Source: | Binary string: \??\C:\Users\user\Desktop\DLL\dhcpcsvc.pdbiHK source: getscreen-799952897-x86.exe, 00000000.00000002.4103075841.0000000004ABB000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: cfgmgr32.pdb( source: getscreen-799952897-x86.exe, 00000000.00000002.4110692473.0000000009904000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\DLL\cryptbase.pdbk source: getscreen-799952897-x86.exe, 00000000.00000002.4103075841.0000000004ABB000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\Kernel.Appcore.pdb}h source: getscreen-799952897-x86.exe, 00000000.00000002.4103075841.0000000004A27000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: winsta.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4110692473.0000000009DD3000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: ntmarta.pdb( source: getscreen-799952897-x86.exe, 00000000.00000002.4110692473.00000000097F1000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wkernel32.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4105286341.0000000007774000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: bcrypt.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4108262557.0000000008E00000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\DLL\dhcpcsvc6.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4103075841.0000000004ABB000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: ucrtbase.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4105286341.000000000794B000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wbemcomn.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4110692473.0000000009E8F000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: ntdsapi.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4108262557.0000000008BCF000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: msvcrt.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4105286341.0000000007760000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: e3samlib.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4106468398.000000000835D000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wrpcrt4.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4105286341.0000000007870000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wntdll.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4105286341.000000000776E000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wbemcomn.pdb( source: getscreen-799952897-x86.exe, 00000000.00000002.4110692473.0000000009E8F000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\fwpuclnt.pdb* source: getscreen-799952897-x86.exe, 00000000.00000002.4103075841.0000000004AA0000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: CoreMessaging.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4110692473.0000000009BEF000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\fwpuclnt.pdbb;K source: getscreen-799952897-x86.exe, 00000000.00000002.4103075841.0000000004ABB000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: advapi32.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4105286341.000000000777F000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wsspicli.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4108262557.00000000090B1000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: ucrtbase.pdb( source: getscreen-799952897-x86.exe, 00000000.00000002.4105286341.000000000794B000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\WindowManagementAPI.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4103075841.0000000004AA0000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\samlib.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4103075841.0000000004AA0000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: bcrypt.pdb( source: getscreen-799952897-x86.exe, 00000000.00000002.4108262557.0000000008E00000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: usp10.pdb( source: getscreen-799952897-x86.exe, 00000000.00000002.4108262557.0000000008FE0000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: audioses.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4110692473.00000000099CD000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: ntmarta.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4110692473.00000000097F1000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\Amsi.pdbb source: getscreen-799952897-x86.exe, 00000000.00000002.4103075841.0000000004AA0000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\rasadhlp.pdbdb source: getscreen-799952897-x86.exe, 00000000.00000002.4103075841.0000000004ABB000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\FWPolicyIOMgr.pdbb-h source: getscreen-799952897-x86.exe, 00000000.00000002.4103075841.0000000004A27000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\JSAMSIProvider32.pdbdb source: getscreen-799952897-x86.exe, 00000000.00000002.4103075841.0000000004AA0000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\JSAMSIProvider32.pdb2o source: getscreen-799952897-x86.exe, 00000000.00000002.4103075841.0000000004AA0000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dhcpcsvc.pdb;Pk source: getscreen-799952897-x86.exe, 00000000.00000002.4103075841.0000000004AA0000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wkernelbase.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4105286341.0000000007779000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: shlwapi.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4106468398.000000000803E000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\winsta.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4103075841.0000000004AA0000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\TextInputFramework.pdb3h source: getscreen-799952897-x86.exe, 00000000.00000002.4103075841.0000000004AA0000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: usp10.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4108262557.0000000008FE0000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\wbemcomn.pdbb source: getscreen-799952897-x86.exe, 00000000.00000002.4103075841.0000000004AA0000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: CoreMessaging.pdb( source: getscreen-799952897-x86.exe, 00000000.00000002.4110692473.0000000009BEF000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: gdiplus.pdb( source: getscreen-799952897-x86.exe, 00000000.00000002.4106468398.000000000833A000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: samcli.pdb( source: getscreen-799952897-x86.exe, 00000000.00000002.4108262557.00000000090A6000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: cryptbase.pdb( source: getscreen-799952897-x86.exe, 00000000.00000002.4108262557.00000000090BC000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\DLL\cryptbase.pdbb source: getscreen-799952897-x86.exe, 00000000.00000002.4103075841.0000000004ABB000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: netapi32.pdb( source: getscreen-799952897-x86.exe, 00000000.00000002.4108262557.0000000008B67000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: CoreUIComponents.pdb( source: getscreen-799952897-x86.exe, 00000000.00000002.4110692473.0000000009D0E000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\fwpuclnt.pdbdb#PS source: getscreen-799952897-x86.exe, 00000000.00000002.4103075841.0000000004AA0000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: comdlg32.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4105286341.00000000078EA000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: InputHost.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4110692473.0000000009C4A000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: MpOAV.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4110692473.0000000009FA8000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\twinapi.appcore.pdb]h source: getscreen-799952897-x86.exe, 00000000.00000002.4103075841.0000000004A27000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: advapi32.pdb( source: getscreen-799952897-x86.exe, 00000000.00000002.4105286341.000000000777F000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: oleacc.pdb( source: getscreen-799952897-x86.exe, 00000000.00000002.4108262557.0000000008C2F000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: winspool.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4108262557.000000000903B000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dhcpcsvc6.pdbb source: getscreen-799952897-x86.exe, 00000000.00000002.4103075841.0000000004AA0000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: iphlpapi.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4106468398.0000000008345000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: MMDevAPI.pdb( source: getscreen-799952897-x86.exe, 00000000.00000002.4110692473.000000000984D000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\wmswsock.pdb\*wQ source: getscreen-799952897-x86.exe, 00000000.00000002.4103075841.0000000004AA0000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\fwpuclnt.pdbui source: getscreen-799952897-x86.exe, 00000000.00000002.4103075841.0000000004ABB000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wrpcrt4.pdb( source: getscreen-799952897-x86.exe, 00000000.00000002.4105286341.0000000007870000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: winmm.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4108262557.0000000008F7D000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: secur32.pdb( source: getscreen-799952897-x86.exe, 00000000.00000002.4108262557.0000000008C8A000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: FirewallAPI.pdb( source: getscreen-799952897-x86.exe, 00000000.00000002.4110692473.0000000009605000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\CoreUIComponents.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4103075841.0000000004AA0000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\CoreUIComponents.pdbb2.Lh# source: getscreen-799952897-x86.exe, 00000000.00000002.4103075841.0000000004AA0000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wwin32u.pdb( source: getscreen-799952897-x86.exe, 00000000.00000002.4105286341.000000000795C000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\CoreMessaging.pdbl source: getscreen-799952897-x86.exe, 00000000.00000002.4103075841.0000000004ABB000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\rasadhlp.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4103075841.0000000004AA0000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: Windows.UI.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4110692473.0000000009A82000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\twinapi.appcore.pdb=h source: getscreen-799952897-x86.exe, 00000000.00000002.4103075841.0000000004A27000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: FWPolicyIOMgr.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4110692473.0000000009790000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\rasadhlp.pdbi source: getscreen-799952897-x86.exe, 00000000.00000002.4103075841.0000000004ABB000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\wmswsock.pdbdb source: getscreen-799952897-x86.exe, 00000000.00000002.4103075841.0000000004AA0000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: rasadhlp.pdb( source: getscreen-799952897-x86.exe, 00000000.00000002.4110692473.000000000A116000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: cfgmgr32.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4110692473.0000000009904000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: combase.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4105286341.0000000007945000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: Windows.Storage.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4110692473.00000000094E2000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wuser32.pdb( source: getscreen-799952897-x86.exe, 00000000.00000002.4105286341.0000000007956000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\InputHost.pdbbwK source: getscreen-799952897-x86.exe, 00000000.00000002.4103075841.0000000004ABB000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wkernel32.pdb( source: getscreen-799952897-x86.exe, 00000000.00000002.4105286341.0000000007774000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\wmswsock.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4103075841.0000000004ABB000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: twinapi.appcore.pdb( source: getscreen-799952897-x86.exe, 00000000.00000002.4110692473.0000000009CA5000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\samlib.pdbGQw source: getscreen-799952897-x86.exe, 00000000.00000002.4103075841.0000000004AA0000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: winsta.pdb( source: getscreen-799952897-x86.exe, 00000000.00000002.4110692473.0000000009DD3000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: secur32.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4108262557.0000000008C8A000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: TextInputFramework.pdb( source: getscreen-799952897-x86.exe, 00000000.00000002.4110692473.0000000009B3A000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dhcpcsvc.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4103075841.0000000004AA0000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: netutils.pdb( source: getscreen-799952897-x86.exe, 00000000.00000002.4108262557.00000000090C2000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: ntdsapi.pdb( source: getscreen-799952897-x86.exe, 00000000.00000002.4108262557.0000000008BCF000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\wmswsock.pdb\* source: getscreen-799952897-x86.exe, 00000000.00000002.4103075841.0000000004ABB000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: rasadhlp.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4110692473.000000000A116000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: netutils.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4108262557.00000000090C2000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wininet.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4108262557.0000000008F14000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: Kernel.Appcore.pdb( source: getscreen-799952897-x86.exe, 00000000.00000002.4110692473.0000000009542000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\rasadhlp.pdbi source: getscreen-799952897-x86.exe, 00000000.00000002.4103075841.0000000004AA0000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wgdi32full.pdb( source: getscreen-799952897-x86.exe, 00000000.00000002.4106468398.0000000008033000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: UMPDC.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4108262557.00000000090B7000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: twinapi.appcore.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4110692473.0000000009CA5000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\CoreMessaging.pdb6K source: getscreen-799952897-x86.exe, 00000000.00000002.4103075841.0000000004ABB000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: WindowManagementAPI.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4110692473.0000000009AE0000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: mfperfhelper.pdb( source: getscreen-799952897-x86.exe, 00000000.00000002.4110692473.00000000099C7000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: comctl32.pdb( source: getscreen-799952897-x86.exe, 00000000.00000002.4106468398.00000000080BB000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: comdlg32.pdb( source: getscreen-799952897-x86.exe, 00000000.00000002.4105286341.00000000078EA000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\twinapi.appcore.pdbf source: getscreen-799952897-x86.exe, 00000000.00000002.4103075841.0000000004ABB000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\wbemcomn.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4103075841.0000000004ABB000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: propsys.pdb( source: getscreen-799952897-x86.exe, 00000000.00000002.4110692473.0000000009D69000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: winmm.pdb( source: getscreen-799952897-x86.exe, 00000000.00000002.4108262557.0000000008F7D000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: shlwapi.pdb( source: getscreen-799952897-x86.exe, 00000000.00000002.4106468398.000000000803E000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\JSAMSIProvider32.pdbb source: getscreen-799952897-x86.exe, 00000000.00000002.4103075841.0000000004AA0000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wgdi32.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4106468398.000000000802D000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: oleaut32.pdb( source: getscreen-799952897-x86.exe, 00000000.00000002.4106468398.000000000818E000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: oleacc.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4108262557.0000000008C2F000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wsspicli.pdb( source: getscreen-799952897-x86.exe, 00000000.00000002.4108262557.00000000090B1000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: MMDevAPI.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4110692473.000000000984D000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\MpOAV.pdbb source: getscreen-799952897-x86.exe, 00000000.00000002.4103075841.0000000004AA0000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: samcli.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4108262557.00000000090A6000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: FirewallAPI.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4110692473.0000000009605000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\exe\getscreen-799952897-x86.pdbS source: getscreen-799952897-x86.exe, 00000000.00000002.4097273383.0000000000778000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wimm32.pdb( source: getscreen-799952897-x86.exe, 00000000.00000002.4106468398.0000000008128000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wtsapi32.pdb( source: getscreen-799952897-x86.exe, 00000000.00000002.4108262557.00000000090A0000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wimm32.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4106468398.0000000008128000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: CoreUIComponents.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4110692473.0000000009D0E000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: WindowManagementAPI.pdb( source: getscreen-799952897-x86.exe, 00000000.00000002.4110692473.0000000009AE0000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\CoreMessaging.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4103075841.0000000004ABB000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wwin32u.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4105286341.000000000795C000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: winhttp.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4108262557.0000000008EB7000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\propsys.pdbcQ source: getscreen-799952897-x86.exe, 00000000.00000002.4103075841.0000000004AA0000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: Windows.Storage.pdb( source: getscreen-799952897-x86.exe, 00000000.00000002.4110692473.00000000094E2000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\fastprox.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4103075841.0000000004ABB000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: sechost.pdb( source: getscreen-799952897-x86.exe, 00000000.00000002.4105286341.000000000780A000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: winhttp.pdb( source: getscreen-799952897-x86.exe, 00000000.00000002.4108262557.0000000008EB7000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: d3d11.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4106468398.0000000008351000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: dhcpcsvc6.pdb( source: getscreen-799952897-x86.exe, 00000000.00000002.4110692473.000000000A002000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: gdiplus.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4106468398.000000000833A000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: fwpuclnt.pdb( source: getscreen-799952897-x86.exe, 00000000.00000002.4110692473.000000000A11C000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\exe\getscreen-799952897-x86.pdb_ source: getscreen-799952897-x86.exe, 00000000.00000002.4097273383.0000000000778000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\version.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4103075841.0000000004AA0000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\fwpuclnt.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4097273383.000000000081B000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\TextInputFramework.pdbmoB source: getscreen-799952897-x86.exe, 00000000.00000002.4103075841.0000000004AA0000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: combase.pdb( source: getscreen-799952897-x86.exe, 00000000.00000002.4105286341.0000000007945000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wntdll.pdb( source: getscreen-799952897-x86.exe, 00000000.00000002.4105286341.000000000776E000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wbemprox.pdb( source: getscreen-799952897-x86.exe, 00000000.00000002.4110692473.0000000009E35000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: d3d11.pdb( source: getscreen-799952897-x86.exe, 00000000.00000002.4106468398.0000000008351000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: dhcpcsvc6.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4110692473.000000000A002000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wgdi32full.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4106468398.0000000008033000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\rasadhlp.pdb* source: getscreen-799952897-x86.exe, 00000000.00000002.4103075841.0000000004AA0000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: sechost.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4105286341.000000000780A000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\fastprox.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4103075841.0000000004AA0000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\FWPolicyIOMgr.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4103075841.0000000004ABB000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: propsys.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4110692473.0000000009D69000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: audioses.pdb( source: getscreen-799952897-x86.exe, 00000000.00000002.4110692473.00000000099CD000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: MpOAV.pdb( source: getscreen-799952897-x86.exe, 00000000.00000002.4110692473.0000000009FA8000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: fastprox.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4110692473.0000000009EEE000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\fwpuclnt.pdbdbbK source: getscreen-799952897-x86.exe, 00000000.00000002.4103075841.0000000004ABB000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\DLL\audioses.pdbb source: getscreen-799952897-x86.exe, 00000000.00000002.4103075841.0000000004ABB000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: msctf.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4110692473.000000000942A000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: FWPolicyIOMgr.pdb( source: getscreen-799952897-x86.exe, 00000000.00000002.4110692473.0000000009790000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\samlib.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4103075841.0000000004AA0000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: TextInputFramework.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4110692473.0000000009B3A000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: UMPDC.pdb( source: getscreen-799952897-x86.exe, 00000000.00000002.4108262557.00000000090B7000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: Kernel.Appcore.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4110692473.0000000009542000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: C:\Github-runner\_work\agent-windows\agent-windows\console\Win32\Release\getscreen.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4098560677.0000000001AF2000.00000040.00000001.01000000.00000003.sdmp, bvsuyaubccihxlebpdetcxrlnozylqt-elevate.exe, 00000001.00000002.4060574453.0000000001642000.00000040.00000001.01000000.00000004.sdmp, getscreen-799952897-x86.exe, 00000003.00000002.4126173661.0000000001AF2000.00000040.00000001.01000000.00000003.sdmp, getscreen-799952897-x86.exe, 00000004.00000002.4146033255.0000000001AF2000.00000040.00000001.01000000.00000003.sdmp |
Source: | Binary string: fwpuclnt.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4110692473.000000000A11C000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: cryptbase.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4108262557.00000000090BC000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: netapi32.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4108262557.0000000008B67000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wgdi32.pdb( source: getscreen-799952897-x86.exe, 00000000.00000002.4106468398.000000000802D000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: msctf.pdb( source: getscreen-799952897-x86.exe, 00000000.00000002.4110692473.000000000942A000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: bcryptprimitives.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4110692473.0000000009487000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wkernelbase.pdb( source: getscreen-799952897-x86.exe, 00000000.00000002.4105286341.0000000007779000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\wmswsock.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4103075841.0000000004AA0000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: mfperfhelper.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4110692473.00000000099C7000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: Windows.UI.pdb( source: getscreen-799952897-x86.exe, 00000000.00000002.4110692473.0000000009A82000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wtsapi32.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4108262557.00000000090A0000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\wbemsvc.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4103075841.0000000004ABB000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: oleaut32.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4106468398.000000000818E000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wuser32.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4105286341.0000000007956000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: comctl32.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4106468398.00000000080BB000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: InputHost.pdb( source: getscreen-799952897-x86.exe, 00000000.00000002.4110692473.0000000009C4A000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wbemprox.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4110692473.0000000009E35000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wininet.pdb( source: getscreen-799952897-x86.exe, 00000000.00000002.4108262557.0000000008F14000.00000004.00000020.00020000.00000000.sdmp |
Source: getscreen-799952897-x86.exe, 00000000.00000002.4098560677.00000000016E1000.00000040.00000001.01000000.00000003.sdmp, bvsuyaubccihxlebpdetcxrlnozylqt-elevate.exe, 00000001.00000002.4060574453.0000000001231000.00000040.00000001.01000000.00000004.sdmp, getscreen-799952897-x86.exe, 00000003.00000002.4126173661.00000000016E1000.00000040.00000001.01000000.00000003.sdmp, getscreen-799952897-x86.exe, 00000004.00000002.4146033255.00000000016E1000.00000040.00000001.01000000.00000003.sdmp | String found in binary or memory: http://crl.comodoca.com/AAACertificateServices.crl06 |
Source: getscreen-799952897-x86.exe, 00000000.00000002.4098560677.00000000016E1000.00000040.00000001.01000000.00000003.sdmp, bvsuyaubccihxlebpdetcxrlnozylqt-elevate.exe, 00000001.00000002.4060574453.0000000001231000.00000040.00000001.01000000.00000004.sdmp, getscreen-799952897-x86.exe, 00000003.00000002.4126173661.00000000016E1000.00000040.00000001.01000000.00000003.sdmp, getscreen-799952897-x86.exe, 00000004.00000002.4146033255.00000000016E1000.00000040.00000001.01000000.00000003.sdmp | String found in binary or memory: http://crl.comodoca.com/COMODOCertificationAuthority.crl0 |
Source: getscreen-799952897-x86.exe, 00000000.00000002.4098560677.00000000016E1000.00000040.00000001.01000000.00000003.sdmp, bvsuyaubccihxlebpdetcxrlnozylqt-elevate.exe, 00000001.00000002.4060574453.0000000001231000.00000040.00000001.01000000.00000004.sdmp, getscreen-799952897-x86.exe, 00000003.00000002.4126173661.00000000016E1000.00000040.00000001.01000000.00000003.sdmp, getscreen-799952897-x86.exe, 00000004.00000002.4146033255.00000000016E1000.00000040.00000001.01000000.00000003.sdmp | String found in binary or memory: http://crl.globalsign.net/root-r2.crl0 |
Source: getscreen-799952897-x86.exe, 00000000.00000002.4098560677.0000000001AF2000.00000040.00000001.01000000.00000003.sdmp, bvsuyaubccihxlebpdetcxrlnozylqt-elevate.exe, 00000001.00000002.4060574453.0000000001642000.00000040.00000001.01000000.00000004.sdmp, getscreen-799952897-x86.exe, 00000003.00000002.4126173661.0000000001AF2000.00000040.00000001.01000000.00000003.sdmp, getscreen-799952897-x86.exe, 00000004.00000002.4146033255.0000000001AF2000.00000040.00000001.01000000.00000003.sdmp | String found in binary or memory: http://proxy.contoso.com:3128/ |
Source: getscreen-799952897-x86.exe, 00000000.00000002.4098560677.00000000016E1000.00000040.00000001.01000000.00000003.sdmp, bvsuyaubccihxlebpdetcxrlnozylqt-elevate.exe, 00000001.00000002.4060574453.0000000001231000.00000040.00000001.01000000.00000004.sdmp, getscreen-799952897-x86.exe, 00000003.00000002.4126173661.00000000016E1000.00000040.00000001.01000000.00000003.sdmp, getscreen-799952897-x86.exe, 00000004.00000002.4146033255.00000000016E1000.00000040.00000001.01000000.00000003.sdmp | String found in binary or memory: http://www.ietf.org/id/draft-holmer-rmcat-transport-wide-cc-extensions-01 |
Source: getscreen-799952897-x86.exe, 00000000.00000002.4098560677.00000000016E1000.00000040.00000001.01000000.00000003.sdmp, bvsuyaubccihxlebpdetcxrlnozylqt-elevate.exe, 00000001.00000002.4060574453.0000000001231000.00000040.00000001.01000000.00000004.sdmp, getscreen-799952897-x86.exe, 00000003.00000002.4126173661.00000000016E1000.00000040.00000001.01000000.00000003.sdmp, getscreen-799952897-x86.exe, 00000004.00000002.4146033255.00000000016E1000.00000040.00000001.01000000.00000003.sdmp | String found in binary or memory: http://www.ietf.org/id/draft-holmer-rmcat-transport-wide-cc-extensions-01http://www.webrtc.org/exper |
Source: getscreen-799952897-x86.exe, 00000000.00000002.4098560677.00000000016E1000.00000040.00000001.01000000.00000003.sdmp, bvsuyaubccihxlebpdetcxrlnozylqt-elevate.exe, 00000001.00000002.4060574453.0000000001231000.00000040.00000001.01000000.00000004.sdmp, getscreen-799952897-x86.exe, 00000003.00000002.4126173661.00000000016E1000.00000040.00000001.01000000.00000003.sdmp, getscreen-799952897-x86.exe, 00000004.00000002.4146033255.00000000016E1000.00000040.00000001.01000000.00000003.sdmp | String found in binary or memory: http://www.webrtc.org/experiments/rtp-hdrext/abs-capture-time |
Source: getscreen-799952897-x86.exe, 00000000.00000002.4098560677.00000000016E1000.00000040.00000001.01000000.00000003.sdmp, bvsuyaubccihxlebpdetcxrlnozylqt-elevate.exe, 00000001.00000002.4060574453.0000000001231000.00000040.00000001.01000000.00000004.sdmp, getscreen-799952897-x86.exe, 00000003.00000002.4126173661.00000000016E1000.00000040.00000001.01000000.00000003.sdmp, getscreen-799952897-x86.exe, 00000004.00000002.4146033255.00000000016E1000.00000040.00000001.01000000.00000003.sdmp | String found in binary or memory: http://www.webrtc.org/experiments/rtp-hdrext/abs-capture-timeurn:3gpp:video-orientationhttp://www.we |
Source: getscreen-799952897-x86.exe, 00000000.00000002.4098560677.00000000016E1000.00000040.00000001.01000000.00000003.sdmp, bvsuyaubccihxlebpdetcxrlnozylqt-elevate.exe, 00000001.00000002.4060574453.0000000001231000.00000040.00000001.01000000.00000004.sdmp, getscreen-799952897-x86.exe, 00000003.00000002.4126173661.00000000016E1000.00000040.00000001.01000000.00000003.sdmp, getscreen-799952897-x86.exe, 00000004.00000002.4146033255.00000000016E1000.00000040.00000001.01000000.00000003.sdmp | String found in binary or memory: http://www.webrtc.org/experiments/rtp-hdrext/abs-send-time |
Source: getscreen-799952897-x86.exe, 00000000.00000002.4098560677.00000000016E1000.00000040.00000001.01000000.00000003.sdmp, bvsuyaubccihxlebpdetcxrlnozylqt-elevate.exe, 00000001.00000002.4060574453.0000000001231000.00000040.00000001.01000000.00000004.sdmp, getscreen-799952897-x86.exe, 00000003.00000002.4126173661.00000000016E1000.00000040.00000001.01000000.00000003.sdmp, getscreen-799952897-x86.exe, 00000004.00000002.4146033255.00000000016E1000.00000040.00000001.01000000.00000003.sdmp | String found in binary or memory: http://www.webrtc.org/experiments/rtp-hdrext/color-space |
Source: getscreen-799952897-x86.exe, 00000000.00000002.4098560677.00000000016E1000.00000040.00000001.01000000.00000003.sdmp, bvsuyaubccihxlebpdetcxrlnozylqt-elevate.exe, 00000001.00000002.4060574453.0000000001231000.00000040.00000001.01000000.00000004.sdmp, getscreen-799952897-x86.exe, 00000003.00000002.4126173661.00000000016E1000.00000040.00000001.01000000.00000003.sdmp, getscreen-799952897-x86.exe, 00000004.00000002.4146033255.00000000016E1000.00000040.00000001.01000000.00000003.sdmp | String found in binary or memory: http://www.webrtc.org/experiments/rtp-hdrext/generic-frame-descriptor-00 |
Source: getscreen-799952897-x86.exe, 00000004.00000002.4146033255.00000000016E1000.00000040.00000001.01000000.00000003.sdmp | String found in binary or memory: http://www.webrtc.org/experiments/rtp-hdrext/inband-cn |
Source: getscreen-799952897-x86.exe, 00000000.00000002.4098560677.00000000016E1000.00000040.00000001.01000000.00000003.sdmp, bvsuyaubccihxlebpdetcxrlnozylqt-elevate.exe, 00000001.00000002.4060574453.0000000001231000.00000040.00000001.01000000.00000004.sdmp, getscreen-799952897-x86.exe, 00000003.00000002.4126173661.00000000016E1000.00000040.00000001.01000000.00000003.sdmp, getscreen-799952897-x86.exe, 00000004.00000002.4146033255.00000000016E1000.00000040.00000001.01000000.00000003.sdmp | String found in binary or memory: http://www.webrtc.org/experiments/rtp-hdrext/playout-delay |
Source: getscreen-799952897-x86.exe, 00000000.00000002.4098560677.00000000016E1000.00000040.00000001.01000000.00000003.sdmp, bvsuyaubccihxlebpdetcxrlnozylqt-elevate.exe, 00000001.00000002.4060574453.0000000001231000.00000040.00000001.01000000.00000004.sdmp, getscreen-799952897-x86.exe, 00000003.00000002.4126173661.00000000016E1000.00000040.00000001.01000000.00000003.sdmp, getscreen-799952897-x86.exe, 00000004.00000002.4146033255.00000000016E1000.00000040.00000001.01000000.00000003.sdmp | String found in binary or memory: http://www.webrtc.org/experiments/rtp-hdrext/transport-wide-cc-02 |
Source: getscreen-799952897-x86.exe, 00000000.00000002.4098560677.00000000016E1000.00000040.00000001.01000000.00000003.sdmp, bvsuyaubccihxlebpdetcxrlnozylqt-elevate.exe, 00000001.00000002.4060574453.0000000001231000.00000040.00000001.01000000.00000004.sdmp, getscreen-799952897-x86.exe, 00000003.00000002.4126173661.00000000016E1000.00000040.00000001.01000000.00000003.sdmp, getscreen-799952897-x86.exe, 00000004.00000002.4146033255.00000000016E1000.00000040.00000001.01000000.00000003.sdmp | String found in binary or memory: http://www.webrtc.org/experiments/rtp-hdrext/video-content-type |
Source: getscreen-799952897-x86.exe, 00000000.00000002.4098560677.00000000016E1000.00000040.00000001.01000000.00000003.sdmp, bvsuyaubccihxlebpdetcxrlnozylqt-elevate.exe, 00000001.00000002.4060574453.0000000001231000.00000040.00000001.01000000.00000004.sdmp, getscreen-799952897-x86.exe, 00000003.00000002.4126173661.00000000016E1000.00000040.00000001.01000000.00000003.sdmp, getscreen-799952897-x86.exe, 00000004.00000002.4146033255.00000000016E1000.00000040.00000001.01000000.00000003.sdmp | String found in binary or memory: http://www.webrtc.org/experiments/rtp-hdrext/video-frame-tracking-id |
Source: getscreen-799952897-x86.exe, 00000000.00000002.4098560677.00000000016E1000.00000040.00000001.01000000.00000003.sdmp, bvsuyaubccihxlebpdetcxrlnozylqt-elevate.exe, 00000001.00000002.4060574453.0000000001231000.00000040.00000001.01000000.00000004.sdmp, getscreen-799952897-x86.exe, 00000003.00000002.4126173661.00000000016E1000.00000040.00000001.01000000.00000003.sdmp, getscreen-799952897-x86.exe, 00000004.00000002.4146033255.00000000016E1000.00000040.00000001.01000000.00000003.sdmp | String found in binary or memory: http://www.webrtc.org/experiments/rtp-hdrext/video-layers-allocation00 |
Source: getscreen-799952897-x86.exe, 00000000.00000002.4098560677.00000000016E1000.00000040.00000001.01000000.00000003.sdmp, bvsuyaubccihxlebpdetcxrlnozylqt-elevate.exe, 00000001.00000002.4060574453.0000000001231000.00000040.00000001.01000000.00000004.sdmp, getscreen-799952897-x86.exe, 00000003.00000002.4126173661.00000000016E1000.00000040.00000001.01000000.00000003.sdmp, getscreen-799952897-x86.exe, 00000004.00000002.4146033255.00000000016E1000.00000040.00000001.01000000.00000003.sdmp | String found in binary or memory: http://www.webrtc.org/experiments/rtp-hdrext/video-timing |
Source: getscreen-799952897-x86.exe, 00000000.00000002.4098560677.0000000001AF2000.00000040.00000001.01000000.00000003.sdmp, bvsuyaubccihxlebpdetcxrlnozylqt-elevate.exe, 00000001.00000002.4060574453.0000000001642000.00000040.00000001.01000000.00000004.sdmp, getscreen-799952897-x86.exe, 00000003.00000002.4126173661.0000000001AF2000.00000040.00000001.01000000.00000003.sdmp, getscreen-799952897-x86.exe, 00000004.00000002.4146033255.0000000001AF2000.00000040.00000001.01000000.00000003.sdmp | String found in binary or memory: http://www.winimage.com/zLibDll |
Source: getscreen-799952897-x86.exe, 00000000.00000002.4098560677.00000000016E1000.00000040.00000001.01000000.00000003.sdmp, bvsuyaubccihxlebpdetcxrlnozylqt-elevate.exe, 00000001.00000002.4060574453.0000000001231000.00000040.00000001.01000000.00000004.sdmp, getscreen-799952897-x86.exe, 00000003.00000002.4126173661.00000000016E1000.00000040.00000001.01000000.00000003.sdmp, getscreen-799952897-x86.exe, 00000004.00000002.4146033255.00000000016E1000.00000040.00000001.01000000.00000003.sdmp | String found in binary or memory: https://aomediacodec.github.io/av1-rtp-spec/#dependency-descriptor-rtp-header-extension |
Source: getscreen-799952897-x86.exe, 00000000.00000002.4098560677.0000000001AF2000.00000040.00000001.01000000.00000003.sdmp, bvsuyaubccihxlebpdetcxrlnozylqt-elevate.exe, 00000001.00000002.4060574453.0000000001642000.00000040.00000001.01000000.00000004.sdmp, getscreen-799952897-x86.exe, 00000003.00000002.4126173661.0000000001AF2000.00000040.00000001.01000000.00000003.sdmp, getscreen-799952897-x86.exe, 00000004.00000002.4146033255.0000000001AF2000.00000040.00000001.01000000.00000003.sdmp | String found in binary or memory: https://docs.g |
Source: getscreen-799952897-x86.exe, 00000000.00000002.4098560677.0000000001AF2000.00000040.00000001.01000000.00000003.sdmp, bvsuyaubccihxlebpdetcxrlnozylqt-elevate.exe, 00000001.00000002.4060574453.0000000001642000.00000040.00000001.01000000.00000004.sdmp, getscreen-799952897-x86.exe, 00000003.00000002.4126173661.0000000001AF2000.00000040.00000001.01000000.00000003.sdmp, getscreen-799952897-x86.exe, 00000004.00000002.4146033255.0000000001AF2000.00000040.00000001.01000000.00000003.sdmp, getscreen-799952897-x86.exe, 00000004.00000003.4089809835.0000000007DDD000.00000004.00000020.00020000.00000000.sdmp, getscreen-799952897-x86.exe, 00000004.00000003.4085577963.0000000007DC4000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://docs.ge |
Source: getscreen-799952897-x86.exe, 00000000.00000002.4098560677.0000000001AF2000.00000040.00000001.01000000.00000003.sdmp, bvsuyaubccihxlebpdetcxrlnozylqt-elevate.exe, 00000001.00000002.4060574453.0000000001642000.00000040.00000001.01000000.00000004.sdmp, getscreen-799952897-x86.exe, 00000003.00000002.4126173661.0000000001AF2000.00000040.00000001.01000000.00000003.sdmp, getscreen-799952897-x86.exe, 00000004.00000002.4146033255.0000000001AF2000.00000040.00000001.01000000.00000003.sdmp | String found in binary or memory: https://docs.getsa |
Source: getscreen-799952897-x86.exe, 00000004.00000002.4146033255.0000000001AF2000.00000040.00000001.01000000.00000003.sdmp | String found in binary or memory: https://docs.getsc |
Source: getscreen-799952897-x86.exe, 00000004.00000003.4145294116.0000000007DDE000.00000004.00000020.00020000.00000000.sdmp, getscreen-799952897-x86.exe, 00000004.00000003.4128420216.0000000007DCB000.00000004.00000020.00020000.00000000.sdmp, getscreen-799952897-x86.exe, 00000004.00000003.4145196397.0000000007DD9000.00000004.00000020.00020000.00000000.sdmp, getscreen-799952897-x86.exe, 00000004.00000003.4129517858.0000000007DD8000.00000004.00000020.00020000.00000000.sdmp, getscreen-799952897-x86.exe, 00000004.00000003.4126900753.0000000007DAB000.00000004.00000020.00020000.00000000.sdmp, getscreen-799952897-x86.exe, 00000004.00000003.4134244952.0000000007DD9000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://docs.getscr |
Source: getscreen-799952897-x86.exe, 00000004.00000003.4144674146.0000000003004000.00000004.00000020.00020000.00000000.sdmp, getscreen-799952897-x86.exe, 00000004.00000003.4144279941.0000000003015000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://docs.getscreen.me/en/rules/privacy-policy/ |
Source: getscreen-799952897-x86.exe, 00000004.00000003.4144674146.0000000003004000.00000004.00000020.00020000.00000000.sdmp, getscreen-799952897-x86.exe, 00000004.00000003.4144279941.0000000003015000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://docs.getscreen.me/en/rules/terms-of-use/ |
Source: getscreen-799952897-x86.exe, 00000004.00000003.4089809835.0000000007DDD000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://docs.getscreen.me/user |
Source: getscreen-799952897-x86.exe, 00000004.00000003.4126900753.0000000007DAB000.00000004.00000020.00020000.00000000.sdmp, getscreen-799952897-x86.exe, 00000004.00000003.4124630475.0000000005CEE000.00000004.00000020.00020000.00000000.sdmp, getscreen-799952897-x86.exe, 00000004.00000003.4128580498.0000000007DB8000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://docs.getscreen.me/user-guides/agent/ |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: d3d11.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: dbghelp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: dxgi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: msdmo.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: msi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: netapi32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: ntdsapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: oleacc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: powrprof.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: sas.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: secur32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: usp10.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: winmm.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: wtsapi32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: samcli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: dsparse.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: edgegdi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: umpdc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: firewallapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: dnsapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: fwbase.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: fwpolicyiomgr.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: mmdevapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: devobj.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: avrt.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: mfwmaaec.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: mfperfhelper.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: audioses.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: avrt.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: windows.ui.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: windowmanagementapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: textinputframework.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: inputhost.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: twinapi.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: twinapi.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: coreuicomponents.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: winsta.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: wbemcomn.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: dhcpcsvc6.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: dhcpcsvc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: rasadhlp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: fwpuclnt.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: samlib.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: symsrv.dll | Jump to behavior |
Source: C:\ProgramData\Getscreen.me\bvsuyaubccihxlebpdetcxrlnozylqt-elevate.exe | Section loaded: d3d11.dll | Jump to behavior |
Source: C:\ProgramData\Getscreen.me\bvsuyaubccihxlebpdetcxrlnozylqt-elevate.exe | Section loaded: dbghelp.dll | Jump to behavior |
Source: C:\ProgramData\Getscreen.me\bvsuyaubccihxlebpdetcxrlnozylqt-elevate.exe | Section loaded: dxgi.dll | Jump to behavior |
Source: C:\ProgramData\Getscreen.me\bvsuyaubccihxlebpdetcxrlnozylqt-elevate.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\ProgramData\Getscreen.me\bvsuyaubccihxlebpdetcxrlnozylqt-elevate.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\ProgramData\Getscreen.me\bvsuyaubccihxlebpdetcxrlnozylqt-elevate.exe | Section loaded: msdmo.dll | Jump to behavior |
Source: C:\ProgramData\Getscreen.me\bvsuyaubccihxlebpdetcxrlnozylqt-elevate.exe | Section loaded: msi.dll | Jump to behavior |
Source: C:\ProgramData\Getscreen.me\bvsuyaubccihxlebpdetcxrlnozylqt-elevate.exe | Section loaded: netapi32.dll | Jump to behavior |
Source: C:\ProgramData\Getscreen.me\bvsuyaubccihxlebpdetcxrlnozylqt-elevate.exe | Section loaded: ntdsapi.dll | Jump to behavior |
Source: C:\ProgramData\Getscreen.me\bvsuyaubccihxlebpdetcxrlnozylqt-elevate.exe | Section loaded: oleacc.dll | Jump to behavior |
Source: C:\ProgramData\Getscreen.me\bvsuyaubccihxlebpdetcxrlnozylqt-elevate.exe | Section loaded: powrprof.dll | Jump to behavior |
Source: C:\ProgramData\Getscreen.me\bvsuyaubccihxlebpdetcxrlnozylqt-elevate.exe | Section loaded: sas.dll | Jump to behavior |
Source: C:\ProgramData\Getscreen.me\bvsuyaubccihxlebpdetcxrlnozylqt-elevate.exe | Section loaded: secur32.dll | Jump to behavior |
Source: C:\ProgramData\Getscreen.me\bvsuyaubccihxlebpdetcxrlnozylqt-elevate.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\ProgramData\Getscreen.me\bvsuyaubccihxlebpdetcxrlnozylqt-elevate.exe | Section loaded: usp10.dll | Jump to behavior |
Source: C:\ProgramData\Getscreen.me\bvsuyaubccihxlebpdetcxrlnozylqt-elevate.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\ProgramData\Getscreen.me\bvsuyaubccihxlebpdetcxrlnozylqt-elevate.exe | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\ProgramData\Getscreen.me\bvsuyaubccihxlebpdetcxrlnozylqt-elevate.exe | Section loaded: wininet.dll | Jump to behavior |
Source: C:\ProgramData\Getscreen.me\bvsuyaubccihxlebpdetcxrlnozylqt-elevate.exe | Section loaded: winmm.dll | Jump to behavior |
Source: C:\ProgramData\Getscreen.me\bvsuyaubccihxlebpdetcxrlnozylqt-elevate.exe | Section loaded: wtsapi32.dll | Jump to behavior |
Source: C:\ProgramData\Getscreen.me\bvsuyaubccihxlebpdetcxrlnozylqt-elevate.exe | Section loaded: samcli.dll | Jump to behavior |
Source: C:\ProgramData\Getscreen.me\bvsuyaubccihxlebpdetcxrlnozylqt-elevate.exe | Section loaded: dsparse.dll | Jump to behavior |
Source: C:\ProgramData\Getscreen.me\bvsuyaubccihxlebpdetcxrlnozylqt-elevate.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\ProgramData\Getscreen.me\bvsuyaubccihxlebpdetcxrlnozylqt-elevate.exe | Section loaded: edgegdi.dll | Jump to behavior |
Source: C:\ProgramData\Getscreen.me\bvsuyaubccihxlebpdetcxrlnozylqt-elevate.exe | Section loaded: umpdc.dll | Jump to behavior |
Source: C:\ProgramData\Getscreen.me\bvsuyaubccihxlebpdetcxrlnozylqt-elevate.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\ProgramData\Getscreen.me\bvsuyaubccihxlebpdetcxrlnozylqt-elevate.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\ProgramData\Getscreen.me\bvsuyaubccihxlebpdetcxrlnozylqt-elevate.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\ProgramData\Getscreen.me\bvsuyaubccihxlebpdetcxrlnozylqt-elevate.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\ProgramData\Getscreen.me\bvsuyaubccihxlebpdetcxrlnozylqt-elevate.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\ProgramData\Getscreen.me\bvsuyaubccihxlebpdetcxrlnozylqt-elevate.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: edgegdi.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: seclogon.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\System32\svchost.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: d3d11.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: dbghelp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: dxgi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: msdmo.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: msi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: netapi32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: ntdsapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: oleacc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: powrprof.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: sas.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: secur32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: usp10.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: winmm.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: wtsapi32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: samcli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: dsparse.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: edgegdi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: umpdc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: winsta.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: d3d11.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: dbghelp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: dxgi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: msdmo.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: msi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: netapi32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: ntdsapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: oleacc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: dxgi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: powrprof.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: sas.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: secur32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: usp10.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: wininet.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: winmm.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: wtsapi32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: samcli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: dsparse.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: edgegdi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: umpdc.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: d2d1.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: dwrite.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: dwmapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: dataexchange.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: dcomp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: twinapi.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: directmanipulation.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: resourcepolicyclient.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: ncrypt.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: ntasn1.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: dxcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: windowscodecs.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: mscms.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: coloradapterclient.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: icm32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: textinputframework.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: coreuicomponents.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: uiautomationcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: textshaping.dll | Jump to behavior |
Source: C:\Users\user\Desktop\getscreen-799952897-x86.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: | Binary string: \??\C:\Users\user\Desktop\DLL\dhcpcsvc.pdbiHK source: getscreen-799952897-x86.exe, 00000000.00000002.4103075841.0000000004ABB000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: cfgmgr32.pdb( source: getscreen-799952897-x86.exe, 00000000.00000002.4110692473.0000000009904000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\DLL\cryptbase.pdbk source: getscreen-799952897-x86.exe, 00000000.00000002.4103075841.0000000004ABB000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\Kernel.Appcore.pdb}h source: getscreen-799952897-x86.exe, 00000000.00000002.4103075841.0000000004A27000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: winsta.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4110692473.0000000009DD3000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: ntmarta.pdb( source: getscreen-799952897-x86.exe, 00000000.00000002.4110692473.00000000097F1000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wkernel32.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4105286341.0000000007774000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: bcrypt.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4108262557.0000000008E00000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\DLL\dhcpcsvc6.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4103075841.0000000004ABB000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: ucrtbase.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4105286341.000000000794B000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wbemcomn.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4110692473.0000000009E8F000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: ntdsapi.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4108262557.0000000008BCF000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: msvcrt.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4105286341.0000000007760000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: e3samlib.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4106468398.000000000835D000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wrpcrt4.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4105286341.0000000007870000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wntdll.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4105286341.000000000776E000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wbemcomn.pdb( source: getscreen-799952897-x86.exe, 00000000.00000002.4110692473.0000000009E8F000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\fwpuclnt.pdb* source: getscreen-799952897-x86.exe, 00000000.00000002.4103075841.0000000004AA0000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: CoreMessaging.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4110692473.0000000009BEF000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\fwpuclnt.pdbb;K source: getscreen-799952897-x86.exe, 00000000.00000002.4103075841.0000000004ABB000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: advapi32.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4105286341.000000000777F000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wsspicli.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4108262557.00000000090B1000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: ucrtbase.pdb( source: getscreen-799952897-x86.exe, 00000000.00000002.4105286341.000000000794B000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\WindowManagementAPI.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4103075841.0000000004AA0000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\samlib.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4103075841.0000000004AA0000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: bcrypt.pdb( source: getscreen-799952897-x86.exe, 00000000.00000002.4108262557.0000000008E00000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: usp10.pdb( source: getscreen-799952897-x86.exe, 00000000.00000002.4108262557.0000000008FE0000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: audioses.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4110692473.00000000099CD000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: ntmarta.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4110692473.00000000097F1000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\Amsi.pdbb source: getscreen-799952897-x86.exe, 00000000.00000002.4103075841.0000000004AA0000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\rasadhlp.pdbdb source: getscreen-799952897-x86.exe, 00000000.00000002.4103075841.0000000004ABB000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\FWPolicyIOMgr.pdbb-h source: getscreen-799952897-x86.exe, 00000000.00000002.4103075841.0000000004A27000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\JSAMSIProvider32.pdbdb source: getscreen-799952897-x86.exe, 00000000.00000002.4103075841.0000000004AA0000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\JSAMSIProvider32.pdb2o source: getscreen-799952897-x86.exe, 00000000.00000002.4103075841.0000000004AA0000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dhcpcsvc.pdb;Pk source: getscreen-799952897-x86.exe, 00000000.00000002.4103075841.0000000004AA0000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wkernelbase.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4105286341.0000000007779000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: shlwapi.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4106468398.000000000803E000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\winsta.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4103075841.0000000004AA0000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\TextInputFramework.pdb3h source: getscreen-799952897-x86.exe, 00000000.00000002.4103075841.0000000004AA0000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: usp10.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4108262557.0000000008FE0000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\wbemcomn.pdbb source: getscreen-799952897-x86.exe, 00000000.00000002.4103075841.0000000004AA0000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: CoreMessaging.pdb( source: getscreen-799952897-x86.exe, 00000000.00000002.4110692473.0000000009BEF000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: gdiplus.pdb( source: getscreen-799952897-x86.exe, 00000000.00000002.4106468398.000000000833A000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: samcli.pdb( source: getscreen-799952897-x86.exe, 00000000.00000002.4108262557.00000000090A6000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: cryptbase.pdb( source: getscreen-799952897-x86.exe, 00000000.00000002.4108262557.00000000090BC000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\DLL\cryptbase.pdbb source: getscreen-799952897-x86.exe, 00000000.00000002.4103075841.0000000004ABB000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: netapi32.pdb( source: getscreen-799952897-x86.exe, 00000000.00000002.4108262557.0000000008B67000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: CoreUIComponents.pdb( source: getscreen-799952897-x86.exe, 00000000.00000002.4110692473.0000000009D0E000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\fwpuclnt.pdbdb#PS source: getscreen-799952897-x86.exe, 00000000.00000002.4103075841.0000000004AA0000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: comdlg32.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4105286341.00000000078EA000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: InputHost.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4110692473.0000000009C4A000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: MpOAV.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4110692473.0000000009FA8000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\twinapi.appcore.pdb]h source: getscreen-799952897-x86.exe, 00000000.00000002.4103075841.0000000004A27000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: advapi32.pdb( source: getscreen-799952897-x86.exe, 00000000.00000002.4105286341.000000000777F000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: oleacc.pdb( source: getscreen-799952897-x86.exe, 00000000.00000002.4108262557.0000000008C2F000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: winspool.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4108262557.000000000903B000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dhcpcsvc6.pdbb source: getscreen-799952897-x86.exe, 00000000.00000002.4103075841.0000000004AA0000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: iphlpapi.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4106468398.0000000008345000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: MMDevAPI.pdb( source: getscreen-799952897-x86.exe, 00000000.00000002.4110692473.000000000984D000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\wmswsock.pdb\*wQ source: getscreen-799952897-x86.exe, 00000000.00000002.4103075841.0000000004AA0000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\fwpuclnt.pdbui source: getscreen-799952897-x86.exe, 00000000.00000002.4103075841.0000000004ABB000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wrpcrt4.pdb( source: getscreen-799952897-x86.exe, 00000000.00000002.4105286341.0000000007870000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: winmm.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4108262557.0000000008F7D000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: secur32.pdb( source: getscreen-799952897-x86.exe, 00000000.00000002.4108262557.0000000008C8A000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: FirewallAPI.pdb( source: getscreen-799952897-x86.exe, 00000000.00000002.4110692473.0000000009605000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\CoreUIComponents.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4103075841.0000000004AA0000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\CoreUIComponents.pdbb2.Lh# source: getscreen-799952897-x86.exe, 00000000.00000002.4103075841.0000000004AA0000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wwin32u.pdb( source: getscreen-799952897-x86.exe, 00000000.00000002.4105286341.000000000795C000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\CoreMessaging.pdbl source: getscreen-799952897-x86.exe, 00000000.00000002.4103075841.0000000004ABB000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\rasadhlp.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4103075841.0000000004AA0000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: Windows.UI.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4110692473.0000000009A82000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\twinapi.appcore.pdb=h source: getscreen-799952897-x86.exe, 00000000.00000002.4103075841.0000000004A27000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: FWPolicyIOMgr.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4110692473.0000000009790000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\rasadhlp.pdbi source: getscreen-799952897-x86.exe, 00000000.00000002.4103075841.0000000004ABB000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\wmswsock.pdbdb source: getscreen-799952897-x86.exe, 00000000.00000002.4103075841.0000000004AA0000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: rasadhlp.pdb( source: getscreen-799952897-x86.exe, 00000000.00000002.4110692473.000000000A116000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: cfgmgr32.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4110692473.0000000009904000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: combase.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4105286341.0000000007945000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: Windows.Storage.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4110692473.00000000094E2000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wuser32.pdb( source: getscreen-799952897-x86.exe, 00000000.00000002.4105286341.0000000007956000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\InputHost.pdbbwK source: getscreen-799952897-x86.exe, 00000000.00000002.4103075841.0000000004ABB000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wkernel32.pdb( source: getscreen-799952897-x86.exe, 00000000.00000002.4105286341.0000000007774000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\wmswsock.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4103075841.0000000004ABB000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: twinapi.appcore.pdb( source: getscreen-799952897-x86.exe, 00000000.00000002.4110692473.0000000009CA5000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\samlib.pdbGQw source: getscreen-799952897-x86.exe, 00000000.00000002.4103075841.0000000004AA0000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: winsta.pdb( source: getscreen-799952897-x86.exe, 00000000.00000002.4110692473.0000000009DD3000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: secur32.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4108262557.0000000008C8A000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: TextInputFramework.pdb( source: getscreen-799952897-x86.exe, 00000000.00000002.4110692473.0000000009B3A000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dhcpcsvc.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4103075841.0000000004AA0000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: netutils.pdb( source: getscreen-799952897-x86.exe, 00000000.00000002.4108262557.00000000090C2000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: ntdsapi.pdb( source: getscreen-799952897-x86.exe, 00000000.00000002.4108262557.0000000008BCF000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\wmswsock.pdb\* source: getscreen-799952897-x86.exe, 00000000.00000002.4103075841.0000000004ABB000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: rasadhlp.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4110692473.000000000A116000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: netutils.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4108262557.00000000090C2000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wininet.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4108262557.0000000008F14000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: Kernel.Appcore.pdb( source: getscreen-799952897-x86.exe, 00000000.00000002.4110692473.0000000009542000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\rasadhlp.pdbi source: getscreen-799952897-x86.exe, 00000000.00000002.4103075841.0000000004AA0000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wgdi32full.pdb( source: getscreen-799952897-x86.exe, 00000000.00000002.4106468398.0000000008033000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: UMPDC.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4108262557.00000000090B7000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: twinapi.appcore.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4110692473.0000000009CA5000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\CoreMessaging.pdb6K source: getscreen-799952897-x86.exe, 00000000.00000002.4103075841.0000000004ABB000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: WindowManagementAPI.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4110692473.0000000009AE0000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: mfperfhelper.pdb( source: getscreen-799952897-x86.exe, 00000000.00000002.4110692473.00000000099C7000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: comctl32.pdb( source: getscreen-799952897-x86.exe, 00000000.00000002.4106468398.00000000080BB000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: comdlg32.pdb( source: getscreen-799952897-x86.exe, 00000000.00000002.4105286341.00000000078EA000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\twinapi.appcore.pdbf source: getscreen-799952897-x86.exe, 00000000.00000002.4103075841.0000000004ABB000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\wbemcomn.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4103075841.0000000004ABB000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: propsys.pdb( source: getscreen-799952897-x86.exe, 00000000.00000002.4110692473.0000000009D69000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: winmm.pdb( source: getscreen-799952897-x86.exe, 00000000.00000002.4108262557.0000000008F7D000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: shlwapi.pdb( source: getscreen-799952897-x86.exe, 00000000.00000002.4106468398.000000000803E000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\JSAMSIProvider32.pdbb source: getscreen-799952897-x86.exe, 00000000.00000002.4103075841.0000000004AA0000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wgdi32.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4106468398.000000000802D000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: oleaut32.pdb( source: getscreen-799952897-x86.exe, 00000000.00000002.4106468398.000000000818E000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: oleacc.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4108262557.0000000008C2F000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wsspicli.pdb( source: getscreen-799952897-x86.exe, 00000000.00000002.4108262557.00000000090B1000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: MMDevAPI.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4110692473.000000000984D000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\MpOAV.pdbb source: getscreen-799952897-x86.exe, 00000000.00000002.4103075841.0000000004AA0000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: samcli.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4108262557.00000000090A6000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: FirewallAPI.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4110692473.0000000009605000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\exe\getscreen-799952897-x86.pdbS source: getscreen-799952897-x86.exe, 00000000.00000002.4097273383.0000000000778000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wimm32.pdb( source: getscreen-799952897-x86.exe, 00000000.00000002.4106468398.0000000008128000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wtsapi32.pdb( source: getscreen-799952897-x86.exe, 00000000.00000002.4108262557.00000000090A0000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wimm32.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4106468398.0000000008128000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: CoreUIComponents.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4110692473.0000000009D0E000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: WindowManagementAPI.pdb( source: getscreen-799952897-x86.exe, 00000000.00000002.4110692473.0000000009AE0000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\CoreMessaging.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4103075841.0000000004ABB000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wwin32u.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4105286341.000000000795C000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: winhttp.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4108262557.0000000008EB7000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\propsys.pdbcQ source: getscreen-799952897-x86.exe, 00000000.00000002.4103075841.0000000004AA0000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: Windows.Storage.pdb( source: getscreen-799952897-x86.exe, 00000000.00000002.4110692473.00000000094E2000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\fastprox.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4103075841.0000000004ABB000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: sechost.pdb( source: getscreen-799952897-x86.exe, 00000000.00000002.4105286341.000000000780A000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: winhttp.pdb( source: getscreen-799952897-x86.exe, 00000000.00000002.4108262557.0000000008EB7000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: d3d11.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4106468398.0000000008351000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: dhcpcsvc6.pdb( source: getscreen-799952897-x86.exe, 00000000.00000002.4110692473.000000000A002000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: gdiplus.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4106468398.000000000833A000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: fwpuclnt.pdb( source: getscreen-799952897-x86.exe, 00000000.00000002.4110692473.000000000A11C000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\exe\getscreen-799952897-x86.pdb_ source: getscreen-799952897-x86.exe, 00000000.00000002.4097273383.0000000000778000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\version.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4103075841.0000000004AA0000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\fwpuclnt.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4097273383.000000000081B000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\symbols\dll\TextInputFramework.pdbmoB source: getscreen-799952897-x86.exe, 00000000.00000002.4103075841.0000000004AA0000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: combase.pdb( source: getscreen-799952897-x86.exe, 00000000.00000002.4105286341.0000000007945000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wntdll.pdb( source: getscreen-799952897-x86.exe, 00000000.00000002.4105286341.000000000776E000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wbemprox.pdb( source: getscreen-799952897-x86.exe, 00000000.00000002.4110692473.0000000009E35000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: d3d11.pdb( source: getscreen-799952897-x86.exe, 00000000.00000002.4106468398.0000000008351000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: dhcpcsvc6.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4110692473.000000000A002000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wgdi32full.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4106468398.0000000008033000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\rasadhlp.pdb* source: getscreen-799952897-x86.exe, 00000000.00000002.4103075841.0000000004AA0000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: sechost.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4105286341.000000000780A000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\fastprox.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4103075841.0000000004AA0000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\FWPolicyIOMgr.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4103075841.0000000004ABB000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: propsys.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4110692473.0000000009D69000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: audioses.pdb( source: getscreen-799952897-x86.exe, 00000000.00000002.4110692473.00000000099CD000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: MpOAV.pdb( source: getscreen-799952897-x86.exe, 00000000.00000002.4110692473.0000000009FA8000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: fastprox.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4110692473.0000000009EEE000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\fwpuclnt.pdbdbbK source: getscreen-799952897-x86.exe, 00000000.00000002.4103075841.0000000004ABB000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\DLL\audioses.pdbb source: getscreen-799952897-x86.exe, 00000000.00000002.4103075841.0000000004ABB000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: msctf.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4110692473.000000000942A000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: FWPolicyIOMgr.pdb( source: getscreen-799952897-x86.exe, 00000000.00000002.4110692473.0000000009790000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\dll\samlib.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4103075841.0000000004AA0000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: TextInputFramework.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4110692473.0000000009B3A000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: UMPDC.pdb( source: getscreen-799952897-x86.exe, 00000000.00000002.4108262557.00000000090B7000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: Kernel.Appcore.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4110692473.0000000009542000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: C:\Github-runner\_work\agent-windows\agent-windows\console\Win32\Release\getscreen.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4098560677.0000000001AF2000.00000040.00000001.01000000.00000003.sdmp, bvsuyaubccihxlebpdetcxrlnozylqt-elevate.exe, 00000001.00000002.4060574453.0000000001642000.00000040.00000001.01000000.00000004.sdmp, getscreen-799952897-x86.exe, 00000003.00000002.4126173661.0000000001AF2000.00000040.00000001.01000000.00000003.sdmp, getscreen-799952897-x86.exe, 00000004.00000002.4146033255.0000000001AF2000.00000040.00000001.01000000.00000003.sdmp |
Source: | Binary string: fwpuclnt.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4110692473.000000000A11C000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: cryptbase.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4108262557.00000000090BC000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: netapi32.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4108262557.0000000008B67000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wgdi32.pdb( source: getscreen-799952897-x86.exe, 00000000.00000002.4106468398.000000000802D000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: msctf.pdb( source: getscreen-799952897-x86.exe, 00000000.00000002.4110692473.000000000942A000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: bcryptprimitives.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4110692473.0000000009487000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wkernelbase.pdb( source: getscreen-799952897-x86.exe, 00000000.00000002.4105286341.0000000007779000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\wmswsock.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4103075841.0000000004AA0000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: mfperfhelper.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4110692473.00000000099C7000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: Windows.UI.pdb( source: getscreen-799952897-x86.exe, 00000000.00000002.4110692473.0000000009A82000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wtsapi32.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4108262557.00000000090A0000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Users\user\Desktop\wbemsvc.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4103075841.0000000004ABB000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: oleaut32.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4106468398.000000000818E000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wuser32.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4105286341.0000000007956000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: comctl32.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4106468398.00000000080BB000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: InputHost.pdb( source: getscreen-799952897-x86.exe, 00000000.00000002.4110692473.0000000009C4A000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wbemprox.pdb source: getscreen-799952897-x86.exe, 00000000.00000002.4110692473.0000000009E35000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: wininet.pdb( source: getscreen-799952897-x86.exe, 00000000.00000002.4108262557.0000000008F14000.00000004.00000020.00020000.00000000.sdmp |