00000002.1726586989.0000000005370000.00000004.08000000.00040000.00000000.sdmp |
String found in binary or memory: https://stackoverflow.com/q/14436606/23354 |
Source: u5GtsPYWPJ.exe, 00000000.00000002.1726586989.0000000005370000.00000004.08000000.00040000.00000000.sdmp |
String found in binary or memory: https://stackoverflow.com/q/2152978/23354 |
Source: C:\Users\user\Desktop\u5GtsPYWPJ.exe |
Code function: 0_2_023ECF20 |
0_2_023ECF20 |
Source: C:\Users\user\Desktop\u5GtsPYWPJ.exe |
Code function: 0_2_023ECF13 |
0_2_023ECF13 |
Source: C:\Users\user\Desktop\u5GtsPYWPJ.exe |
Code function: 0_2_05557298 |
0_2_05557298 |
Source: C:\Users\user\Desktop\u5GtsPYWPJ.exe |
Code function: 0_2_0555EA38 |
0_2_0555EA38 |
Source: C:\Users\user\Desktop\u5GtsPYWPJ.exe |
Code function: 0_2_05557288 |
0_2_05557288 |
Source: C:\Users\user\Desktop\u5GtsPYWPJ.exe |
Code function: 0_2_0555087A |
0_2_0555087A |
Source: C:\Users\user\Desktop\u5GtsPYWPJ.exe |
Code function: 0_2_05550888 |
0_2_05550888 |
Source: C:\Users\user\Desktop\u5GtsPYWPJ.exe |
Code function: 0_2_0555EA28 |
0_2_0555EA28 |
Source: C:\Users\user\Desktop\u5GtsPYWPJ.exe |
Code function: 0_2_05B60006 |
0_2_05B60006 |
Source: C:\Users\user\Desktop\u5GtsPYWPJ.exe |
Code function: 0_2_05B60040 |
0_2_05B60040 |
Source: C:\Users\user\Desktop\u5GtsPYWPJ.exe |
Code function: 0_2_05B7E230 |
0_2_05B7E230 |
Source: C:\Users\user\Desktop\u5GtsPYWPJ.exe |
Code function: 0_2_05B85A89 |
0_2_05B85A89 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Code function: 1_2_00B235C3 |
1_2_00B235C3 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Code function: 1_2_00B23E78 |
1_2_00B23E78 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Code function: 1_2_00B268D0 |
1_2_00B268D0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Code function: 1_2_00B268C2 |
1_2_00B268C2 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Code function: 1_2_00B27A18 |
1_2_00B27A18 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Code function: 1_2_00B27A09 |
1_2_00B27A09 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Code function: 1_2_00B23BF0 |
1_2_00B23BF0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Code function: 1_2_00B23BE0 |
1_2_00B23BE0 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Code function: 1_2_00B26FF8 |
1_2_00B26FF8 |
Source: u5GtsPYWPJ.exe, 00000000.00000002.1707958881.0000000002692000.00000004.00000800.00020000.00000000.sdmp |
Binary or memory string: OriginalFilenameZaflzhwbmkh.exe" vs u5GtsPYWPJ.exe |
Source: u5GtsPYWPJ.exe, 00000000.00000002.1726586989.0000000005370000.00000004.08000000.00040000.00000000.sdmp |
Binary or memory string: OriginalFilenameprotobuf-net.dllJ vs u5GtsPYWPJ.exe |
Source: u5GtsPYWPJ.exe, 00000000.00000002.1721268265.0000000003BC4000.00000004.00000800.00020000.00000000.sdmp |
Binary or memory string: OriginalFilenameZaflzhwbmkh.exe" vs u5GtsPYWPJ.exe |
Source: u5GtsPYWPJ.exe, 00000000.00000002.1707198664.00000000008EE000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: OriginalFilenameclr.dllT vs u5GtsPYWPJ.exe |
Source: u5GtsPYWPJ.exe, 00000000.00000002.1707958881.0000000002BC0000.00000004.00000800.00020000.00000000.sdmp |
Binary or memory string: OriginalFilenameZaflzhwbmkh.exe" vs u5GtsPYWPJ.exe |
Source: u5GtsPYWPJ.exe, 00000000.00000002.1707958881.0000000002621000.00000004.00000800.00020000.00000000.sdmp |
Binary or memory string: OriginalFilename vs u5GtsPYWPJ.exe |
Source: u5GtsPYWPJ.exe, 00000000.00000002.1727434169.0000000005EB0000.00000004.08000000.00040000.00000000.sdmp |
Binary or memory string: OriginalFilenameMicrosoft.Win32.TaskScheduler.dll\ vs u5GtsPYWPJ.exe |
Source: u5GtsPYWPJ.exe, 00000000.00000002.1721268265.00000000038DD000.00000004.00000800.00020000.00000000.sdmp |
Binary or memory string: OriginalFilenameprotobuf-net.dllJ vs u5GtsPYWPJ.exe |
Source: u5GtsPYWPJ.exe, 00000000.00000002.1721268265.00000000038DD000.00000004.00000800.00020000.00000000.sdmp |
Binary or memory string: OriginalFilenameMicrosoft.Win32.TaskScheduler.dll\ vs u5GtsPYWPJ.exe |
Source: u5GtsPYWPJ.exe, 00000000.00000002.1724249366.0000000004D60000.00000004.08000000.00040000.00000000.sdmp |
Binary or memory string: OriginalFilenameOxrnlxikngj.dll" vs u5GtsPYWPJ.exe |
Source: u5GtsPYWPJ.exe, 00000000.00000002.1727670446.0000000006040000.00000004.00000020.00020000.00000000.sdmp |
Binary or memory string: OriginalFilenameNOV DUE SOA.exe8 vs u5GtsPYWPJ.exe |
Source: u5GtsPYWPJ.exe |
Binary or memory string: OriginalFilenameNOV DUE SOA.exe8 vs u5GtsPYWPJ.exe |
Source: C:\Users\user\Desktop\u5GtsPYWPJ.exe |
Section loaded: mscoree.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\u5GtsPYWPJ.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\u5GtsPYWPJ.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\u5GtsPYWPJ.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\u5GtsPYWPJ.exe |
Section loaded: vcruntime140_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\u5GtsPYWPJ.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\u5GtsPYWPJ.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\u5GtsPYWPJ.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\u5GtsPYWPJ.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\u5GtsPYWPJ.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\u5GtsPYWPJ.exe |
Section loaded: cryptsp.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\u5GtsPYWPJ.exe |
Section loaded: rsaenh.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\u5GtsPYWPJ.exe |
Section loaded: cryptbase.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\u5GtsPYWPJ.exe |
Section loaded: amsi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\u5GtsPYWPJ.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\u5GtsPYWPJ.exe |
Section loaded: msasn1.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\u5GtsPYWPJ.exe |
Section loaded: gpapi.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\u5GtsPYWPJ.exe |
Section loaded: wbemcomn.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\u5GtsPYWPJ.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\u5GtsPYWPJ.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Users\user\Desktop\u5GtsPYWPJ.exe |
Section loaded: ntmarta.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Section loaded: mscoree.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Section loaded: vcruntime140_clr0400.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Section loaded: ucrtbase_clr0400.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Section loaded: wtsapi32.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Section loaded: winsta.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Section loaded: cryptsp.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Section loaded: rsaenh.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Section loaded: cryptbase.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Section loaded: amsi.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Section loaded: msasn1.dll |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Section loaded: gpapi.dll |
Jump to behavior |
Source: |
Binary string: C:\Windows\mscorlib.pdbpdblib.pdb source: InstallUtil.exe, 00000001.00000002.2946020220.0000000000A10000.00000004.00000020.00020000.00000000.sdmp |
Source: |
Binary string: \??\C:\Windows\symbols\dll\System.pdbxP source: InstallUtil.exe, 00000001.00000002.2946020220.0000000000A10000.00000004.00000020.00020000.00000000.sdmp |
Source: |
Binary string: C:\Windows\System.pdbpdbtem.pdb source: InstallUtil.exe, 00000001.00000002.2946020220.0000000000A10000.00000004.00000020.00020000.00000000.sdmp |
Source: |
Binary string: \??\C:\Windows\dll\mscorlib.pdb source: InstallUtil.exe, 00000001.00000002.2946020220.0000000000A10000.00000004.00000020.00020000.00000000.sdmp |
Source: |
Binary string: \??\C:\Windows\mscorlib.pdbqQ, source: InstallUtil.exe, 00000001.00000002.2946020220.0000000000A10000.00000004.00000020.00020000.00000000.sdmp |
Source: |
Binary string: C:\Users\dahall\Documents\GitHubRepos\TaskScheduler\TaskService\obj\Release\net40\Microsoft.Win32.TaskScheduler.pdbSHA256e source: u5GtsPYWPJ.exe, 00000000.00000002.1727434169.0000000005EB0000.00000004.08000000.00040000.00000000.sdmp, u5GtsPYWPJ.exe, 00000000.00000002.1721268265.00000000038DD000.00000004.00000800.00020000.00000000.sdmp |
Source: |
Binary string: ((.pdb source: InstallUtil.exe, 00000001.00000002.2944881169.00000000003E8000.00000004.00000010.00020000.00000000.sdmp |
Source: |
Binary string: \??\C:\Windows\symbols\exe\InstallUtil.pdb source: InstallUtil.exe, 00000001.00000002.2946020220.00000000009CA000.00000004.00000020.00020000.00000000.sdmp |
Source: |
Binary string: \??\C:\Windows\dll\mscorlib.pdb3 source: InstallUtil.exe, 00000001.00000002.2946020220.0000000000A10000.00000004.00000020.00020000.00000000.sdmp |
Source: |
Binary string: \??\C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System\v4.0_4.0.0.0__b77a5c561934e089\System.pdbR source: InstallUtil.exe, 00000001.00000002.2946020220.00000000009CA000.00000004.00000020.00020000.00000000.sdmp |
Source: |
Binary string: C:\Users\dahall\Documents\GitHubRepos\TaskScheduler\TaskService\obj\Release\net40\Microsoft.Win32.TaskScheduler.pdb source: u5GtsPYWPJ.exe, 00000000.00000002.1727434169.0000000005EB0000.00000004.08000000.00040000.00000000.sdmp, u5GtsPYWPJ.exe, 00000000.00000002.1721268265.00000000038DD000.00000004.00000800.00020000.00000000.sdmp |
Source: |
Binary string: protobuf-net.pdbSHA256}Lq source: u5GtsPYWPJ.exe, 00000000.00000002.1726586989.0000000005370000.00000004.08000000.00040000.00000000.sdmp |
Source: |
Binary string: \??\C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.pdb source: InstallUtil.exe, 00000001.00000002.2946020220.0000000000988000.00000004.00000020.00020000.00000000.sdmp |
Source: |
Binary string: protobuf-net.pdb source: u5GtsPYWPJ.exe, 00000000.00000002.1726586989.0000000005370000.00000004.08000000.00040000.00000000.sdmp |
Source: |
Binary string: \??\C:\Windows\System.pdb source: InstallUtil.exe, 00000001.00000002.2946020220.0000000000A10000.00000004.00000020.00020000.00000000.sdmp |
Source: |
Binary string: InstallUtil.pdb source: InstallUtil.exe, 00000001.00000002.2946020220.0000000000A10000.00000004.00000020.00020000.00000000.sdmp |
Source: |
Binary string: \??\C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.pdbl source: InstallUtil.exe, 00000001.00000002.2946020220.0000000000988000.00000004.00000020.00020000.00000000.sdmp |
Source: |
Binary string: o.pdb source: InstallUtil.exe, 00000001.00000002.2944881169.00000000003E8000.00000004.00000010.00020000.00000000.sdmp |
Source: |
Binary string: >symbols\exe\InstallUtil.pdb source: InstallUtil.exe, 00000001.00000002.2944881169.00000000003E8000.00000004.00000010.00020000.00000000.sdmp |
Source: |
Binary string: \??\C:\Windows\symbols\dll\mscorlib.pdbR[ source: InstallUtil.exe, 00000001.00000002.2946020220.0000000000A10000.00000004.00000020.00020000.00000000.sdmp |
Source: |
Binary string: C:\Windows\InstallUtil.pdbpdbtil.pdb source: InstallUtil.exe, 00000001.00000002.2946020220.0000000000A10000.00000004.00000020.00020000.00000000.sdmp |
Source: |
Binary string: \??\C:\Windows\dll\System.pdb8 source: InstallUtil.exe, 00000001.00000002.2946020220.0000000000A10000.00000004.00000020.00020000.00000000.sdmp |
Source: |
Binary string: \??\C:\Windows\exe\InstallUtil.pdb source: InstallUtil.exe, 00000001.00000002.2946020220.0000000000A10000.00000004.00000020.00020000.00000000.sdmp |
Source: |
Binary string: \??\C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.PDBpwT source: InstallUtil.exe, 00000001.00000002.2946020220.0000000000988000.00000004.00000020.00020000.00000000.sdmp |
Source: |
Binary string: \??\C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System\v4.0_4.0.0.0__b77a5c561934e089\System.pdb source: InstallUtil.exe, 00000001.00000002.2946020220.00000000009CA000.00000004.00000020.00020000.00000000.sdmp |
Source: |
Binary string: InstallUtil.pdbllUtil.pdbpdbtil.pdb.30319\InstallUtil.pdbh source: InstallUtil.exe, 00000001.00000002.2944881169.00000000003E8000.00000004.00000010.00020000.00000000.sdmp |
Source: |
Binary string: \??\C:\Windows\mscorlib.pdb source: InstallUtil.exe, 00000001.00000002.2946020220.0000000000A10000.00000004.00000020.00020000.00000000.sdmp |
Source: |
Binary string: oC:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.pdb( source: InstallUtil.exe, 00000001.00000002.2944881169.00000000003E8000.00000004.00000010.00020000.00000000.sdmp |
Source: |
Binary string: \??\C:\Windows\InstallUtil.pdb source: InstallUtil.exe, 00000001.00000002.2946020220.0000000000A10000.00000004.00000020.00020000.00000000.sdmp |
Source: |
Binary string: n8C:\Windows\InstallUtil.pdbA source: InstallUtil.exe, 00000001.00000002.2944881169.00000000003E8000.00000004.00000010.00020000.00000000.sdmp |
Source: C:\Users\user\Desktop\u5GtsPYWPJ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\u5GtsPYWPJ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\u5GtsPYWPJ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\u5GtsPYWPJ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\u5GtsPYWPJ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\u5GtsPYWPJ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\u5GtsPYWPJ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\u5GtsPYWPJ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\u5GtsPYWPJ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\u5GtsPYWPJ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\u5GtsPYWPJ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\u5GtsPYWPJ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\u5GtsPYWPJ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\u5GtsPYWPJ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\u5GtsPYWPJ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\u5GtsPYWPJ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\u5GtsPYWPJ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\u5GtsPYWPJ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\u5GtsPYWPJ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\u5GtsPYWPJ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\u5GtsPYWPJ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\u5GtsPYWPJ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\u5GtsPYWPJ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\u5GtsPYWPJ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\u5GtsPYWPJ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\u5GtsPYWPJ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\u5GtsPYWPJ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\u5GtsPYWPJ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\u5GtsPYWPJ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\u5GtsPYWPJ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\u5GtsPYWPJ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\u5GtsPYWPJ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\u5GtsPYWPJ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\u5GtsPYWPJ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\u5GtsPYWPJ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\u5GtsPYWPJ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\u5GtsPYWPJ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\u5GtsPYWPJ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\u5GtsPYWPJ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Users\user\Desktop\u5GtsPYWPJ.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Windows\SysWOW64\WerFault.exe |
Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX |
Jump to behavior |
Source: u5GtsPYWPJ.exe, 00000000.00000002.1707958881.0000000002692000.00000004.00000800.00020000.00000000.sdmp |
Binary or memory string: $dq 1:en-CH:VMware|VIRTUAL|A M I|Xen |
Source: u5GtsPYWPJ.exe, 00000000.00000002.1707958881.0000000002692000.00000004.00000800.00020000.00000000.sdmp |
Binary or memory string: vmware |
Source: u5GtsPYWPJ.exe, 00000000.00000002.1707958881.0000000002692000.00000004.00000800.00020000.00000000.sdmp |
Binary or memory string: VMware|VIRTUAL|A M I|Xen |
Source: u5GtsPYWPJ.exe, 00000000.00000002.1707958881.0000000002692000.00000004.00000800.00020000.00000000.sdmp |
Binary or memory string: Microsoft|VMWare|Virtual |
Source: u5GtsPYWPJ.exe, 00000000.00000002.1707958881.0000000002692000.00000004.00000800.00020000.00000000.sdmp |
Binary or memory string: $dq 1:en-CH:Microsoft|VMWare|Virtual |
Source: u5GtsPYWPJ.exe, 00000000.00000002.1707958881.0000000002692000.00000004.00000800.00020000.00000000.sdmp |
Binary or memory string: explorer SbieDll.dll!cuckoomon.dll"win32_process.handle='{0}'#ParentProcessId$cmd%select * from Win32_BIOS8Unexpected WMI query failure&version'SerialNumber)VMware|VIRTUAL|A M I|Xen*select * from Win32_ComputerSystem+manufacturer,model-Microsoft|VMWare|Virtual.john/anna0xxxxxxxx |