Source: explorer.exe, 0000000D.00000000.1547614933.0000000007306000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000000D.00000000.1565835129.0000000008F83000.00000004.00000001.00020000.00000000.sdmp | String found in binary or memory: http://cacerts.digicert.com/DigiCertGlobalRootG2.crt0 |
Source: explorer.exe, 0000000D.00000000.1547614933.0000000007306000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000000D.00000000.1565835129.0000000008F83000.00000004.00000001.00020000.00000000.sdmp | String found in binary or memory: http://crl3.digicert.com/DigiCertGlobalRootG2.crl07 |
Source: explorer.exe, 0000000D.00000000.1547614933.0000000007306000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000000D.00000000.1565835129.0000000008F83000.00000004.00000001.00020000.00000000.sdmp | String found in binary or memory: http://crl4.digicert.com/DigiCertGlobalRootG2.crl0 |
Source: Mansion_setup (1).exe | String found in binary or memory: http://nsis.sf.net/NSIS_ErrorError |
Source: explorer.exe, 0000000D.00000000.1547614933.0000000007306000.00000004.00000001.00020000.00000000.sdmp, explorer.exe, 0000000D.00000000.1565835129.0000000008F83000.00000004.00000001.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.digicert.com0 |
Source: explorer.exe, 0000000D.00000000.1547614933.00000000071FC000.00000004.00000001.00020000.00000000.sdmp | String found in binary or memory: http://ocsp.digicert.comhttp://crl3.digicert.com/DigiCertGlobalRootG2.crlhttp://crl4.digicert.com/Di |
Source: explorer.exe, 0000000D.00000000.1565046627.0000000008820000.00000002.00000001.00040000.00000000.sdmp, explorer.exe, 0000000D.00000000.1565016510.0000000008810000.00000002.00000001.00040000.00000000.sdmp, explorer.exe, 0000000D.00000000.1564035206.0000000007C70000.00000002.00000001.00040000.00000000.sdmp | String found in binary or memory: http://schemas.micro |
Source: explorer.exe, 0000000D.00000000.1547614933.00000000071B2000.00000004.00000001.00020000.00000000.sdmp | String found in binary or memory: http://www.foreca.com |
Source: explorer.exe, 0000000D.00000000.1565835129.0000000008F83000.00000004.00000001.00020000.00000000.sdmp | String found in binary or memory: https://activity.windows.com/UserActivity.ReadWrite.CreatedByApp |
Source: explorer.exe, 0000000D.00000000.1565835129.000000000913F000.00000004.00000001.00020000.00000000.sdmp | String found in binary or memory: https://android.notify.windows.com/iOS |
Source: explorer.exe, 0000000D.00000000.1565835129.0000000008F09000.00000004.00000001.00020000.00000000.sdmp | String found in binary or memory: https://api.msn.com/v1/news/Feed/Windows? |
Source: explorer.exe, 0000000D.00000000.1547614933.00000000071FC000.00000004.00000001.00020000.00000000.sdmp | String found in binary or memory: https://api.msn.com/v1/news/Feed/Windows?activityId=DD4083B70FE54739AB05D6BBA3484042&timeOut=5000&oc |
Source: explorer.exe, 0000000D.00000000.1547614933.00000000071FC000.00000004.00000001.00020000.00000000.sdmp | String found in binary or memory: https://api.msn.com:443/v1/news/Feed/Windows? |
Source: explorer.exe, 0000000D.00000000.1565835129.0000000008DFE000.00000004.00000001.00020000.00000000.sdmp | String found in binary or memory: https://arc.msn.com |
Source: explorer.exe, 0000000D.00000000.1547614933.00000000071FC000.00000004.00000001.00020000.00000000.sdmp | String found in binary or memory: https://assets.msn.com/weathermapdata/1/static/finance/1stparty/FinanceTaskbarIcons/Finance_Earnings |
Source: explorer.exe, 0000000D.00000000.1547614933.00000000071FC000.00000004.00000001.00020000.00000000.sdmp | String found in binary or memory: https://assets.msn.com/weathermapdata/1/static/weather/Icons/JyNGQgA=/Condition/AAehwh2.svg |
Source: explorer.exe, 0000000D.00000000.1547614933.00000000071FC000.00000004.00000001.00020000.00000000.sdmp | String found in binary or memory: https://cdn.query.prod.cms.msn.com/cms/api/amp/binary/AA13f2DV |
Source: explorer.exe, 0000000D.00000000.1547614933.00000000071FC000.00000004.00000001.00020000.00000000.sdmp | String found in binary or memory: https://cdn.query.prod.cms.msn.com/cms/api/amp/binary/AA13f2DV-dark |
Source: explorer.exe, 0000000D.00000000.1547614933.00000000071FC000.00000004.00000001.00020000.00000000.sdmp | String found in binary or memory: https://cdn.query.prod.cms.msn.com/cms/api/amp/binary/AA13fcaT |
Source: explorer.exe, 0000000D.00000000.1547614933.00000000071FC000.00000004.00000001.00020000.00000000.sdmp | String found in binary or memory: https://cdn.query.prod.cms.msn.com/cms/api/amp/binary/AA13fcaT-dark |
Source: e67ccac6-1b55-47d3-986b-064f1ebcae9d.tmp.14.dr | String found in binary or memory: https://chrome.cloudflare-dns.com |
Source: en-GB.pak.5.dr, tr.pak.5.dr | String found in binary or memory: https://chrome.google.com/webstore/category/extensions |
Source: en-GB.pak.5.dr | String found in binary or memory: https://chrome.google.com/webstore?hl=en-GB&category=theme81https://myactivity.google.com/myactivity |
Source: en-GB.pak.5.dr | String found in binary or memory: https://chrome.google.com/webstore?hl=en-GBShortcut |
Source: tr.pak.5.dr | String found in binary or memory: https://chrome.google.com/webstore?hl=tr&category=theme81https://myactivity.google.com/myactivity/?u |
Source: tr.pak.5.dr | String found in binary or memory: https://chrome.google.com/webstore?hl=trK |
Source: en-GB.pak.5.dr, tr.pak.5.dr | String found in binary or memory: https://chromeenterprise.google/policies/#BrowserSwitcherEnabled |
Source: en-GB.pak.5.dr, tr.pak.5.dr | String found in binary or memory: https://chromeenterprise.google/policies/#BrowserSwitcherExternalGreylistUrl |
Source: en-GB.pak.5.dr, tr.pak.5.dr | String found in binary or memory: https://chromeenterprise.google/policies/#BrowserSwitcherExternalSitelistUrl |
Source: en-GB.pak.5.dr, tr.pak.5.dr | String found in binary or memory: https://chromeenterprise.google/policies/#BrowserSwitcherUrlGreylist |
Source: en-GB.pak.5.dr, tr.pak.5.dr | String found in binary or memory: https://chromeenterprise.google/policies/#BrowserSwitcherUrlList |
Source: en-GB.pak.5.dr, tr.pak.5.dr | String found in binary or memory: https://chromeenterprise.google/policies/#BrowserSwitcherUseIeSitelist |
Source: explorer.exe, 0000000D.00000000.1568820754.000000000C091000.00000004.00000001.00020000.00000000.sdmp | String found in binary or memory: https://excel.office.com |
Source: explorer.exe, 0000000D.00000000.1547614933.00000000071FC000.00000004.00000001.00020000.00000000.sdmp | String found in binary or memory: https://img-s-msn-com.akamaized.net/tenant/amp/entityid/AA11f7Wa.img |
Source: explorer.exe, 0000000D.00000000.1547614933.00000000071FC000.00000004.00000001.00020000.00000000.sdmp | String found in binary or memory: https://img-s-msn-com.akamaized.net/tenant/amp/entityid/AA15Yat4.img |
Source: explorer.exe, 0000000D.00000000.1547614933.00000000071FC000.00000004.00000001.00020000.00000000.sdmp | String found in binary or memory: https://img-s-msn-com.akamaized.net/tenant/amp/entityid/AA1bjET8.img |
Source: explorer.exe, 0000000D.00000000.1547614933.00000000071FC000.00000004.00000001.00020000.00000000.sdmp | String found in binary or memory: https://img-s-msn-com.akamaized.net/tenant/amp/entityid/AA1c9Jin.img |
Source: explorer.exe, 0000000D.00000000.1547614933.00000000071FC000.00000004.00000001.00020000.00000000.sdmp | String found in binary or memory: https://img-s-msn-com.akamaized.net/tenant/amp/entityid/BBNvr53.img |
Source: en-GB.pak.5.dr, tr.pak.5.dr | String found in binary or memory: https://myactivity.google.com/ |
Source: explorer.exe, 0000000D.00000000.1568820754.000000000C091000.00000004.00000001.00020000.00000000.sdmp | String found in binary or memory: https://outlook.com |
Source: en-GB.pak.5.dr, tr.pak.5.dr | String found in binary or memory: https://passwords.google.comGoogle |
Source: en-GB.pak.5.dr, tr.pak.5.dr | String found in binary or memory: https://photos.google.com/settings?referrer=CHROME_NTP |
Source: en-GB.pak.5.dr, tr.pak.5.dr | String found in binary or memory: https://policies.google.com/ |
Source: explorer.exe, 0000000D.00000000.1568820754.000000000C091000.00000004.00000001.00020000.00000000.sdmp | String found in binary or memory: https://powerpoint.office.com |
Source: tr.pak.5.dr | String found in binary or memory: https://support.google.com/chrome/a/answer/9122284 |
Source: en-GB.pak.5.dr, tr.pak.5.dr | String found in binary or memory: https://support.google.com/chrome/answer/6098869 |
Source: en-GB.pak.5.dr, tr.pak.5.dr | String found in binary or memory: https://support.google.com/chromebook?p=app_intent |
Source: explorer.exe, 0000000D.00000000.1547614933.00000000071FC000.00000004.00000001.00020000.00000000.sdmp | String found in binary or memory: https://windows.msn.com:443/shell?osLocale=en-GB&chosenMarketReason=ImplicitNew |
Source: explorer.exe, 0000000D.00000000.1547614933.00000000071FC000.00000004.00000001.00020000.00000000.sdmp | String found in binary or memory: https://windows.msn.com:443/shellv2?osLocale=en-GB&chosenMarketReason=ImplicitNew |
Source: explorer.exe, 0000000D.00000000.1565835129.00000000090F2000.00000004.00000001.00020000.00000000.sdmp | String found in binary or memory: https://wns.windows.com/ |
Source: explorer.exe, 0000000D.00000000.1568820754.000000000C091000.00000004.00000001.00020000.00000000.sdmp | String found in binary or memory: https://word.office.com |
Source: tr.pak.5.dr | String found in binary or memory: https://www.google.com/chrome/privacy/eula_text.htmlKurulu |
Source: en-GB.pak.5.dr | String found in binary or memory: https://www.google.com/chrome/privacy/eula_text.htmlManaged |
Source: explorer.exe, 0000000D.00000000.1547614933.00000000071FC000.00000004.00000001.00020000.00000000.sdmp | String found in binary or memory: https://www.msn.com/en-us/lifestyle/lifestyle-buzz/what-to-do-if-a-worst-case-nuclear-scenario-actua |
Source: explorer.exe, 0000000D.00000000.1547614933.00000000071FC000.00000004.00000001.00020000.00000000.sdmp | String found in binary or memory: https://www.msn.com/en-us/money/careersandeducation/student-loan-debt-forgiveness-arrives-for-some-b |
Source: explorer.exe, 0000000D.00000000.1547614933.00000000071FC000.00000004.00000001.00020000.00000000.sdmp | String found in binary or memory: https://www.msn.com/en-us/money/markets/costco-is-seeing-a-gold-rush-what-s-behind-the-demand-for-it |
Source: explorer.exe, 0000000D.00000000.1547614933.00000000071FC000.00000004.00000001.00020000.00000000.sdmp | String found in binary or memory: https://www.msn.com/en-us/money/realestate/why-this-florida-city-is-a-safe-haven-from-hurricanes/ar- |
Source: explorer.exe, 0000000D.00000000.1547614933.00000000071FC000.00000004.00000001.00020000.00000000.sdmp | String found in binary or memory: https://www.msn.com/en-us/music/news/6-rock-ballads-that-tug-at-the-heartstrings/ar-AA1hIdsm |
Source: explorer.exe, 0000000D.00000000.1547614933.00000000071FC000.00000004.00000001.00020000.00000000.sdmp | String found in binary or memory: https://www.msn.com/en-us/news/politics/kinzinger-has-theory-about-who-next-house-speaker-will-be/vi |
Source: explorer.exe, 0000000D.00000000.1547614933.00000000071FC000.00000004.00000001.00020000.00000000.sdmp | String found in binary or memory: https://www.msn.com/en-us/news/technology/prehistoric-comet-impacted-earth-and-triggered-the-switch- |
Source: explorer.exe, 0000000D.00000000.1547614933.00000000071FC000.00000004.00000001.00020000.00000000.sdmp | String found in binary or memory: https://www.msn.com/en-us/news/us/dumb-and-dumber-12-states-with-the-absolute-worst-education-in-the |
Source: explorer.exe, 0000000D.00000000.1547614933.00000000071FC000.00000004.00000001.00020000.00000000.sdmp | String found in binary or memory: https://www.msn.com/en-us/sports/other/simone-biles-leads-u-s-women-s-team-to-seventh-straight-world |
Source: explorer.exe, 0000000D.00000000.1547614933.00000000071FC000.00000004.00000001.00020000.00000000.sdmp | String found in binary or memory: https://www.msn.com/en-us/weather/topstories/accuweather-el-ni |
Source: explorer.exe, 0000000D.00000000.1547614933.00000000071FC000.00000004.00000001.00020000.00000000.sdmp | String found in binary or memory: https://www.msn.com/en-us/weather/topstories/here-s-who-could-see-above-average-snowfall-this-winter |
Source: explorer.exe, 0000000D.00000000.1547614933.00000000071FC000.00000004.00000001.00020000.00000000.sdmp | String found in binary or memory: https://www.msn.com/en-us/weather/topstories/us-winter-forecast-for-the-2023-2024-season/ar-AA1hGINt |
Source: explorer.exe, 0000000D.00000000.1547614933.00000000071FC000.00000004.00000001.00020000.00000000.sdmp | String found in binary or memory: https://www.msn.com:443/en-us/feed |
Source: explorer.exe, 0000000D.00000000.1547614933.00000000071B2000.00000004.00000001.00020000.00000000.sdmp | String found in binary or memory: https://www.pollensense.com/ |
Source: unknown | Process created: C:\Users\user\Desktop\Mansion_setup (1).exe "C:\Users\user\Desktop\Mansion_setup (1).exe" | |
Source: C:\Users\user\Desktop\Mansion_setup (1).exe | Process created: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe C:\Users\user~1\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Process created: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe "C:\Users\user~1\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe" --type=gpu-process --user-data-dir="C:\Users\user\AppData\Roaming\my-electron-app" --gpu-preferences=WAAAAAAAAADgAAAMAAAAAAAAAAAAAAAAAABgAAAAAAA4AAAAAAAAAAAAAAAEAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAGAAAAAAAAAAYAAAAAAAAAAgAAAAAAAAACAAAAAAAAAAIAAAAAAAAAA== --mojo-platform-channel-handle=1660 --field-trial-handle=1664,i,10003974961743176471,10805792500059126368,262144 --disable-features=SpareRendererForSitePerProcess,WinRetrieveSuggestionsOnlyOnDemand /prefetch:2 | |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Process created: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe "C:\Users\user~1\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --user-data-dir="C:\Users\user\AppData\Roaming\my-electron-app" --mojo-platform-channel-handle=2940 --field-trial-handle=1664,i,10003974961743176471,10805792500059126368,262144 --disable-features=SpareRendererForSitePerProcess,WinRetrieveSuggestionsOnlyOnDemand /prefetch:8 | |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Process created: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe "C:\Users\user~1\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe" --type=renderer --user-data-dir="C:\Users\user\AppData\Roaming\my-electron-app" --app-path="C:\Users\user~1\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\resources\app.asar" --enable-sandbox --first-renderer-process --lang=en-GB --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=4 --time-ticks-at-unix-epoch=-1739628551283596 --launch-time-ticks=4519743123 --mojo-platform-channel-handle=3100 --field-trial-handle=1664,i,10003974961743176471,10805792500059126368,262144 --disable-features=SpareRendererForSitePerProcess,WinRetrieveSuggestionsOnlyOnDemand /prefetch:1 | |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Process created: C:\games\DDR5_NetCache\ExtractJPEGcmd.exe C:\games\DDR5_NetCache\ExtractJPEGcmd.exe | |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Process created: C:\games\DDR5_NetCache\qtZint.exe C:\games\DDR5_NetCache\qtZint.exe | |
Source: C:\Windows\explorer.exe | Process created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe" | |
Source: C:\Windows\explorer.exe | Process created: C:\Windows\SysWOW64\svchost.exe "C:\Windows\System32\svchost.exe" | |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Process created: C:\Windows\SysWOW64\WerFault.exe C:\Windows\SysWOW64\WerFault.exe -u -p 6176 -s 344 | |
Source: C:\Windows\explorer.exe | Process created: C:\Windows\System32\svchost.exe "C:\Windows\System32\svchost.exe" | |
Source: C:\Windows\System32\svchost.exe | Process created: C:\Program Files\Google\Chrome\Application\chrome.exe --user-data-dir="C:\Users\user~1\AppData\Local\Temp\chrE697.tmp" --explicitly-allowed-ports=8000 --disable-gpu --new-window "http://127.0.0.1:8000/c75c1857/bd5c97e1" | |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --mojo-platform-channel-handle=2400 --field-trial-handle=2096,i,7666385675108331514,3856656827583616406,262144 /prefetch:8 | |
Source: C:\Windows\System32\svchost.exe | Process created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe --user-data-dir="C:\Users\user~1\AppData\Local\Temp\chrEBD8.tmp" --explicitly-allowed-ports=8000 --disable-gpu --new-window "http://127.0.0.1:8000/c75c1857/0da50779" | |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | Process created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --mojo-platform-channel-handle=2532 --field-trial-handle=1980,i,2109797830624315799,4341307213657690466,262144 /prefetch:3 | |
Source: C:\Windows\System32\svchost.exe | Process created: C:\Program Files\Windows Media Player\wmlaunch.exe "C:\Program Files\Windows Media Player\wmlaunch.exe" | |
Source: C:\Program Files\Windows Media Player\wmlaunch.exe | Process created: C:\Windows\System32\dllhost.exe "C:\Windows\system32\dllhost.exe" | |
Source: C:\Users\user\Desktop\Mansion_setup (1).exe | Process created: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe C:\Users\user~1\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Process created: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe "C:\Users\user~1\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe" --type=gpu-process --user-data-dir="C:\Users\user\AppData\Roaming\my-electron-app" --gpu-preferences=WAAAAAAAAADgAAAMAAAAAAAAAAAAAAAAAABgAAAAAAA4AAAAAAAAAAAAAAAEAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAGAAAAAAAAAAYAAAAAAAAAAgAAAAAAAAACAAAAAAAAAAIAAAAAAAAAA== --mojo-platform-channel-handle=1660 --field-trial-handle=1664,i,10003974961743176471,10805792500059126368,262144 --disable-features=SpareRendererForSitePerProcess,WinRetrieveSuggestionsOnlyOnDemand /prefetch:2 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Process created: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe "C:\Users\user~1\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --user-data-dir="C:\Users\user\AppData\Roaming\my-electron-app" --mojo-platform-channel-handle=2940 --field-trial-handle=1664,i,10003974961743176471,10805792500059126368,262144 --disable-features=SpareRendererForSitePerProcess,WinRetrieveSuggestionsOnlyOnDemand /prefetch:8 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Process created: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe "C:\Users\user~1\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe" --type=renderer --user-data-dir="C:\Users\user\AppData\Roaming\my-electron-app" --app-path="C:\Users\user~1\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\resources\app.asar" --enable-sandbox --first-renderer-process --lang=en-GB --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=4 --time-ticks-at-unix-epoch=-1739628551283596 --launch-time-ticks=4519743123 --mojo-platform-channel-handle=3100 --field-trial-handle=1664,i,10003974961743176471,10805792500059126368,262144 --disable-features=SpareRendererForSitePerProcess,WinRetrieveSuggestionsOnlyOnDemand /prefetch:1 | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Process created: C:\games\DDR5_NetCache\ExtractJPEGcmd.exe C:\games\DDR5_NetCache\ExtractJPEGcmd.exe | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Process created: C:\games\DDR5_NetCache\qtZint.exe C:\games\DDR5_NetCache\qtZint.exe | Jump to behavior |
Source: C:\games\DDR5_NetCache\qtZint.exe | Process created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe" | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Process created: C:\Windows\SysWOW64\svchost.exe "C:\Windows\System32\svchost.exe" | |
Source: C:\Windows\SysWOW64\svchost.exe | Process created: C:\Windows\System32\svchost.exe "C:\Windows\System32\svchost.exe" | |
Source: C:\Windows\System32\svchost.exe | Process created: C:\Program Files\Google\Chrome\Application\chrome.exe --user-data-dir="C:\Users\user~1\AppData\Local\Temp\chrE697.tmp" --explicitly-allowed-ports=8000 --disable-gpu --new-window "http://127.0.0.1:8000/c75c1857/bd5c97e1" | |
Source: C:\Windows\System32\svchost.exe | Process created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe --user-data-dir="C:\Users\user~1\AppData\Local\Temp\chrEBD8.tmp" --explicitly-allowed-ports=8000 --disable-gpu --new-window "http://127.0.0.1:8000/c75c1857/0da50779" | |
Source: C:\Windows\System32\svchost.exe | Process created: C:\Program Files\Windows Media Player\wmlaunch.exe "C:\Program Files\Windows Media Player\wmlaunch.exe" | |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --mojo-platform-channel-handle=2400 --field-trial-handle=2096,i,7666385675108331514,3856656827583616406,262144 /prefetch:8 | |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | |
Source: C:\Program Files\Google\Chrome\Application\chrome.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | Process created: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-GB --service-sandbox-type=none --mojo-platform-channel-handle=2532 --field-trial-handle=1980,i,2109797830624315799,4341307213657690466,262144 /prefetch:3 | |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | Process created: unknown unknown | |
Source: C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | Process created: unknown unknown | |
Source: C:\Program Files\Windows Media Player\wmlaunch.exe | Process created: C:\Windows\System32\dllhost.exe "C:\Windows\system32\dllhost.exe" | |
Source: C:\Users\user\Desktop\Mansion_setup (1).exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Mansion_setup (1).exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Mansion_setup (1).exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Mansion_setup (1).exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Mansion_setup (1).exe | Section loaded: dwmapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Mansion_setup (1).exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Mansion_setup (1).exe | Section loaded: oleacc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Mansion_setup (1).exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Mansion_setup (1).exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Mansion_setup (1).exe | Section loaded: shfolder.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Mansion_setup (1).exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Mansion_setup (1).exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Mansion_setup (1).exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Mansion_setup (1).exe | Section loaded: iconcodecservice.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Mansion_setup (1).exe | Section loaded: windowscodecs.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Mansion_setup (1).exe | Section loaded: windows.staterepositoryps.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Mansion_setup (1).exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Mansion_setup (1).exe | Section loaded: windows.fileexplorer.common.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Mansion_setup (1).exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Mansion_setup (1).exe | Section loaded: ntshrui.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Mansion_setup (1).exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Mansion_setup (1).exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Mansion_setup (1).exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: ffmpeg.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: uiautomationcore.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: dbghelp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: winmm.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: dwrite.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: secur32.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: dhcpcsvc.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: powrprof.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: umpdc.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: kbdus.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: dpapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: nlaapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: dhcpcsvc6.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: dnsapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: textinputframework.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: coreuicomponents.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: windows.ui.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: windowmanagementapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: inputhost.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: twinapi.appcore.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: twinapi.appcore.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: mscms.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: coloradapterclient.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: wtsapi32.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: winsta.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: mmdevapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: devobj.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: iconcodecservice.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: windowscodecs.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: dwmapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: dataexchange.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: d3d11.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: dcomp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: dxgi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: windows.globalization.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: bcp47langs.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: bcp47mrm.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: msspellcheckingfacility.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: twinapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: onecoreuapcommonproxystub.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: atlthunk.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: oleacc.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: directmanipulation.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: napinsp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: pnrpnsp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: wshbth.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: winrnr.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: ffmpeg.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: uiautomationcore.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: dbghelp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: winmm.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: dwrite.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: secur32.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: dhcpcsvc.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: powrprof.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: umpdc.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: dxgi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: resourcepolicyclient.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: mf.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: mfplat.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: rtworkq.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: msmpeg2vdec.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: mfperfhelper.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: dxva2.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: msvproc.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: dwmapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: d3d11.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: dcomp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: d3d10warp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: dxcore.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: vcruntime140_1.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: vcruntime140.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: msvcp140.dll | Jump to behavior |
Source: C:\Windows\explorer.exe | Section loaded: vcruntime140.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: ffmpeg.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: uiautomationcore.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: dbghelp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: winmm.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: dwrite.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: secur32.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: dhcpcsvc.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: powrprof.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: umpdc.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: kbdus.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: nlaapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: dhcpcsvc6.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: dnsapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: rasadhlp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: ffmpeg.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: uiautomationcore.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: dbghelp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: winmm.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: dwrite.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: secur32.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: dhcpcsvc.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: powrprof.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: umpdc.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\games\DDR5_NetCache\ExtractJPEGcmd.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\games\DDR5_NetCache\ExtractJPEGcmd.exe | Section loaded: oleacc.dll | Jump to behavior |
Source: C:\games\DDR5_NetCache\ExtractJPEGcmd.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\games\DDR5_NetCache\ExtractJPEGcmd.exe | Section loaded: msimg32.dll | Jump to behavior |
Source: C:\games\DDR5_NetCache\ExtractJPEGcmd.exe | Section loaded: wininet.dll | Jump to behavior |
Source: C:\games\DDR5_NetCache\ExtractJPEGcmd.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\games\DDR5_NetCache\ExtractJPEGcmd.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\games\DDR5_NetCache\ExtractJPEGcmd.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\games\DDR5_NetCache\ExtractJPEGcmd.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\games\DDR5_NetCache\ExtractJPEGcmd.exe | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\games\DDR5_NetCache\ExtractJPEGcmd.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\games\DDR5_NetCache\ExtractJPEGcmd.exe | Section loaded: webio.dll | Jump to behavior |
Source: C:\games\DDR5_NetCache\ExtractJPEGcmd.exe | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\games\DDR5_NetCache\ExtractJPEGcmd.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\games\DDR5_NetCache\ExtractJPEGcmd.exe | Section loaded: winnsi.dll | Jump to behavior |
Source: C:\games\DDR5_NetCache\ExtractJPEGcmd.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\games\DDR5_NetCache\ExtractJPEGcmd.exe | Section loaded: dnsapi.dll | Jump to behavior |
Source: C:\games\DDR5_NetCache\ExtractJPEGcmd.exe | Section loaded: rasadhlp.dll | Jump to behavior |
Source: C:\games\DDR5_NetCache\ExtractJPEGcmd.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\games\DDR5_NetCache\ExtractJPEGcmd.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\games\DDR5_NetCache\ExtractJPEGcmd.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\games\DDR5_NetCache\ExtractJPEGcmd.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\games\DDR5_NetCache\qtZint.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\games\DDR5_NetCache\qtZint.exe | Section loaded: wtsapi32.dll | Jump to behavior |
Source: C:\games\DDR5_NetCache\qtZint.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\games\DDR5_NetCache\qtZint.exe | Section loaded: dwmapi.dll | Jump to behavior |
Source: C:\games\DDR5_NetCache\qtZint.exe | Section loaded: opengl32.dll | Jump to behavior |
Source: C:\games\DDR5_NetCache\qtZint.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\games\DDR5_NetCache\qtZint.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\games\DDR5_NetCache\qtZint.exe | Section loaded: netapi32.dll | Jump to behavior |
Source: C:\games\DDR5_NetCache\qtZint.exe | Section loaded: winmm.dll | Jump to behavior |
Source: C:\games\DDR5_NetCache\qtZint.exe | Section loaded: msvcp140.dll | Jump to behavior |
Source: C:\games\DDR5_NetCache\qtZint.exe | Section loaded: vcruntime140.dll | Jump to behavior |
Source: C:\games\DDR5_NetCache\qtZint.exe | Section loaded: glu32.dll | Jump to behavior |
Source: C:\games\DDR5_NetCache\qtZint.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\games\DDR5_NetCache\qtZint.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\games\DDR5_NetCache\qtZint.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\games\DDR5_NetCache\qtZint.exe | Section loaded: wininet.dll | Jump to behavior |
Source: C:\games\DDR5_NetCache\qtZint.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\games\DDR5_NetCache\qtZint.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\games\DDR5_NetCache\qtZint.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\games\DDR5_NetCache\qtZint.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\games\DDR5_NetCache\qtZint.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\games\DDR5_NetCache\qtZint.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\games\DDR5_NetCache\qtZint.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\games\DDR5_NetCache\qtZint.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\games\DDR5_NetCache\qtZint.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\games\DDR5_NetCache\qtZint.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\games\DDR5_NetCache\qtZint.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Windows\SysWOW64\svchost.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Windows\SysWOW64\svchost.exe | Section loaded: wbemcomn.dll | |
Source: C:\Windows\SysWOW64\svchost.exe | Section loaded: amsi.dll | |
Source: C:\Windows\SysWOW64\svchost.exe | Section loaded: userenv.dll | |
Source: C:\Windows\SysWOW64\svchost.exe | Section loaded: profapi.dll | |
Source: C:\Windows\SysWOW64\svchost.exe | Section loaded: version.dll | |
Source: C:\Windows\SysWOW64\svchost.exe | Section loaded: uxtheme.dll | |
Source: C:\Windows\SysWOW64\svchost.exe | Section loaded: windows.storage.dll | |
Source: C:\Windows\SysWOW64\svchost.exe | Section loaded: wldp.dll | |
Source: C:\Windows\SysWOW64\svchost.exe | Section loaded: sspicli.dll | |
Source: C:\Windows\SysWOW64\svchost.exe | Section loaded: mpr.dll | |
Source: C:\Windows\SysWOW64\svchost.exe | Section loaded: powrprof.dll | |
Source: C:\Windows\SysWOW64\svchost.exe | Section loaded: umpdc.dll | |
Source: C:\Windows\SysWOW64\svchost.exe | Section loaded: wbemcomn.dll | |
Source: C:\Windows\SysWOW64\svchost.exe | Section loaded: wbemcomn.dll | |
Source: C:\Windows\SysWOW64\svchost.exe | Section loaded: mswsock.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: cryptbase.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: netapi32.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: netutils.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: mswsock.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: dnsapi.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: iphlpapi.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: rasadhlp.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: fwpuclnt.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: dpapi.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: uxtheme.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: wkscli.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: cscapi.dll | |
Source: C:\Windows\System32\svchost.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Program Files\Windows Media Player\wmlaunch.exe | Section loaded: mpr.dll | |
Source: C:\Program Files\Windows Media Player\wmlaunch.exe | Section loaded: mfplat.dll | |
Source: C:\Program Files\Windows Media Player\wmlaunch.exe | Section loaded: kernel.appcore.dll | |
Source: C:\Program Files\Windows Media Player\wmlaunch.exe | Section loaded: rtworkq.dll | |
Source: C:\Program Files\Windows Media Player\wmlaunch.exe | Section loaded: cryptbase.dll | |
Source: C:\Program Files\Windows Media Player\wmlaunch.exe | Section loaded: mswsock.dll | |
Source: C:\Program Files\Windows Media Player\wmlaunch.exe | Section loaded: uxtheme.dll | |
Source: C:\Windows\System32\dllhost.exe | Section loaded: cryptbase.dll | |
Source: C:\Windows\System32\dllhost.exe | Section loaded: iphlpapi.dll | |
Source: C:\Windows\System32\dllhost.exe | Section loaded: mswsock.dll | |
Source: C:\Windows\System32\dllhost.exe | Section loaded: dhcpcsvc.dll | |
Source: ffmpeg.dll.5.dr | Static PE information: section name: .00cfg |
Source: ffmpeg.dll.5.dr | Static PE information: section name: .gxfg |
Source: ffmpeg.dll.5.dr | Static PE information: section name: .retplne |
Source: ffmpeg.dll.5.dr | Static PE information: section name: _RDATA |
Source: libEGL.dll.5.dr | Static PE information: section name: .00cfg |
Source: libEGL.dll.5.dr | Static PE information: section name: .gxfg |
Source: libEGL.dll.5.dr | Static PE information: section name: .retplne |
Source: libEGL.dll.5.dr | Static PE information: section name: _RDATA |
Source: libGLESv2.dll.5.dr | Static PE information: section name: .00cfg |
Source: libGLESv2.dll.5.dr | Static PE information: section name: .gxfg |
Source: libGLESv2.dll.5.dr | Static PE information: section name: .retplne |
Source: libGLESv2.dll.5.dr | Static PE information: section name: _RDATA |
Source: Mansion.exe.5.dr | Static PE information: section name: .00cfg |
Source: Mansion.exe.5.dr | Static PE information: section name: .gxfg |
Source: Mansion.exe.5.dr | Static PE information: section name: .retplne |
Source: Mansion.exe.5.dr | Static PE information: section name: .rodata |
Source: Mansion.exe.5.dr | Static PE information: section name: CPADinfo |
Source: Mansion.exe.5.dr | Static PE information: section name: LZMADEC |
Source: Mansion.exe.5.dr | Static PE information: section name: _RDATA |
Source: Mansion.exe.5.dr | Static PE information: section name: malloc_h |
Source: vk_swiftshader.dll.5.dr | Static PE information: section name: .00cfg |
Source: vk_swiftshader.dll.5.dr | Static PE information: section name: .gxfg |
Source: vk_swiftshader.dll.5.dr | Static PE information: section name: .retplne |
Source: vk_swiftshader.dll.5.dr | Static PE information: section name: _RDATA |
Source: vulkan-1.dll.5.dr | Static PE information: section name: .00cfg |
Source: vulkan-1.dll.5.dr | Static PE information: section name: .gxfg |
Source: vulkan-1.dll.5.dr | Static PE information: section name: .retplne |
Source: vulkan-1.dll.5.dr | Static PE information: section name: _RDATA |
Source: ffmpeg.dll0.5.dr | Static PE information: section name: .00cfg |
Source: ffmpeg.dll0.5.dr | Static PE information: section name: .gxfg |
Source: ffmpeg.dll0.5.dr | Static PE information: section name: .retplne |
Source: ffmpeg.dll0.5.dr | Static PE information: section name: _RDATA |
Source: libEGL.dll0.5.dr | Static PE information: section name: .00cfg |
Source: libEGL.dll0.5.dr | Static PE information: section name: .gxfg |
Source: libEGL.dll0.5.dr | Static PE information: section name: .retplne |
Source: libEGL.dll0.5.dr | Static PE information: section name: _RDATA |
Source: libGLESv2.dll0.5.dr | Static PE information: section name: .00cfg |
Source: libGLESv2.dll0.5.dr | Static PE information: section name: .gxfg |
Source: libGLESv2.dll0.5.dr | Static PE information: section name: .retplne |
Source: libGLESv2.dll0.5.dr | Static PE information: section name: _RDATA |
Source: Mansion.exe0.5.dr | Static PE information: section name: .00cfg |
Source: Mansion.exe0.5.dr | Static PE information: section name: .gxfg |
Source: Mansion.exe0.5.dr | Static PE information: section name: .retplne |
Source: Mansion.exe0.5.dr | Static PE information: section name: .rodata |
Source: Mansion.exe0.5.dr | Static PE information: section name: CPADinfo |
Source: Mansion.exe0.5.dr | Static PE information: section name: LZMADEC |
Source: Mansion.exe0.5.dr | Static PE information: section name: _RDATA |
Source: Mansion.exe0.5.dr | Static PE information: section name: malloc_h |
Source: vk_swiftshader.dll0.5.dr | Static PE information: section name: .00cfg |
Source: vk_swiftshader.dll0.5.dr | Static PE information: section name: .gxfg |
Source: vk_swiftshader.dll0.5.dr | Static PE information: section name: .retplne |
Source: vk_swiftshader.dll0.5.dr | Static PE information: section name: _RDATA |
Source: vulkan-1.dll0.5.dr | Static PE information: section name: .00cfg |
Source: vulkan-1.dll0.5.dr | Static PE information: section name: .gxfg |
Source: vulkan-1.dll0.5.dr | Static PE information: section name: .retplne |
Source: vulkan-1.dll0.5.dr | Static PE information: section name: _RDATA |
Source: qtZint.exe.9.dr | Static PE information: section name: .qtmetad |
Source: qtZint.exe.9.dr | Static PE information: section name: _RDATA |
Source: qtZint.exe.9.dr | Static PE information: section name: .qtmimed |
Source: C:\Users\user\Desktop\Mansion_setup (1).exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Mansion_setup (1).exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Mansion_setup (1).exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Mansion_setup (1).exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\Desktop\Mansion_setup (1).exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\explorer.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\2sBmKhYkAMuETMmMTCVRNvTLAaj\Mansion.exe | Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\games\DDR5_NetCache\qtZint.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\games\DDR5_NetCache\qtZint.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\games\DDR5_NetCache\qtZint.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\games\DDR5_NetCache\qtZint.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\games\DDR5_NetCache\qtZint.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\games\DDR5_NetCache\qtZint.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\games\DDR5_NetCache\qtZint.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\games\DDR5_NetCache\qtZint.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\games\DDR5_NetCache\qtZint.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\games\DDR5_NetCache\qtZint.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\games\DDR5_NetCache\qtZint.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\games\DDR5_NetCache\qtZint.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\games\DDR5_NetCache\qtZint.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\games\DDR5_NetCache\qtZint.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\games\DDR5_NetCache\qtZint.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\games\DDR5_NetCache\qtZint.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\games\DDR5_NetCache\qtZint.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\games\DDR5_NetCache\qtZint.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\games\DDR5_NetCache\qtZint.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\games\DDR5_NetCache\qtZint.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\games\DDR5_NetCache\qtZint.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\games\DDR5_NetCache\qtZint.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\games\DDR5_NetCache\qtZint.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\games\DDR5_NetCache\qtZint.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\games\DDR5_NetCache\qtZint.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\games\DDR5_NetCache\qtZint.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\games\DDR5_NetCache\qtZint.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\games\DDR5_NetCache\qtZint.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\games\DDR5_NetCache\qtZint.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\games\DDR5_NetCache\qtZint.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\games\DDR5_NetCache\qtZint.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\games\DDR5_NetCache\qtZint.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\games\DDR5_NetCache\qtZint.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\games\DDR5_NetCache\qtZint.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\games\DDR5_NetCache\qtZint.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\games\DDR5_NetCache\qtZint.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe | Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\svchost.exe | Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\svchost.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\svchost.exe | Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\svchost.exe | Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX | |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX | |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: NOOPENFILEERRORBOX | |
Source: C:\Windows\SysWOW64\WerFault.exe | Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX | |
Source: C:\Windows\System32\svchost.exe | Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\svchost.exe | Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | |
Source: C:\Program Files\Windows Media Player\wmlaunch.exe | Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | |
Source: C:\Program Files\Windows Media Player\wmlaunch.exe | Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | |
Source: C:\Program Files\Windows Media Player\wmlaunch.exe | Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\dllhost.exe | Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | |
Source: C:\Windows\System32\dllhost.exe | Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX | |
Source: explorer.exe, 0000000D.00000000.1539720367.0000000000C74000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: SCSI\DISK&VEN_VMWARE&PROD_VIRTUAL_DISK\4&1656F219&0&000000I |
Source: explorer.exe, 0000000D.00000000.1541733935.0000000003249000.00000004.00000001.00020000.00000000.sdmp | Binary or memory string: VMware, Inc. |
Source: explorer.exe, 0000000D.00000000.1565835129.0000000008DFE000.00000004.00000001.00020000.00000000.sdmp | Binary or memory string: BBSCSI\CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00\4&224f42ef&0&000000 |
Source: explorer.exe, 0000000D.00000000.1565835129.0000000008F4D000.00000004.00000001.00020000.00000000.sdmp | Binary or memory string: Hyper-V RAW |
Source: explorer.exe, 0000000D.00000000.1541733935.0000000003249000.00000004.00000001.00020000.00000000.sdmp | Binary or memory string: VMware, Inc.NoneVMware-42 27 88 19 56 cc 59 1a-97 79 fb 8c bf a1 e2 9dVMware20,1 |
Source: explorer.exe, 0000000D.00000000.1541733935.0000000003249000.00000004.00000001.00020000.00000000.sdmp | Binary or memory string: VMware, Inc.VMW201.00V.20829224.B64.221121184211/21/2022 |
Source: explorer.exe, 0000000D.00000000.1565835129.0000000009013000.00000004.00000001.00020000.00000000.sdmp | Binary or memory string: SCSI\Disk&Ven_VMware&Prod_Virtual_disk\4&1656f219&0&000000 |
Source: explorer.exe, 0000000D.00000000.1541733935.0000000003249000.00000004.00000001.00020000.00000000.sdmp | Binary or memory string: VMware SVGA II |
Source: explorer.exe, 0000000D.00000000.1547614933.0000000007306000.00000004.00000001.00020000.00000000.sdmp | Binary or memory string: War&Prod_VMware_xU1 |
Source: explorer.exe, 0000000D.00000000.1565835129.0000000008DFE000.00000004.00000001.00020000.00000000.sdmp | Binary or memory string: \\?\scsi#cdrom&ven_necvmwar&prod_vmware_sata_cd00#4&224f42ef&0&000000#{53f56308-b6bf-11d0-94f2-00a0c91efb8b}e |
Source: explorer.exe, 0000000D.00000000.1565835129.0000000008F4D000.00000004.00000001.00020000.00000000.sdmp | Binary or memory string: SCSI\Disk&Ven_VMware&Prod_Virtual_disk\4&1656f219&0&000000I}~" |
Source: explorer.exe, 0000000D.00000000.1565835129.0000000009052000.00000004.00000001.00020000.00000000.sdmp | Binary or memory string: SCSI\CDROM&VEN_NECVMWAR&PROD_VMWARE_SATA_CD00\4&224F42EF&0&000000}io |
Source: explorer.exe, 0000000D.00000000.1565835129.0000000008F4D000.00000004.00000001.00020000.00000000.sdmp | Binary or memory string: VMware SATA CD00 |
Source: explorer.exe, 0000000D.00000000.1565835129.0000000008DFE000.00000004.00000001.00020000.00000000.sdmp | Binary or memory string: Hyper-V RAWystem32\DriverStore\en-US\machine.inf_loc5 |
Source: explorer.exe, 0000000D.00000000.1541733935.0000000003249000.00000004.00000001.00020000.00000000.sdmp | Binary or memory string: VMware20,1 |
Source: explorer.exe, 0000000D.00000000.1541733935.0000000003249000.00000004.00000001.00020000.00000000.sdmp | Binary or memory string: VMware Virtual RAM00000001VMW-4096MBRAM slot #0RAM slot #0 |
Source: explorer.exe, 0000000D.00000000.1565835129.0000000008DFE000.00000004.00000001.00020000.00000000.sdmp | Binary or memory string: VMWare |
Source: explorer.exe, 0000000D.00000000.1565835129.0000000009052000.00000004.00000001.00020000.00000000.sdmp | Binary or memory string: SCSI\CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00\4&224f42ef&0&000000' |
Source: explorer.exe, 0000000D.00000000.1547614933.0000000007306000.00000004.00000001.00020000.00000000.sdmp | Binary or memory string: War&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\ |
Source: explorer.exe, 0000000D.00000000.1565835129.0000000008F27000.00000004.00000001.00020000.00000000.sdmp | Binary or memory string: Hyper-V RAWT` |
Source: explorer.exe, 0000000D.00000000.1541733935.0000000003249000.00000004.00000001.00020000.00000000.sdmp | Binary or memory string: VMware SVGA IIES1371 |
Source: explorer.exe, 0000000D.00000000.1541733935.0000000003249000.00000004.00000001.00020000.00000000.sdmp | Binary or memory string: VMware Virtual RAM |
Source: explorer.exe, 0000000D.00000000.1541733935.0000000003249000.00000004.00000001.00020000.00000000.sdmp | Binary or memory string: VMware-42 27 88 19 56 cc 59 1a-97 79 fb 8c bf a1 e2 9d |
Source: explorer.exe, 0000000D.00000000.1539720367.0000000000C74000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: SCSI\DISK&VEN_VMWARE&PROD_VIRTUAL_DISK\4&1656F219&0&000000 |
Source: explorer.exe, 0000000D.00000000.1565835129.0000000008DFE000.00000004.00000001.00020000.00000000.sdmp | Binary or memory string: \\?\scsi#cdrom&ven_necvmwar&prod_vmware_sata_cd00#4&224f42ef&0&000000#{53f56308-b6bf-11d0-94f2-00a0c91efb8b} |
Source: explorer.exe, 0000000D.00000000.1539720367.0000000000C74000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: \\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b} |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\Cache |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\Code Cache\js |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\DawnCache |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web Applications\_crx_fmgjjmmmlfnkbppncabfkddbjimcfncm |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\AvailabilityDB |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\y572q81e.default |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\Code Cache\js\index-dir |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web Applications |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\Code Cache\wasm |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Site Characteristics Database |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Code Cache\js\index-dir |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync App Settings |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web Applications\_crx_kefjledonklijopmnomlcbpllchaibag |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker\EventDB |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\fu7wner3.default-release\startupCache |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Segmentation Platform\SignalDB |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Download Service |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Download Service\EntryDB |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web Applications\_crx_agimnkijcaahngcdmfeangaknmldooml |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\fu7wner3.default-release |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\blob_storage\6f70cc77-7837-4f44-9c31-7de59e446d67 |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Download Service\Files |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\shared_proto_db |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\fu7wner3.default-release\safebrowsing\google4 |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\fu7wner3.default-release\settings\main |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Session Storage |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Code Cache |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\PersistentOriginTrials |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\Local Storage |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extension Scripts |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\WebStorage |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Code Cache\wasm |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Segmentation Platform |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Segmentation Platform\SignalStorageConfigDB |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\GCM Store\Encryption |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web Applications\_crx_aghbiahbpaijignceidepookljebhfak |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\commerce_subscription_db |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\GPUCache |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\blob_storage |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\Code Cache |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\fu7wner3.default-release\safebrowsing |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\fu7wner3.default-release\settings |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\BudgetDatabase |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Feature Engagement Tracker |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web Applications\_crx_mpnpojknpmmopombnjdcgaaiekajbnjb |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\databases |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sessions |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\shared_proto_db\metadata |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extension State |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\Network |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Code Cache\js |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\optimization_guide_model_metadata_store |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\GPUCache |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\Local Storage\leveldb |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\fu7wner3.default-release\settings\main\ms-language-packs\browser\newtab |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Network |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\GCM Store |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\Session Storage |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\fu7wner3.default-release\cache2\doomed |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\optimization_guide_hint_cache_store |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\Code Cache\wasm\index-dir |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\DawnCache |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\coupon_db |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\AutofillStrikeDatabase |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync Data |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\fu7wner3.default-release\thumbnails |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web Applications\Manifest Resources |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Code Cache\wasm\index-dir |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extension Rules |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext\nmmhkkegccagdldgiimedpiccmgmieda\def\Cache\Cache_Data |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\fu7wner3.default-release\settings\main\ms-language-packs |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Segmentation Platform\SegmentInfoDB |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Storage\ext |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web Applications\_crx_fhihpiojkbmbpdjeoajapmgkhlnakfjf |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\fu7wner3.default-release\cache2 |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\fu7wner3.default-release\settings\main\ms-language-packs\browser |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Cache |
Source: C:\Windows\System32\svchost.exe | File opened: C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\fu7wner3.default-release\cache2\entries |